In this blog, George Ryan and Neil Jones, explore the growing use of AI agents and agentic AI and the risks these systems pose, including:
- How generative AI, AI agents and agentic AI differ
- The key risks associated with agentic systems
- Practical controls organisations can implement to improve oversight, accountability and security
- How established AI governance frameworks such as ISO/IEC 38507 (ISO 38507), ISO/IEC 42001 (ISO 42001) and the NIST AI Risk Management Framework (RMF) can support the responsible use of AI agents.
Many organisations exposed to AI today simply use it through a chat function. You prompt, and the AI responds, generating new content, such as text. AI agents differ fundamentally to this. Rather than simply responding, they can reason, plan, take actions and reassess their plans without needing human intervention. Beyond simple AI agents, organisations can utilise agentic AI, often consisting of multiple agents working together providing a system-level capability. While this increased autonomy can unlock significant business benefits, it also introduces additional risks and complexity, making effective governance and oversight even more important.
In practice, the first governance challenge is often not a failure resulting from the use of AI. It is discovering to what extent teams are already experimenting with agents, connecting them to business systems and granting permissions before ownership and oversight have been agreed. This is why organisations should establish visibility and accountability early, rather than waiting until agentic AI becomes business-critical.
How do AI agents and agentic AI work in practice?
Unlike generative AI, which typically supports individual tasks, agentic AI can coordinate activities across multiple functions. If we consider AI agents as the different members of a football team, then the agents are the players, working together but with different roles (e.g., goalkeeper, defence, midfield attack), governed by the manager, to achieve the goal of winning the match.
Consider the use of AI in the onboarding of new employees in an organisation:

What is the need for governance of agentic AI?
When used correctly, AI agents and agentic AI can be a business enabler. Unlike general purpose AI tools, AI agents can be tailored to specific business objectives and workflows. They can introduce significant benefits, such as increasing operational efficiency, aiding in decision making, improving customer experience and identifying trends.
However, this comes at a trade-off. As we have seen with organisations adopting increasingly advanced AI capabilities, greater autonomy is often accompanied by a greater potential for unintended outcomes. Improper usage can significantly increase your organisation’s risk, as the complex interactions of the different agents can be difficult to predict, test and manage. Without appropriate governance, these risks can lead to a range of adverse outcomes, such as unintended information disclosure, service disruption, reputational damage, and financial impacts, to name but a few.
AI governance is already crucial for organisations using generative AI seeking to manage AI-related risks effectively. If you are looking to further increase your organisation’s AI capability through agents, strong governance becomes even more essential due to their greater autonomy and complexity, as well as their increased capacity to create widespread impacts if they fail or behave unexpectedly.
My agents only use established AI models, why should I care?
Often, organisations build agents using existing AI models instead of creating their own models from scratch. However, taking this approach does not relieve your organisation of its responsibilities. Although it would be easy to assume that governance of the models used is solely the responsibility of the model creators, your organisation is responsible for how it uses the model, i.e., how it behaves, what it can access, and what actions it can perform.
Critically, you need to govern the agent, not the model. Whilst the same model can be used for both generative AI purposes (chat, drafting) and agentic systems (autonomous actions, decisions), these very different uses require separate governance.
In our earlier onboarding example, we had agents for onboarding, IT support, facilities, HR as well as the generative AI itself. Each of these agents, even if using the same underlying model, have different access, instructions and capabilities, which in turn necessitate subtly different governance.
How do I start?
The first step is to understand your AI system landscape. Start by identifying every agent involved in the agentic AI system and defining the scope of each one. For each agent, establish what it is intended to do, who will use it or have access to it, which systems and information it needs access to, and which actions it can perform. Then compare the access requested with the access genuinely required. In our experience, this simple exercise often reveals unclear ownership, duplicated capabilities and permissions that are broader than the agent’s role requires. As with an employee, an agent should only be permitted to access information and perform actions necessary for its role.
A useful lesson from governance reviews is not to rely solely on a central list of approved AI tools. Speak to the teams designing workflows, ask which systems their agents can access and verify the permissions in practice. The gap between an agent’s intended role and its actual access is often where the most significant risks emerge.
What risks should I be aware of, and what can I do?
The table below draws on the issues we most frequently encounter when discussing or reviewing AI agent deployments with organisations. It sets out why each issue matters and the practical measures that can help reduce the risk.

