For better or worse, AI agents are now a part of the workforce. They write code, analyze documents, respond to customers, coordinate workflows, and make decisions across multiple business systems with very little human involvement.Â
AI agents have proven they can do the work. Now, enterprises must prepare for a world where they do far more of it. With Gartner predicting that the average Fortune 500 company will run more than 150,000 AI agents by 2028, enterprises need to lay a strong foundation now to ensure proper governance of the technology.
THE OLD MODEL DOESN’T SCALE
Historically, governance has been built around human systems. Security, compliance, privacy, and risk teams reviewed new systems before they went live, identified concerns, and worked with the business to resolve them. That model worked because software changed slowly and deployment cycles stretched over months.
With AI, that goes out the window. An agent can make thousands of decisions before a traditional review process even begins. As organizations move from a handful of AI agents to hundreds, or eventually thousands, the volume of activity quickly exceeds what humans can realistically monitor.
Research repeatedly shows that enterprises can’t keep up. IBM found that 70% of technology executives say AI is being deployed faster than IT can track it.
Gartner found that only 13% of organizations believe they have the right AI governance in place, and similarly, Deloitte found that only 21% of enterprises report having mature governance for agentic AI. Enterprises facing these challenges can’t solve them by simply throwing more people and money at the problem. Instead, they need to redesign how governance functions within their organizations, with AI at the center.
A NEW LAYER OF SUPERVISION
Unlike traditional software that follows predefined instructions, AI agents reason through goals, decide what actions to take, and adapt to situations they were never explicitly programmed to encounter. As organizations deploy them across finance, HR, IT, software development, and customer operations, oversight becomes a very different challenge.
Enter a new category of AI: guardian agents.
Just as business agents perform work, guardian agents supervise that work. Rather than replacing governance teams, these agents extend them. They monitor how other agents interact with enterprise systems and evaluate planned actions against organizational policies. They understand which tools an agent is using, what data it is accessing, and the permissions it is operating under. When activity falls outside acceptable boundaries, they intervene.
Intervention will look different depending on the task and guardrails set. Sometimes it will be the creation of an audit trail. Other times it may mean alerting a human reviewer or requiring approval before an action proceeds. In higher-risk situations, it can block actions altogether.
Instead of reviewing decisions after the fact, organizations can evaluate and influence them as they’re being made. This shift from reactive to proactive enables governance teams to operate at the same speed as AI, reducing risk before it becomes a business problem.
WHY BLOCKING ISN’T THE SAME AS JUDGMENT
Consider an AI agent responsible for optimizing a customer marketing campaign. It analyzes customer behavior and finds that people experiencing financial hardship are less likely to comparison shop and more likely to accept higher prices. Mathematically, the strategy maximizes revenue. Most organizations would never want to treat customers that way.
The agent accomplished exactly what it was asked to do. The problem was that it lacked the judgment and business context a human employee would have applied before acting.
That’s why thinking about AI governance solely in terms of guardrails misses part of the challenge. Safeguards and approval workflows are important, but they can only prevent scenarios people have anticipated. No one creates a policy to stop an AI from exploiting a consumer’s financial hardship because, until now, that wasn’t a risk anyone expected to encounter.
What would catch it is the organization’s own judgment. Every company has already worked out how far it will go for revenue and where it won’t go at all. That thinking lives in the heads of experienced governance professionals and gets applied a few decisions at a time. Guardian agents offer a way to make it available every time an agent acts.
That doesn’t remove human accountability. Leaders still set policy and remain accountable for the more complex decisions. What changes is the scale at which organizations can manage governance. Judgment that used to cover a handful of reviews can now apply to every AI interaction, without waiting for a person to be in the room.
AI agents are improving at a remarkable rate. Whether that creates value or introduces risk will depend on the decisions organizations make now about how those systems should operate.
Blake Brannon is the chief innovation officer at OneTrust.
Â