As the use of AI agents rises, organizations face a widening gap between adoption and governance. New insights from Info-Tech Research Group indicate that governing agentic AI is fundamentally different from previous governance models. Agents can autonomously access systems, trigger workflows, and make decisions faster than the organization can detect, leading to growing security, compliance, and reputational risks. The firm's blueprint, Govern Enterprise AI Agents While Preserving Innovation, provides a structured approach to managing agent identity, access, autonomy limits, and ongoing oversight without slowing the innovation that agentic AI is meant to deliver.
ARLINGTON, Va., Aug. 28, 2026 /CNW/ -- AI agents are emerging as a distinct class of digital actor, operating autonomously across enterprise systems with a speed and access that outpace traditional oversight. New research from Info-Tech Research Group, Govern Enterprise AI Agents While Preserving Innovation, examines why conventional approval-based governance cannot keep pace with agentic AI and emphasizes that agents lack conscience and cannot be morally incentivized. The firm presents a step-by-step framework to help organizations limit agents' autonomy and access while preserving space for innovation.
"AI agents cannot be governed like traditional IT assets or earlier AI models because they do more than generate outputs; they act across systems," says Altaz Valani, principal advisory director at Info-Tech Research Group. "Many people will have multiple agents working for them, but AI agents cannot be governed the way we govern humans because they move quicker and lack emotions, conscience, and consequences."
Info-Tech's research outlines a practical governance model, starting with visibility into which agents exist, who owns them, what they can access, and their level of autonomy. The model helps organizations classify agents by risk, monitor behavior while they operate, and define when to intervene before a risk becomes an incident.
Key Challenges Organizations Face in Governing Enterprise AI Agents
The firm's blueprint identifies several governance gaps that arise as organizations adopt agentic AI, including:
- Shadow AI: Agents created outside sanctioned tools exist without IT's knowledge.
- Capability mismatch: Agent autonomy and access lack matching validation and monitoring.
- Runtime drift: Agents quietly expand scope through tool, prompt, and permission changes.
- Unmanaged access: Permissions and service accounts overextend what agents can do.
- Ambiguous ownership: No clearly defined responsibility and accountability when agents cause harm.
Info-Tech's Three-Phase Approach to Governing Enterprise AI Agents
To close the governance gap, the firm's Govern Enterprise AI Agents While Preserving Innovation blueprint recommends a phased approach and outlines the following priorities for CIOs, CISOs, and AI governance leaders:
Phase 1: Establish Agentic AI Governance Authority and Guardrails. Governance leaders formalize the agentic AI mandate, confirm decision rights, and align on a small set of enforceable principles, guardrails, and decision rights.
Phase 2: Define the Agentic AI Governance Model. Governance and technical teams map the agent lifecycle, find agents wherever they are created, classify them by risk, and define runtime monitoring expectations and clear intervention actions based on the risk tier.
Phase 3: Operationalize Oversight and Accountability. Business owners, technical owners, AI governance, and enterprise risk leaders agree on a clear accountability model, define metrics, establish executive reporting through a dashboard view, and execute a phased rollout plan.
The Govern Enterprise AI Agents While Preserving Innovation blueprint includes case studies, practical tools, and templates, including an Agentic AI Governance Playbook, Agentic AI Governance Charter Example, State-of-AI-Agents Executive Dashboard, and Agentic AI Governance Glossary.
By applying this framework, organizations can move from a one-time approval method to ongoing governance that manages risk as agents operate, enables safe experimentation, and gives leaders a clear view of exposure as AI use expands across the organization.
For exclusive and timely commentary from Info-Tech's experts, including Altaz Valani, and access to the complete Govern Enterprise AI Agents While Preserving Innovation blueprint, please contact [email protected].
About Info-Tech Research Group
Info-Tech Research Group is the "get things done" partner for over 30,000 IT, HR, and marketing leaders worldwide. The fastest growing research and advisory firm, Info-Tech enables leaders to make well-informed decisions and transform their organizations through AI, strategic foresight, step-by-step methodologies, practical tools, industry-leading advisory, and training programs. For nearly 30 years, tens of thousands of private and public organizations have trusted Info-Tech to lead their most important initiatives through periods of change and deliver outcomes that truly matter.
To learn more about Info-Tech's HR research and advisory services, visit McLean & Company, and for data-driven software buying insights and vendor evaluations, visit the firm's SoftwareReviews platform.
Media professionals can register for unrestricted access to research across IT, HR, and software, and hundreds of industry analysts through the firm's Media Insiders program. To gain access, contact [email protected].
For information about Info-Tech Research Group or to access the latest research, visit infotech.com and connect via LinkedIn and X.
SOURCE Info-Tech Research Group

Media Contact: Sufyan Al-Hassan, PR Director, Info-Tech Research Group, [email protected], +1 (888) 670-8889 x2418
Share this article