02 setembro 2026 / 09:37 da manhã

Governance in the Age of Agentic AI

Agentic AI is transforming the relationship between people, information, and processes. Governing it requires moving from controlling tools to governing capabilities.

By Angel Fernández, Senior Executive at SDG Group Spain

The adoption of artificial intelligence within organizations has, until now, followed a fairly recognizable pattern. Traditional AI based on machine learning models emerged with a clear focus on solving business problems, but its implementation remained largely in the hands of technical teams: data scientists, data engineers, cloud architects, or teams specializing in advanced analytics.

Something similar happened with the first Generative AI and LLMOps initiatives, where experimentation with models, prompts, embeddings, RAGs, and deployment pipelines remained closely tied to technical profiles.

Agentic AI introduces a significant shift in this logic: Tools such as Microsoft Copilot, Gemini Enterprise, Copilot Studio, Claude, or ChatGPT Enterprise are not only designed to develop AI solutions, but also to put advanced capabilities for reasoning, content generation, and task execution directly into the hands of business users, even those with limited technical knowledge. This enables people to identify recurring problems, automate tasks, explore process improvements, and develop new ways of working with a much lower technical barrier to entry.

For organizations committed to becoming truly data-driven, this represents a major accelerator.

Faced with this reality, many organizations are asking themselves how to govern these new agents. However, given that this capability is widely distributed—often at scale through licenses sponsored by senior management—trying to control it solely through restrictions does not seem realistic or sustainable. Perhaps the right question is not how to govern the tool, but how to govern the purposes that this capability enables.

Something similar has already happened with other enterprise technologies: Excel itself is not governed simply because it exists, but rather based on how it is used, the information it handles, and the decisions and discussions it supports. Agentic AI does not break this logic. What changes is the speed, autonomy, and ability to interact that these new tools provide.

The challenge is to understand what users are doing with these capabilities, what information they are using, what decisions they support, and the potential impact they may have on the organization, its customers, or third parties.

Not all agents carry the same level of risk. An assistant used to summarize documents or draft emails has a limited impact on the user themselves. However, the situation changes when an agent participates in internal processes, generates information used to make business decisions, interacts with customers, or executes actions within corporate systems. In these scenarios, operational, regulatory, reputational, and ethical risks emerge, requiring proportionate oversight mechanisms. From a governance perspective, this requires an evolution of the traditional approach.

Historically, organizations have governed data, applications, and processes. Agentic AI introduces a new dimension: the governance of capabilities. It is no longer enough to know which systems exist or which data is being used. Organizations need to understand which capabilities are being enabled, who can use them, what actions they can perform, for what purpose they will be used, and what impact they may generate.

However, governing capabilities cannot rely solely on policies, procedures, or review committees. As agents gain access to corporate information, reasoning capabilities, and the ability to act on business processes, governance mechanisms need to be embedded directly into the technology architecture, making it possible to automate controls and scale at the same speed as the adoption of agents.

At SDG Group, we address this challenge through a model based on three complementary layers: Knowledge Store, Agent Layer, and Risk & Evaluation Layer.

  • The first layer, Knowledge Store, focuses on governing the knowledge used by agents, ensuring that the information they rely on is trustworthy, compliant with privacy regulations, controlled, and assigned to clearly defined owners. At the same time, a governed Knowledge Store helps reduce time to market, as well as incidents, inconsistencies, and hallucinations.
  • The second layer, Agent Layer, addresses the governance of the agents themselves, defining which capabilities they can use, which actions they can perform, and under what levels of authorization and supervision. It provides the same benefits discussed in relation to the Knowledge Store.
  • Finally, the Risk & Evaluation Layer makes it possible to monitor agent behavior and continuously manage the associated risks, ensuring that their operation remains aligned with internal policies and regulatory requirements, both during the development stage and throughout operational monitoring.

At SDG Group, we always aim to avoid reinventing the wheel. For this reason, whenever possible, this approach builds on the native governance, security, monitoring, and control capabilities offered by hyperscalers and agentic platform providers themselves.

Leveraging these configurations and modules makes it possible to accelerate adoption, reduce technological complexity, and ensure more natural integration with the control mechanisms already in place across the corporate ecosystem. We complement these layers with a unique development methodology designed to move from distributed experimentation to scalable, reusable, and secure solutions. The goal is not for every business area to build agents according to different criteria, but rather to establish a common framework for identifying use cases, assessing their feasibility, designing agents, validating results, documenting decisions, and establishing controls before and after deployment.

Similarly, Agentic AI requires a clear strategy for training and change management. If these capabilities are designed to be used by the business, users need to understand not only how to build or use agents, but also their limitations, risks, and responsibilities. Training should help distinguish between individual use cases and those with corporate impact, recognize sensitive information, validate results, and scale those use cases that can generate value beyond the team that originated them. Without this cultural dimension, governance risks becoming a theoretical framework disconnected from actual use.

But Agentic AI does not only introduce new control challenges. It also creates an extraordinary opportunity to drive organizational transformation. Beyond controlling risks, governance should act as a mechanism for identifying, classifying, and scaling the initiatives that generate value. The goal is not to limit innovation, but to channel it.

The combination of Agentic AI and governance can create a virtuous cycle in which users explore new ways of working, agents reveal opportunities for improvement, and governance provides the framework needed to scale these innovations safely and sustainably. The most mature organizations will not necessarily be those that deploy the most agents, but those that are able to understand which capabilities they are enabling, what knowledge they are using, what risks they generate, and what transformation opportunities they are discovering.

Ultimately, Agentic AI should not be seen merely as a new technology. It should be understood as a new way of interaction between people, information, and processes. And, as has historically been the case with any other technological capability, its success will depend less on the tool being used than on the organization's ability to govern it, measure its impact, and turn it into a sustainable source of value creation.