AI News Feed
Market watch
Cybersecurity

AI Agent Governance Must Begin With Enterprise Data, TechRadar Argues

A TechRadar article says deploying AI agents requires governed enterprise data first, including classified inputs, least-privilege access, provenance and retained records of prompts, outputs and decisions.

Executives are spending a great deal of time asking whether AI agents are ready for production, but the article says this is the wrong place to start because agents do not act in a vacuum. If an agent receives outdated customer information, duplicate records or material that was never properly classified, it will work with what it has and make poorly informed decisions quickly across thousands of transactions, according to the article.

According to TechRadar, the gap between AI adoption and governance is widening fast. In the rush to adopt AI, many organizations are pushing agents into production before solving the underlying data problem, and the vast majority of AI projects show zero ROI, the article says. Governance also covers the data an agent produces, including its decisions, the instructions it was given and documents it created. As AI contributes to significant decisions within the enterprise, AI traceability and defensibility have become critical capabilities, the article says.

The article says the data problem comes first. Data governance is not a new problem, but because agentic AI can rapidly act on weaknesses at scale, the issue has become more pressing. Before an agent is given access to data, IT needs to identify sensitive and regulated information, apply classification and retention policies consistently, and determine which sources are current and reliable enough for the job. Legacy data deserves particular care because retired applications often contain valuable business history but also hold duplicate records, obsolete information and data subject to legal holds or retention requirements. Organizations should preserve the context and relationships that give legacy data meaning, then make selected, policy-controlled datasets available. Without surrounding context, agents will either fail to complete their tasks or make and act on faulty decisions, according to the article.

Access is a business decision, the article says. A mistake enterprises make is providing agents with access to more data than they need. Agents should only have access to the data required to complete their assigned tasks, and the fact that a system can be connected to an agent does not mean it should be. The article recommends treating agents like employees and following the principle of least privilege. For example, a customer service agent may need current account and transaction information but most likely does not need legal files or historic employee records. Provenance also matters: an agent should not treat a current system of record and a decades-old archive as equally authoritative. Agents must know where information came from, when it was updated and which policies apply.

Governance does not end once the agent receives approved data, according to the article. AI-related data is rapidly becoming material to litigation, compliance reviews and customer complaints. Organizations should be able to show what the agent was asked to do, which information it accessed, which policies were applied and what happened next. Prompts, retrieved content, outputs and resulting decisions should be retained as business records. A reviewer should be able to reconstruct the AI's decision and trace it back to both the source data and the person or function that authorized the activity.

Accountability cannot belong to the technology team alone, the article says. Security, data, privacy, legal and compliance leaders all have a role, but a named business owner must remain responsible for the outcome. Automation can perform an action, but it cannot accept accountability for it. The article says data readiness is not a secondary workstream to be addressed after an AI pilot succeeds; it is part of the decision to move that pilot into production. If an organization cannot trust the information, the article's argument goes, it cannot trust the agent's decisions.

Editor's Summary

The TechRadar article argues that AI agent governance must start with governed enterprise data, including classified, current and policy-controlled inputs, least-privilege access and retained records of prompts, outputs and decisions. It says many AI projects show zero ROI because organizations deploy agents before fixing data problems. The article adds that a named business owner, not technology alone, must remain accountable for agent outcomes.