AI Agents: The Urgent Governance Challenge for CIOs

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
The Rise of Non-Human Identities
In the near future, companies will face a major transformation: the number of non-human digital identities will surpass that of human users. This evolution is already underway, profoundly changing how businesses manage their operations.
Artificial intelligence agents, whether they are autonomous assistants, software robots, or intelligent workflows, will interact with data and applications, performing tasks on behalf of employees. For example, an AI agent can today extract information from a CRM, conduct searches in databases, prepare business proposals, update various systems, and relay a summary to a colleague. These capabilities offer significant productivity gains, but they also raise crucial governance questions.
- Who grants rights to these agents?
- Who oversees the data they manipulate?
- Who is responsible in the event of incorrect transmission of confidential information or erroneous actions?
Historically, companies have structured their governance models around two main categories: users and applications. The introduction of AI agents challenges this established balance.
A New Challenge for CIOs
Over the past decade, CIOs have worked to regain control over Shadow IT, Shadow SaaS, and the proliferation of applications within companies. However, a new phenomenon is already emerging, often outside any governance framework: AI agents.
The issue does not lie in their existence, but in how most organizations continue to perceive them as mere productivity tools, while they are gradually becoming full-fledged operational actors. As is often the case in digital transformation, technology is advancing faster than governance structures.
The Evolution of AI Agents
For a long time, artificial intelligence was relatively easy to frame. Employees would query an assistant, receive a response, and then remain responsible for the action. This boundary is beginning to blur.
New agents no longer just provide answers. They execute tasks. They search for information across multiple applications, update data, create tickets, generate reports, or trigger workflows.
- A sales agent can prepare a proposal from CRM data.
- A support agent can analyze a ticket, consult a knowledge base, and propose a solution.
- An HR agent can compile summaries from multiple internal sources.
These uses mark a significant break. For the first time, software entities with a degree of autonomy directly access information systems and act upon them. However, our current governance models are not designed to manage this new reality.
A New Category of Digital Identities
For decades, information systems have relied on a relatively simple distinction: on one side, users; on the other, applications. The former have an identity, permissions, and responsibilities. The latter execute processes according to predefined rules. All modern digital governance has been built around these two categories.
The arrival of AI agents changes the game. An agent is not a collaborator, but it can act on their behalf. An agent is not a traditional application, but it can access multiple applications simultaneously and make certain decisions within a defined framework. This intermediary position creates a gray area that current models struggle to address.
Most organizations are therefore faced with a new reality: they must now govern a third category of digital identities. And this is precisely where the difficulties begin.
The Real Risk: Lack of Framework
When a new technology emerges, companies naturally focus their efforts on usage and potential gains. AI agents are no exception. Businesses experiment, automate, and seek to save time. This dynamic is healthy, but it can quickly produce the same effects observed with Shadow IT or early cloud services.
- How many agents are currently in use within the company?
- Who created them?
- What data do they access?
- What actions are they authorized to perform?
- Who is responsible for their behavior?
In many organizations, these questions remain unanswered. The danger is not the existence of agents, but their proliferation without an appropriate governance model.
Four Principles to Frame AI Agents
CIOs do not need to completely reinvent their practices. However, they must adapt them to this new category of digital actors. Four principles seem essential to me.
-
Assign a Unique Identity to Each Agent
Today, many agents implicitly inherit the rights of their creator or user. This approach quickly reaches its limits. Each agent should have a clearly identifiable identity, a designated owner, and an explicit scope of action. The goal is simple: to know at all times who is acting, on whose behalf, and within what framework. One should never have to wonder whether an action was performed by a collaborator or by an agent. -
Apply the Principle of Least Privilege
Agents should only have access necessary for their mission. An agent tasked with assisting a sales team does not need access to HR data. A marketing agent does not need to intervene in financial systems. This principle is well-known in cybersecurity. It becomes even more important when entities are capable of operating autonomously and at scale. The question should not be: "What can this agent access?" but "What does this agent actually need to accomplish its task?" -
Make Every Action Traceable
Trust relies on visibility. Every action performed by an agent should be auditable. What data was accessed? What decision was made? What action was executed? In what context? This requirement is not solely about security. It becomes essential for understanding behaviors, correcting errors, and demonstrating process compliance. An agent that acts without traceability quickly becomes an operational risk. -
Maintain Human Oversight
Autonomy should never eliminate responsibility. Not all processes present the same level of risk. Some tasks can be largely automated. Others require systematic human oversight. The ability to define these boundaries will become one of the key roles of CIOs in the coming years. The question is not whether to choose between automation and human control. It is about determining where to smartly place the balance.
Shared Responsibility Beyond the CIO
It would also be a mistake to consider the governance of AI agents as a purely technical issue. The stakes involve security, but also compliance, human resources, business units, and sometimes even corporate governance.
- Who can create an agent?
- Who validates its permissions?
- Who controls its scope of action?
- Who bears responsibility when an incident occurs?
These questions require organizational answers as much as technological ones. As with cloud or data, the most mature companies will likely be those that approach the topic transversely rather than as a simple IT project.
Govern Before Suffering
The history of digital technology shows a recurring pattern. Usages always arrive before the rules that frame them. Smartphones arrived before BYOD policies. The cloud arrived before cloud governance strategies. Generative AI arrived before most usage charters. AI agents are now following the same trajectory.
The good news is that CIOs still have a window of opportunity. The subject remains emergent. Usages are numerous but still under construction. This is precisely the time to define the principles that will frame their development.
For the real ticking time bomb is probably not artificial intelligence itself. It is the risk of seeing thousands of agents capable of acting, accessing data, and taking initiatives emerge within information systems without the company having clearly defined the rules governing their existence.
And as is often the case with governance, organizations that act early will have a decisive advantage over those that wait for the problem to become visible.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.