From Governing People to Governing Agents: The New Data Governance Reality

September 25, 2026
Posted By
Nilabh Bajpai
From Governing People to Governing Agents: The New Data Governance Reality

Key highlights

For years, enterprise data governance focused on access, classification, ownership, lineage and approvals. These controls still matter. But AI agents introduce a different problem: software can now retrieve data, interpret it, make decisions, and take action without a person checking every step.

Consider something as simple as “active customer.” A CRM might define an active customer as anyone with a live account. Billing might count customers who paid within the last 90 days. A loyalty platform might use another definition.

A human analyst can usually recognise the difference and choose the definition that fits the question. An AI agent may not. If it selects the wrong definition and uses the result to trigger an action, the problem is not that it lacked permission. It is that it made a decision using the wrong business context.

That is the central shift in AI agent data governance. Governance must cover not only what an agent can access but also how it understands data, what decisions it makes, what actions it can take, and how those actions can be investigated or stopped.

Why AI Agent Data Governance Breaks on Definitions, Not Permissions

The obvious risk is an agent accessing something it should not. Access controls address much of that risk.

The harder problem is an agent doing exactly what it is authorised to do with a definition or context that is wrong.

When definitions differ across systems, an agent needs clear instructions about which one applies to a particular decision. Without them, it may retrieve a perfectly valid number that answers the wrong question.

 The warning signs may appear only later. Segment sizes change. Campaign volumes increase. Forecasts shift. Nothing obvious in the market explains the movement.
By then, the agent may have been operating on the wrong definition for days or weeks.
This is why permission correctness is not decision correctness. Security can determine whether an agent is allowed to access data. It cannot, by itself, determine whether the agent understood that data correctly.

As agents move closer to production systems, governance therefore needs to become part of the system itself. Controls should influence which data an agent can use, which tools it can access, what actions it can perform and when human intervention is required.

Fig 1: Permission ≠ Decision; An AI agent can have the right access and still make the wrong decision

Fig 1: Permission ≠ Decision; An AI agent can have the right access and still make the wrong decision

Human-in-the-Loop vs Human-on-the-Loop Is Not the Whole Decision

Governance discussions often focus on where the human sits.

Human-in-the-loop means a person approves an action before it happens.

Human-on-the-loop means the system operates more independently while a person monitors it and can intervene.

Both models have a place, but the right level of oversight also depends on consequence and reversibility.

Reversibility simply means how easily an action can be undone. An agent changing a product price may be able to reverse the change within minutes. An agent sending 40,000 customers a message cannot fully undo that communication once it has been delivered.

The oversight model should therefore consider three things: the agent’s autonomy, the potential business consequence, and how easily the action can be stopped or undone.

Action class Business consequence External action Oversight that fits Evidence to retain
Internal read and analysis Low None On-the-loop monitoring Query and source details
Configuration or model change Medium to high Yes On-the-loop with tested rollback Version history and change reason
Outbound customer contact Medium to high Yes In-the-loop approval at batch level Approval record and audience definition
Financial or contractual commitment High Yes In-the-loop, named approver Decision record and supporting evidence

This approach avoids the need for human approval of every low-risk action while putting stronger controls around actions that could create significant or difficult-to-reverse consequences.

What a Data Governance Framework for AI Agents Should Include

Organisations do not necessarily need a completely new governance stack. Many required capabilities already exist across data governance, security, architecture and risk. The change is how those capabilities connect to autonomous decision-making.

Recent McKinsey research on AI trust and the agentic era found that only about 30% of surveyed organisations had reached maturity level three or higher across strategy, governance and agentic AI governance. Security and risk concerns also remained a leading barrier to scaling agentic AI.

Fig 2 Five questions to put agent decisions under control

Fig 2 Five questions to put agent decisions under control

Start With the Decision

The practical starting point is not the agent itself. It is the decision.

List the decisions currently made or influenced by autonomous systems. For each one, identify the data it depends on, the authoritative definition, the person or function responsible for the outcome and what happens if the decision is wrong.

A simple test is:

What decision is being made? Which data supports it? Which definition applies? Who owns the outcome? Can the action be stopped or reversed?

This exercise can reveal a relatively small number of decisions and metrics carrying significant business impact. Those become the first priorities for governance.

Strong data foundations also become more important as agents gain autonomy. Trusted data, clear definitions, ownership and lineage help reduce the risk of an agent acting confidently on the wrong information.

Governance Has to Follow the Decision

AI agents do not make traditional data governance obsolete. They expose assumptions that human review could previously compensate for.

When software can retrieve data, interpret it, make a decision, and act on that decision, governance needs to cover the full chain from data definition to decision to action.

For enterprises, that means trusted data, clear ownership, governed actions, decision evidence and tested intervention paths become part of the architecture of reliable AI systems.

The question is no longer simply whether an agent can access the right data. It is whether the enterprise can understand and control what the agent does with it.

Not sure what your agents are actually reading?

We show you which of your agents’ definitions disagree, and which decisions that breaks

FAQs

Start with the metric definitions those agents use, especially where an incorrect definition could materially affect a decision.

Establish an authoritative definition for each decision-relevant metric and document important differences between source systems.

The function that owns the decision should remain accountable for its outcome, while data teams can own the definitions and data foundations underneath it.

Keep decision evidence showing the relevant definition, data context, decision, action, and accountable owner.

No. Oversight should reflect the consequence and reversibility of the action. Lower-risk activity can often be monitored, while high-impact or difficult-to-reverse actions may require approval.

Not exactly. AI governance covers broader policies, risks, and controls. Agent governance adds controls for systems that can independently retrieve information, make decisions, and take actions.

Sources

McKinsey & Company, State of AI trust in 2026: Shifting to the agentic era, 25 March 2026. https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era

Nilabh Bajpai
Nilabh Bajpai
Business Head-Priorise
Nilabh Bajpai is Business Head at Priorise, advising enterprises on data and AI strategy, enterprise architecture and modern data platforms. His career spans four decades of technology delivery, transformation and leadership, with deep experience in building scalable systems, modernising data environments and aligning technology investments with business priorities. He writes on data engineering, cloud and data platforms, applied Gen AI, enterprise AI adoption and what it takes to design, build and run reliable AI and data systems at production scale.