MilikMilik

Enterprise AI Agents Face a New Control Problem

Enterprise AI Agents Face a New Control Problem
Interest|High-Quality Software

Defining the enterprise AI agent control problem

Enterprise AI agent control is the challenge of allowing autonomous systems to act inside business workflows while maintaining human oversight, regulatory compliance, security, and clear lines of accountability. As AI agents gain the ability to reason, access tools, and take actions, the gap between raw model capability and safe, governed use is becoming a central concern for leaders building enterprise AI governance frameworks. Salesforce calls this emerging landscape the “agentic enterprise,” where AI agents work across functions, but only within an “agentic harness” that keeps data access, permissions, and auditability in check. At the same time, enterprise AI compliance teams must answer practical questions: which systems stay in charge, when must a human approve decisions, and how far should agents be allowed to change work instead of only answering questions.

Enterprise AI Agents Face a New Control Problem

Salesforce: three core challenges shaping enterprise AI governance

Salesforce Futures VP Mick Costigan says customers face three linked questions as AI agents spread across organizations: how capable agents will become, how to bring them into existing systems, and what humans will do when agents take on more work. This triad goes to the heart of enterprise AI governance. Capability raises autonomous systems risks as models improve at “the beginning of an exponential rate,” while implementation demands reliable connections to data, tools, permissions, and governance policies. Human roles and accountability must then be redesigned around AI agent control, not replaced by it. Salesforce’s answer is the “agentic harness” around large language models: a layer that enforces zero data retention where required, controls access to sensitive records, and ensures outputs are auditable. According to Salesforce, enterprise AI agents only become useful once this control infrastructure is as mature as the models themselves.

Workday: testing how much autonomy AI agents should have

Workday is turning these abstract governance debates into concrete workflow decisions. Its AI agents now appear in HR, finance, and public-sector scenarios where mistakes carry heavy consequences, so the company is testing how far agents can go before human review becomes mandatory. Workday draws a clear line between conversational interfaces and agents that “change work.” A chatbot may answer questions, but an enterprise agent can submit leave requests, approve timesheets, trigger personnel actions, or validate policies. This shift makes enterprise AI compliance and control the primary design problem. Workday’s integration of its Sana Self-Service Agent with Microsoft 365 Copilot shows how interfaces can spread into productivity tools while keeping transactions anchored in Workday, under existing approvals and business rules. The company is effectively experimenting with a tiered autonomy model: agents can act, but only within the guardrails of a governed system of record.

Autonomous systems risks and the need for new control layers

Both Salesforce and Workday highlight the tension between expanding agent capability and maintaining organizational control. As agents gain access to more tools and data, autonomous systems risks multiply: policy misapplication, hidden bias in decisions, and opaque chains of responsibility when things go wrong. Modern enterprise AI governance must therefore extend beyond model selection and prompt design. It needs explicit policies on which systems own the transaction, clear approval thresholds, and logging that shows what an agent changed and why. Workday’s approach keeps data and transactions “at home” in its core platform, even when prompts start in external interfaces. Salesforce’s harness concept, by contrast, focuses on context, data access, and zero data retention where required. In both cases, the control layer becomes the real product: a structured way to keep agents powerful enough to be useful, but constrained enough to satisfy compliance and audit needs.

Balancing automation, compliance, and the future of work

Underlying these technical guardrails is a broader organizational question: how should enterprises share work between humans and agents without increasing operational risk? Costigan advises customers to pursue near-term productivity gains while exploring deeper changes to jobs, skills, and workflows. Workday’s roadmap shows what this might look like in high-stakes environments. Its planned Personnel Action Request Agent for government HR aims to cut processing cycle times for complex actions, where Workday reports current routines can run from 22 to 45 days and recruitment can stretch to 80 to 120 days. Such gains are only acceptable if enterprise AI governance keeps pace, giving agencies and companies clear audit trails and policy explanations. The emerging norm is a layered model: AI agents automate repetitive steps, human experts oversee edge cases, and platforms hard‑code compliance, security, and controls into every autonomous action.

Milik earns a commission when you shop through our links, at no extra cost to you. This article was generated with AI from published sources and product data.

You May Also Like

Comments
Say something...
No comments yet. Be the first to share your thoughts!