Skip to content

From AI Assistants to Agents: Why Autonomy Raises the Stakes on Data Governance

 Featured image

DvK-3095 Large-1By Jaap van Duijvenbode

Co-Founder and VP Product Strategy & Customer Experience

Summary: An AI assistant answers questions; an AI agent acts on data. Agents can inherit the same over-permissioned access as the users they work for, and they can act on it at speed. Scoped access, traceability and clear boundaries on what agents can reach need to be in place before autonomy scales.

From answers to actions

The first wave of enterprise AI was conversational. Assistants summarized documents, drafted emails and answered questions, and a person decided what to do with the output. Agents change that. They plan multi-step tasks, call tools, read and write files, and hand work to other agents, often without a person reviewing each step.

The governance concern is not new. It is the old problem of over-permissioned data, now operated by software that works faster than any employee. In Gartner's 2026 Microsoft 365 and Copilot survey, 80% of IT leaders agreed that additional governance controls are required before widely deploying agents, and 68% said they were worried about agent sprawl. The same concern applies to agents built on any platform or framework.

What agents inherit

An agent usually acts with the permissions of the person who launched it, or with a service identity that has broad access by design. Either way, it may inherit:

  • Sharing that was set to "everyone" years ago and never reviewed.
  • Access that should have been removed when people changed roles.
  • Archives that nobody remembers are connected.
  • Sensitive records mixed into general project folders.

A person with the same access might never stumble on any of it. An agent tasked with "gathering everything relevant" will find all of it, and may copy it into a summary, a message or another system.

Four foundations to put in place

  1. Scope access to the task. Agents should reach only the sources a task requires. Broad service accounts are the agent equivalent of a shared admin password.
  2. Enforce permissions at the data layer. Access rules should be applied where the data is retrieved, so every assistant, agent and integration inherits the same controls rather than each re-implementing them.
  3. Make every retrieval traceable. Log which agent asked, on whose behalf, which sources it reached and what it returned. Without that record, incident response and audits become guesswork.
  4. Define exclusion zones. Some data may need to remain outside the reach of AI, regardless of who asks. Make those boundaries explicit and easy to change.

One governance layer, many agents

Most organizations will run agents from several vendors: productivity suites, business applications, coding tools and custom builds. Governing each one separately produces inconsistent rules and gaps between them. A shared, permission-aware layer between agents and enterprise data, reachable through open standards such as the Model Context Protocol, lets every agent draw on the same trusted context under the same controls.

Start before scale

The time to set these foundations is while agent deployments are still small enough to inventory. Retrofitting governance onto hundreds of agents is far harder than designing it in from the start.

Want to assess your organization's readiness for AI agents? Talk to our specialists.

Sources