Damon Tompkins, CEO of Pathlock, delivering audit-ready identity and access governance for ERP systems and business-critical applications.gettyGartner Inc. predicted in August 2025 that 40% of enterprise applications would include task-specific AI agents by the end of 2026, up from less than 5% at that time.The level of access and authority these AI agents are granted is mind-blowing. At the same time, while AI brings tremendous value, it also introduces risk at a scale we've never dealt with.Yet in many organizations, questions around AI adoption center around ROI and implementation rather than risk management. Boards ask: What's our AI strategy? How quickly are we deploying AI? How much productivity can we gain?These are reasonable questions. Businesses operate under constant pressure to improve efficiency and drive growth. However, questions about risk ownership are less common—a dangerous gap. How much power are AI agents gaining inside the enterprise? Why does it matter to boards? How does governing AI differ from governing human identities? What questions should executives be asking to ensure effective AI risk management?AI is moving into core business operations.AI has extended beyond content generation and analytics into the core of business operations, where it can influence decisions involving financial, legal and other critical business domains.Google has launched a dedicated Gemini Enterprise app for business users, connecting enterprise data across productivity platforms such as Google Workspace, Microsoft 365, Salesforce and others. SAP has introduced an AI strategy combining Business AI, Business Data Cloud and Knowledge Graph to embed autonomous AI agents directly into enterprise processes and automate end-to-end workflows.At this point, AI adoption becomes a governance issue requiring board-level attention. When AI participates in those processes, it introduces a new category of risk that existing control and governance frameworks, centered around human decision makers, were never designed to address.Authorities are already recognizing the AI governance challenge.The importance of AI governance is already being recognized at the federal level. In April 2025, the Trump administration required federal agencies to appoint chief AI officers (CAIOs) to be accountable for AI risk and compliance. The objective is to ensure that before new AI technologies are deployed, organizations understand their security implications, operational risks and potential impact on public trust.This development sends an important signal to the private sector. AI governance is becoming a strategic organization's responsibility, and companies that fail to establish appropriate oversight today may face significant operational, regulatory and security risks tomorrow.Governing AI agents is different from governing human users.Traditional identity governance frameworks are built around a simple assumption: Humans are responsible for actions within enterprise systems.The key difference is that, unlike humans, AI agents can interact with applications using different interfaces through APIs—and they can do so at machine speed. At the same time, organizations often grant AI agents access based on existing human roles. However, permissions designed for people aren't necessarily appropriate for autonomous systems.For example, in SAP environments, machine identities may have direct access to databases, system tables or sensitive business data that human users would never be permitted to access directly. As a result, AI agents may be capable of making decisions or performing actions that differ significantly from what a human employee could do.Consider an AI agent connected to SAP and authorized to automate accounts payable processes. If improperly governed, it could mistakenly approve duplicate vendor payments, modify supplier banking information or process transactions that bypass established segregation-of-duties controls. In a global enterprise, such errors could affect thousands of transactions before anyone notices. Because SAP often serves as the backbone for finance, procurement, HR and supply chain operations, unrestricted AI access can quickly translate into financial loss, audit findings, regulatory exposure and operational disruption. Unlike a human error that may affect a single transaction, an AI-driven error can be replicated thousands of times across multiple systems before it's detected.As AI becomes capable of executing complex, multistep workflows across applications, governance must move beyond policy-level oversight. It requires transaction-level visibility into what AI is doing, which processes it influences, what controls are applied and who is accountable when something goes wrong.What questions should boards be asking? Boards that focus exclusively on AI adoption may be asking the wrong questions. The governance gap is real, growing and increasingly becoming a source of organizational risk. To address it, boards should start with fundamental questions:1. Do we have a clear inventory of the AI technologies being used across the organization? Do we have policies in place about what AI we're using? Do we have corporate-level accounts or subscriptions for certain AIs? Boards should understand which AI platforms are approved, whether enterprise subscriptions are being used and what rules govern acceptable use.2. Are AI systems involved in critical business processes or decision making? Organizations need visibility into where AI is augmenting or replacing human decision making, particularly in areas involving financial, legal, operational or compliance risk.3. What risks have been identified, and how are they being managed? Organizations should have a clear framework.4. What controls are in place to govern AI agents? Boards should understand how AI access is granted, monitored and reviewed. They should also know whether organizations can explain and audit AI-driven outcomes.Conclusion The question organizations must ask themselves is whether they can govern AI effectively. Boards that begin asking the right questions today will be far better positioned to capture AI’s benefits while managing its risks tomorrow.Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
Questions To Ask As AI Agents Become Powerful Enterprise Actors
AI has extended into the core of business operations, where it can influence decisions involving financial, legal and other critical business domains.
Gartner forecasts 40% of enterprise apps will embed AI agents by 2026 with access exceeding human permissions. AI errors replicate silently across thousands of transactions; boards must implement transaction-level governance to manage financial and compliance risk.










