Enterprise AI agents can trigger workflows and act before anyone checks their output, says SAS strategist Marinela Profi. Her practical prescription is to govern the whole action chain: restrict permissions, log tool use and require approval where the consequences warrant it.
Watch Desk analysis
What happened
In an interview published by AI News on 8 October, Profi argues that organisations should treat governance as part of an agent’s architecture, not a policy document filed after the interesting decisions have been made. She recommends testing complete systems, including what happens when tools fail, data is stale or permissions change.
Her checklist is concrete: define what data an agent can access, which actions need approval, what triggers escalation and what must be logged. Profi also argues that autonomy should vary with risk, reversibility and consequence. A low-risk action that can be undone may need less oversight than a decision affecting someone’s health, credit or employment.
Why it matters
A chatbot’s wrong answer can be ignored. An agent’s wrong action may already have reached another system. Profi’s argument is that organisations need to test not just whether a model answers correctly, but whether the system was authorised to act, used appropriate data and stayed within its boundaries.
She cites SAS research saying 89% of agents deployed in production are acting rather than merely assisting, while more than half operate with limited or no human approval. Those are figures presented in the interview from SAS research, not an independent audit of the wider market.
Our read
The useful distinction is between human approval for every click and human control over the rules. Making people rubber-stamp every routine action is not a governance strategy; it is a queue with better branding. Set permissions, escalation thresholds and audit logs before expanding an agent’s authority, then test the awkward cases, not just the polished demo.
What to watch
- Whether organisations put agent-level permissions and tool-use logs into production systems.
- Whether testing covers stale data, failed tools and changed permissions, not just model answers.
- Whether human approval is reserved for actions where the risk or irreversibility warrants it.
Discussion spark: Should enterprise agents be allowed to act on their own inside strict limits, or should a person approve every consequential action?
Sources and evidence
- Marinela Profi, SAS: On governing autonomous AI agents – AI News (8 October 2026, 14:56 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.