As agents gain enterprise traction, boards need to probe deeply
Responsible board members want to ask the right questions about AI agents.
That’s not as difficult as it sounds, even though the technology is new.
Oversight starts with an understanding of the specific threats posed by AI agents within the board’s current understanding of organizational risks. When it comes to AI agents, those threats begin with the fact that such agents can make autonomous decisions, act on those decisions and perhaps become quite overzealous in the pursuit of their goals.
Just as in prior waves of outsourcing and automation, when AI agents are built to optimize certain processes or functions, they can cause unintended consequences elsewhere.
“Agents can act like super-aggressive interns trying to get the job done,” said Grant Thornton Forensic Advisory Services Partner Johnny Lee, who leads the firm’s Forensic Technology practice. “They may not come to the exercise knowing the permissible bounds of how to accomplish the stated goal.”
Recent news reports have described agents that have escaped from their ostensibly safe “sandboxes” to obtain unauthorized access to other sites to accomplish their objectives. Boards can play a critical role in oversight that can mitigate such risks, but to date, boards have a mixed record on AI oversight.
Just 52% of business leaders said their boards have established policies or governance expectations for AI, according to Grant Thornton’s AI Impact Survey. This statistic becomes more meaningful when juxtaposed with the finding that 74% of organizations are piloting, scaling or have fully implemented agentic AI. This seems to indicate that many organizations are experimenting with enterprise agentic AI without the corresponding guardrails needed to manage risk, at least at the board level.
Boards may need to play a larger oversight role as agentic AI adoption grows, but that oversight should not come at the expense of innovation. Enterprise agentic AI will yield the best results when boards encourage management to expand autonomy in proportion to demonstrated value, an articulated risk appetite and a commensurate control environment to achieve that value and manage those risks.
The good news for boards is that their time-tested governance principles apply to agentic AI. The board’s role remains unchanged: oversight without infringing on management’s operational responsibilities. Boards need to hold management accountable without interfering in its day-to-day activities, and they need to examine risk — both current and emergent.
The novelty of agentic AI as a governance phenomenon is that it requires boards to ask new questions to ensure that nonhuman agents behave in the best interests of the company. Agentic AI changes the governance equation because organizations are beginning to delegate authority to systems that can make decisions and take actions on the organization’s behalf. For boards, that raises a fundamental oversight question: How much authority should management delegate to an AI agent, under what conditions, and which specific human operator remains accountable for the outcome?
Identifying risks isn’t just an IT job
Managing risks starts with a proper contemplation of them, a responsibility that shouldn’t be confined to the technicians alone (such as IT personnel and engineers building agents). The IT team may be well situated to identify technical obstacles and data concerns associated with agentic AI, but it might not understand the full implications of legal constraints, public- or vendor-relations issues, or operational risks associated with the agents they are creating.
A multidisciplinary team that also includes legal, finance, compliance, operations and communications leaders is needed to identify risks and to develop procedures to test for those identified risks. Once the risk universe is identified, controls need to be examined to determine whether there are gaps in the controls that manage the identified risks, especially those risks that are highly likely to occur and those with potentially severe implications.
Boards should ask management…
- Which organizational decisions are autonomous, human-in-the-loop, or human-approved — and who set the risk tiers for these decisions?
- Where are we deliberately keeping human judgment, even at the cost of speed?
When processes change, the risk assessment needs to be revisited to see if new risks have emerged or others have disappeared.
“The enterprise needs to keep that risk and control matrix current, and boards need to inquire of management as to how formal its risk assessment process is,” Lee said.
Boards can probe management’s processes by selecting an agentic AI use case within the enterprise at random and asking:
- How the introduction of that agent was assessed for new risks?
- How was the agent’s design modified to mitigate those risks?
- Which control activities were added or adjusted to address those risks; and
- How frequently will management revisit its risk assessment for that agent, or more completely, for the process that agent supports?
“Is this risk assessment part of a regimented enterprise risk management rotation, or is it something novel that management never intends to repeat?” Lee said. “The way that management provides those answers will tell the board a lot about the maturity and sophistication of the risk assessment exercise — including how circumspect management was in contemplating risks adjacent to the process or function supported by the agentic technology.”
Agentic AI also creates a need for boards to identify their own standard for when it is acceptable for humans to trust agents, or where machine authority begins, based on risk analysis. The answer won’t be the same for every company, every function or every agent, as each scenario will (and should) come with its own quotient of risk tolerance.
As a general proposition, it seems obvious that, as new risks are borne with agentic AI-related processes, the amount of human review and intervention needs to increase. Boards should remain attuned to the reality that the frenetic urge to create AI-related benefits can tempt management to place AI agents within arm’s reach of sensitive data and/or mission-critical processes, with little human oversight.
That’s why board governance is so critical.
How we can help you
SERVICE
SERVICE
Autonomous systems require continuous monitoring
Boards need to make clear to management that casual review of agents is no longer sufficient when AI agents can make decisions and act on behalf of the enterprise thousands of times per day.
As the speed of decision-making increases with AI agents, the controls that monitor them need to increase in sophistication. Fortunately, this is an area where AI and automation can assist by triggering alerts or dashboard notifications to prompt human intervention when agents go awry. This is where boards can insist that management explain how they will detect something if they can’t necessarily prevent it from happening.
But when AI is monitoring AI, the need for human oversight of these detective controls only intensifies. And even with that oversight, there’s potential for something to go wrong.
Boards need to understand what will happen if something does go wrong with AI agents. In addition to asking management about the real-time capabilities of preventive and detective
controls, boards need to ascertain management’s plan for responding to any crisis that might arise when an agent goes rogue.
Boards should ask management…
- How do we monitor agents in real time, and what triggers a kill switch?
- Do we have a tested incident response playbook for AI failures?
“Many of these agents are doing some pretty liberated tasks for a robot,” Lee said. “So you need to prepare for what could happen on the worst possible day. Who will you call? It’s not at all overengineered to conduct tabletop exercises for these high-risk scenarios, in the same fashion that you would for an adverse cyber event.
Indeed, boards should be inquiring as to which AI use cases are receiving such attention. Which use cases have a formal response plan? Does such a response plan bolt onto the existing cyber response plan, the disaster recovery plan, and possibly the strategic communications plan, or potentially all of these, depending on how catastrophic the scenario might be.”
Fortunately, organizations have experience with this type of scenario planning based on the possibility of cybersecurity breaches or natural disasters. But most don’t have a practiced plan for catastrophes that could be created by AI.
Only 20% of business leaders said in our AI Impact Survey that their organization has an AI-specific incident response playbook with defined owners that has been tested through tabletop exercises. The board should have some visibility into this, namely the level of planning and risk analysis that management has contemplated for its most impactful agentic AI scenarios. The potential for agents to cause serious harm should motivate boards to make sure that management has a well-practiced and prepared response.
Accountability and traceability should be verified
If an AI agent does create a crisis, the board and management will want to know:
- What happened?
- Why did it happen?
- Who is responsible?
- How can we prevent it from happening again?
Boards should ask management…
- How do we monitor agents in real time, and what triggers a kill switch?
- Do we have a tested incident response playbook for AI failures?
The answers to these questions require accountability and traceability, which are essential to strong AI governance but are lacking at many organizations. A mere 22% of our AI Impact Survey respondents were very confident that their organization could pass an independent audit of AI governance and controls within the next 90 days.
To nudge organizations in the right direction, boards can ask management what it has done to identify risks beyond quality and accuracy, and whether it has employed a multidisciplinary team to identify liabilities. Accountability and traceability require a strong commitment to documentation of these risks as well as ownership and the process used to create agents.
“This is easy when the sandbox is confined and the sources are known,” Lee said. “It gets more complicated when you start to bolt together an agent that accomplishes one task then hands off to another agent. But it’s important to be able to take a process, deconstruct it into its constituent parts, identify risks associated with each part, then contemplate what could go wrong at each turn.”
This deconstruction exercise helps prevent catastrophes, but it also provides a roadmap for postmortem remediation in the event that a crisis occurs.
Vigilance is essential for third-party risks
Boards need to understand the risks that are being created as both AI agents and third-party vendors are being given unprecedented access and permissions to systems and data.
Best practices require that application programming interfaces (APIs) or other data-access architectures be provisioned to provide specific permissions to access data and systems. Given the rapidity with which agentic workflows are created, it’s often difficult to determine whether agents are being given improper permissions or whether vendor behaviors have changed.
Boards should ask management…
- To which tools and data does each agent have access, and do we apply least privilege with review?
- Do vendor agents meet the same governance standard as the agents we build?
“If monitoring those permissions on a continuous basis is not part of your vendor management, it should be,” Lee said.
In many cases, a thorough review of vendor agreements also is needed to identify whether risks related to third-party agents are being properly mitigated.
“If your maximum recovery from a vendor is $2 million and they are exposing you to a $20 million risk, you have indemnification, but it’s not terribly meaningful,” Lee said.
By the same token, if a vendor is a $2 million company that is exposing you to $20 million in risk, you might need to consider a new vendor, as a $20 million liability would bankrupt them — assuming you could prevail in a lengthy dispute. With that in mind, boards may wish to ask management to revisit third-party vendors and prioritize those with good insurance, a reputation for providing notice about incidents quickly, cooperating with investigations and that are likely to be in business five years from now.
In addition, if your vendor contracts don’t address the third party’s ability to access or safeguard private organizational data, this might be time to re-examine those contracts.
All these issues should be approached again by a multidisciplinary team whose breadth of perspectives can eliminate blind spots related to third-party risk analysis.
Effective governance doesn’t require technical mastery
The emergence of AI agents should strengthen board members’ resolve to keep a close watch over management’s decisions.
Board members can still provide effective governance over agentic AI processes, even if they don’t possess the technical proficiency to construct (or deconstruct) an agent on their own. That said, it helps if board members are familiar with the broad concepts related to agentic AI. They need to understand that agents’ biggest risks include the overzealous pursuit of their goals, third-party vendor risks and data-access risks. They also need to know that accountability and traceability are essential.
Directors need to know the level of authority that management has given agentic AI, why that authority is appropriate, who remains accountable for its actions and what evidence exists (and can be provided to the board) that demonstrates that it is operating within the organization’s risk appetite.
Proper governance can give management confidence to expand agent autonomy where the potential value warrants it and to constrain that autonomy where the consequences of failure are too great. For boards, that is the emerging challenge of agentic AI: enabling innovation without delegating accountability to nonhuman actors.
When boards thoughtfully apply their time-honored, traditional oversight principles to these risks, they will ask the right questions about agentic AI.
In turn, properly governed agentic AI can be an asset that creates considerable value for the organization without creating unnecessary risk.
For more information on board governance over AI, stay tuned for upcoming summaries of Grant Thornton’s presentation on this topic at the NACD Directors Summit.
Content disclaimer
This Grant Thornton Advisors LLC content provides information and comments on current issues and developments. It is not a comprehensive analysis of the subject matter covered. It is not, and should not be construed as, accounting, legal, tax, or professional advice provided by Grant Thornton Advisors LLC. All relevant facts and circumstances, including the pertinent authoritative literature, need to be considered to arrive at conclusions that comply with matters addressed in this content.
Grant Thornton Advisors LLC and its subsidiary entities are not licensed CPA firms.
For additional information on topics covered in this content, contact a Grant Thornton Advisors LLC professional.
Share with your network
Share