AI Agents Are Forcing a Rewrite of Enterprise Governance

The pattern is clear: the next software battleground is not only who builds the smartest model. It is who controls the agents that models unleash.

By Nivedita Sahor | Jul 17, 2026
.

Opinions expressed by Entrepreneur contributors are their own.

You're reading Entrepreneur India, an international franchise of Entrepreneur Media.

The enterprise software industry is moving toward a future in which AI does not simply assist work. It performs it.

That change is no longer theoretical. Microsoft has introduced Agent 365 as a control plane to govern and secure agents across the organization. ServiceNow is opening its system of action to AI agents that can move across enterprise workflows. IBM is positioning watsonx.governance as an assurance layer for AI oversight across hybrid, multi-vendor environments. Google’s Secure AI Framework, or SAIF, places AI security and risk management into a broader model for building and deploying AI responsibly.

The pattern is clear: the next software battleground is not only who builds the smartest model. It is who controls the agents that models unleash.

Agents are different from copilots and chatbots. A chatbot answers. A copilot assists. An agent can pursue a goal, retrieve context, call tools, interact with applications and initiate actions. In enterprise settings, that means agents may eventually touch service tickets, customer records, HR workflows, financial systems, security alerts, procurement approvals and software deployment pipelines.

That creates a new governance problem. Enterprises have spent decades assigning authority to humans and permissions to software. AI agents blur the two. They operate like software, but increasingly behave like delegated actors.

Gartner has warned that agent sprawl could become one of the next major enterprise control challenges. It predicts that by 2028, an average global Fortune 500 enterprise could have more than 150,000 agents in use, up from fewer than 15 in 2025. Gartner has also said only a small share of organizations believe they have adequate AI agent governance in place today.

That forecast should change how boards and CEOs think about AI adoption. A company would not hire 150,000 employees without role definitions, reporting lines, access controls, audit trails and termination procedures. Yet many organizations are moving toward agentic AI before they have equivalent structures for non-human actors.

This is not just a technology operations problem. It is an authority problem.

Who can create an agent? Who approves what the agent can do? Does the agent have its own identity, or does it act through a human user’s privileges? Can it access customer data? Can it write to systems of record? Can it trigger an external communication? Can it approve a transaction? Can it call another agent? Can it be suspended immediately?

These are no longer niche architectural questions. They are becoming boardroom questions because AI agents turn governance from a policy issue into a live operating risk.

Microsoft’s Agent 365 reflects this shift by positioning agent governance around visibility, security and observability. Salesforce describes Agentforce agents as autonomous systems that can use business knowledge to take action. ServiceNow has framed agents as part of enterprise workflows that can handle multistep work and resolve issues autonomously. IBM’s watsonx.governance emphasizes visibility, accountability and continuous oversight across AI systems

These offerings suggest where the market is heading. Enterprises are beginning to need a governance layer for AI agents that resembles identity management, risk management, security operations, compliance assurance and workforce oversight at the same time.

That is where EC-Council’s proprietary Adopt. Defend. Govern. AI Framework, or ADG, fits into the broader industry movement. ADG is not competing as another AI agent platform. It enters the market as an operating model for enterprises that need to decide how AI systems, including agents, are adopted, secured and governed before they scale.

The framework was developed with input from practitioners and advisory board members across organizations including Citi, JPMorgan Chase, Microsoft, KPMG, Deloitte, NTT Data, GE Healthcare, GlobalLogic, Prudential and Salesforce, according to EC-Council’s ADG launch announcement. That composition matters because agentic AI will not be governed by one team alone. Product, security, legal, risk, compliance and business leaders all have a stake in how much autonomy an agent should be allowed to exercise.

ADG’s relevance to agents lies in its architecture. Adopt focuses on the business case, use-case selection, architecture, deployment and operating model. Defend focuses on threat modeling, red-teaming, model and data integrity, runtime guardrails, detection and incident response. Govern focuses on decision rights, regulatory alignment, assurance, audit and board-level evidence. The ADG framework site also maps governance across nine surfaces: prompt, context, model, tools, orchestration, identity, safety layer, telemetry and learning loop.

For agents, those surfaces are not academic. They describe the places where control can break. A prompt can be manipulated. Context can be poisoned. Tool permissions can be too broad. Orchestration can create unexpected loops. Identity can be borrowed from a human account. Telemetry can be incomplete. A learning loop can drift without enough oversight.

The agent market is already showing signs of overreach. Reuters, citing Gartner, reported that more than 40% of agentic AI projects could be canceled by the end of 2027 because of rising costs, unclear business value and inadequate risk controls. That is not a rejection of agentic AI. It is a warning that autonomy without governance becomes expensive quickly.

The strongest enterprises will not treat agents as a feature toggle inside software platforms. They will create a management model for agents as a class of enterprise actor. That means unique identities, defined scopes, permission boundaries, audit logs, escalation paths, incident triggers, kill switches and clear ownership.

EC-Council’s ADG adds a useful layer to this shift because it connects the business need to deploy agents with the security need to break-test them and the boardroom need to govern them with evidence. Its AI Governance Council model is particularly relevant because agents create natural conflict inside organizations: business teams want speed, security teams want caution, legal teams want defensibility and boards want assurance.

The agent era will not be won by companies that deploy the most bots. It will be won by companies that know which agents deserve authority, which require restraint and which should never have reached production.

Enterprise governance was built for people, applications and data. AI agents are forcing it to make room for something else: autonomous actors that work inside the business, but cannot be trusted unless they are managed like risk-bearing participants in it.

The enterprise software industry is moving toward a future in which AI does not simply assist work. It performs it.

That change is no longer theoretical. Microsoft has introduced Agent 365 as a control plane to govern and secure agents across the organization. ServiceNow is opening its system of action to AI agents that can move across enterprise workflows. IBM is positioning watsonx.governance as an assurance layer for AI oversight across hybrid, multi-vendor environments. Google’s Secure AI Framework, or SAIF, places AI security and risk management into a broader model for building and deploying AI responsibly.

The pattern is clear: the next software battleground is not only who builds the smartest model. It is who controls the agents that models unleash.

Reports on emerging technologies, data-led enterprises, and the intersection of innovation and regulation.

Related Content