ao link
Business Reporter
Business Reporter
Business Reporter
Search Business Report
My Account
Remember Login
My Account
Remember Login

Your AI agents may already be your biggest blind spot

Raj Koneru at Kore.ai explores a growing challenge many enterprises are overlooking as they accelerate AI agent adoption

Linked InXFacebook

Most large organisations can now tell you how many AI pilots they’re running. Far fewer can tell you how many AI agents are actually live across the business, what data each one can touch, or who is accountable when one gets a decision wrong. That gap between AI adoption and AI visibility is becoming one of the more pressing problems I hear about from CIOs and CISOs this year.

 

A McKinsey report, The state of AI in 2025: Agents, innovation, and transformation, found that almost two-thirds of organisations are now experimenting with AI agents, and nearly a quarter are scaling an agentic system somewhere in the enterprise. The technology works. The question keeping boards up at night is different: can we run hundreds of these agents responsibly?

 

 

Why agentic AI creates a different governance problem

Traditional enterprise software waits for a human to tell it what to do. AI agents don’t. They’re built to act autonomously, querying data, making judgements, taking action, often without a person in the loop at the moment of decision. At the same time, individual departments are standing up their own agents to solve their own problems, frequently with no central visibility into what’s been built, what it can access, or how it’s making decisions.

 

I’d call this the early stage of the next generation of shadow IT. Except this time, the "shadow" tools aren’t spreadsheets or unsanctioned SaaS subscriptions. They’re autonomous systems making decisions that can touch customers, money, and compliance.

 

Two examples make the stakes concrete. If a banking AI agent reviews a customer’s account history and recommends a loan decision, who is accountable if that decision is challenged months later? If a healthcare AI agent flags, or fails to flag, something during a patient interaction, who answers for a delayed diagnosis? These aren’t hypothetical edge cases. They’re the kind of scenarios already playing out as agents move from pilot into live operation, and in both cases, the real challenge isn’t the AI’s judgement. It’s the absence of a clear record of how that judgement was reached.

 

I’ll give you a pattern rather than a name, because the specifics change but the shape of the conversation doesn’t. One CISO told me his team only discovered they had three separate lending agents after a routine audit. Three teams had built nearly identical systems. None knew the others existed. No single team had done anything wrong. But that was the problem – every decision had been reasonable in isolation, and the business still had no way of seeing the whole picture until an audit forced the question.

 

 

What actually closes the gap

Closing this gap doesn’t mean slowing AI down. It means treating agents as enterprise infrastructure from day one, not as experiments that graduate into production unsupervised. In practice, that comes down to three shifts.

 

Standardise instead of decentralising. When every department builds and deploys agents its own way, no one, including the CISO, can answer basic questions about what exists. Agent development needs the same central standards as any other enterprise system.

 

Build visibility before scale, not after. Leaders need a real-time answer to what agents are running, what systems and data they touch, and how they’re performing. A quarterly audit that finds out after the fact isn’t enough.

 

Treat governance as architecture, not oversight. The organisations getting this right aren’t bolting compliance on top of finished agents. They’re logging, timestamping, and tracing every agent decision back to a specific control as a basic feature of how the system is built, the same way audit trails are a basic feature of financial systems, not an add-on.

 

 

The payoff isn’t just risk reduction

It’s tempting to file governance under "necessary cost," something that slows teams down in the name of caution. In regulated industries especially, I’d argue the opposite is true. When every agent action is traceable to a specific control, organisations spend less time relitigating what happened after the fact and more time deploying the next agent with confidence. Governance, done well, isn’t the brake on scale. It’s what makes scale possible without losing control of what’s actually happening inside the business.

 

Ultimately, organisations won’t struggle because they deployed too many AI agents. They’ll struggle if those agents become impossible to understand, govern and audit as they spread across the business. 

 

In the next phase of enterprise AI, the organisations that win won’t necessarily be those with the most agents. They’ll be the ones that know exactly what every agent is doing, who owns it, and can prove every decision it makes.

 


 

Raj Koneru is Founder and CEO of Kore.ai

 

Main image courtesy of iStockPhoto.com and tadamichi

Linked InXFacebook
Business Reporter

Winston House, 3rd Floor, Units 306-309, 2-4 Dollis Park, London, N3 1HF

23-29 Hendon Lane, London, N3 1RT

020 8349 4363

© 2025, Lyonsdown Limited. Business Reporter® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543