For the past few years, much of the conversation around artificial intelligence has focused on what AI can tell us. The next phase is about what AI can actually do.
AI agents are moving beyond generating text, summarising documents and answering questions. Increasingly, they can interact with business systems, execute multi-stage workflows, use software tools, retrieve and update information, and take actions on behalf of employees.
That represents a much bigger shift for enterprise technology.
Giving an employee an AI assistant is one thing. Giving an AI system permission to change a customer record, create a purchase order, update a product catalogue, contact a supplier or trigger another business process is something else entirely.
The opportunity is substantial, but so are the architectural and governance questions.
From AI assistants to AI agents
Traditional generative AI largely follows a simple pattern: a person asks a question and the system generates a response.
Agentic systems can go further.
An agent might be given an objective, determine the steps required to achieve it, interact with several systems and then execute some or all of those steps.
Consider an ecommerce business with millions of products.
Rather than asking AI to identify catalogue problems and handing the resulting report to a person, an agentic workflow could potentially:
- detect missing or inconsistent product data;
- identify the likely source of the problem;
- retrieve information from approved sources;
- propose or make corrections;
- send unusual cases for human review;
- update downstream systems;
- verify that the change has propagated correctly; and
- record what happened for audit purposes.
The important development isn’t necessarily better artificial intelligence. It’s connecting intelligence to action.
The enterprise becomes the environment
This changes how businesses should think about AI implementation.
A useful enterprise agent cannot operate effectively as an isolated chatbot. It needs controlled access to the systems where work actually happens: CRMs, ERPs, databases, product information systems, ticketing platforms, document repositories, communications tools and internal APIs.
That makes integration architecture increasingly important.
The quality of an agentic system will depend not only on the underlying AI model but on the quality of the environment surrounding it.
Businesses therefore need to understand which systems an agent can access, what information it can retrieve, which actions it can perform and under what circumstances it must stop and ask a human.
Permissions become critical
Identity and access management has always mattered in enterprise IT. Agentic AI makes it even more important.
An AI agent should rarely have unrestricted access simply because the employee using it has broad permissions.
Instead, organisations need to consider the principle of least privilege: giving an agent only the access necessary to complete a defined task.
A customer service agent might be allowed to retrieve an order and draft a refund recommendation, for example, without being permitted to issue an unlimited refund automatically.
A procurement agent might prepare purchase orders but require approval above a financial threshold.
The question changes from “Can the AI do this?” to “Under exactly what circumstances should the AI be allowed to do this?”
Human oversight should be designed, not assumed
There is a temptation to frame agentic AI as replacing humans in workflows. In many enterprise environments, the more practical objective will be deciding where humans add the most value.
Some processes can be highly automated. Others should contain deliberate checkpoints.
A useful framework is to divide actions into three broad categories: those an agent can execute automatically, those it can prepare but a person must approve, and those that should remain human-led.
The appropriate boundary depends on consequence rather than technical capability.
Updating a low-risk internal classification may reasonably happen automatically. Authorising a large payment, terminating an employee account or making a legally significant commitment demands a very different level of control.
Auditability matters
When software starts making decisions and taking actions across business systems, organisations need to be able to reconstruct what happened.
That means logging more than the final result.
Businesses may need records showing what information an agent accessed, which tools it used, what actions it attempted, what approvals were obtained and what ultimately changed.
This becomes particularly important when several agents or automated systems interact.
Without sufficient observability, an apparently simple automated workflow can become remarkably difficult to investigate when something goes wrong.
Where should businesses deploy agents first?
The most impressive demonstration is not necessarily the best production use case.
Businesses should look for processes that combine relatively high volumes of repetitive work with clear rules, accessible data and measurable outcomes.
Strong candidates can include product data management, internal research, document processing, customer service triage, sales administration, reporting, IT operations and selected finance or procurement workflows.
The objective should be solving an identifiable business problem rather than deploying an agent because the technology is available.
A process that currently consumes hundreds of employee hours each month is much easier to evaluate than a vague ambition to “become an agentic business”.
Start with the workflow, not the model
One of the biggest mistakes organisations can make is starting with an AI platform and then searching for somewhere to use it.
The better starting point is often the workflow.
Map what currently happens. Identify the systems involved. Understand where employees spend time, where delays occur, what decisions are made and what happens when something goes wrong.
Only then determine which elements should be automated.
In many cases, the resulting solution may combine conventional software automation, APIs, deterministic business rules and AI rather than relying on an autonomous agent for everything.
That is often a strength rather than a limitation.
The economics of agentic AI
Agentic systems also need to demonstrate economic value.
Running a model once to generate an answer is relatively straightforward. An agent that reasons repeatedly, queries several systems, invokes tools and checks its own work can create considerably more infrastructure and model usage.
At enterprise scale, those costs matter.
Businesses should therefore measure agentic systems against operational outcomes: time saved, throughput increased, errors reduced, response times improved or revenue generated.
The goal is not maximum autonomy. It is productive automation.
The agentic enterprise will still need people
The arrival of AI agents does not mean businesses suddenly become autonomous.
Instead, it changes where people sit within processes.
Employees may increasingly define objectives, review exceptions, approve consequential decisions and improve systems rather than manually performing every intermediate step.
Technology teams, meanwhile, will need to think beyond model selection towards integration, identity, security, observability, data architecture and governance.
That is why agentic AI is ultimately an enterprise architecture question as much as an artificial intelligence question.
From experimentation to infrastructure
The first wave of generative AI gave businesses an extraordinarily capable new interface for information.
The next wave connects that intelligence to the machinery of the organisation.
That is potentially much more valuable — and considerably more consequential.
The businesses that benefit most are unlikely to be those that simply deploy the greatest number of agents. They will be those that identify where autonomous action creates genuine value, establish clear permissions and safeguards, integrate AI properly with existing systems and retain human judgement where the consequences demand it.
The question for enterprise leaders is therefore no longer simply what AI can answer.
It is what they are prepared to let it do.
