Tuesday, September 15, 2026 AboutContact
Tech

Enterprise Data Rules Assume a Human Makes the Final Call, and That Assumption Has Broken

AI agents are already drafting communications, updating customer records and approving transactions inside large organisations, under governance written for people.

By Simone Bassett· September 11, 2026· 3 min read
Enterprise Data Rules Assume a Human Makes the Final Call, and That Assumption Has Broken
Photo Courtesy: Getty Images · source

Every large organisation has rules about its data: who can reach it, how it may be used, what happens when something goes wrong. For as long as those rules have existed they have rested on one assumption, which is that a human being makes the final decision.

Richard Clough, global chief data officer at EY, argues that the assumption has now been overtaken by what is already running in production.

AI agents are software systems that carry out tasks on behalf of people, sometimes entirely autonomously, sometimes alongside a swarm of other agents. Inside enterprise environments they are already drafting communications, updating customer records, approving routine transactions and generating reports that go to external audiences. In many cases nobody reviews the output first.

The governance was written for a different user

The problem is not that the old rules are wrong. It is that they were written when the primary user of enterprise data was a person.

Traditional data governance was built around a human in the loop. People made decisions drawing on customer systems, financial records, supply chain platforms and HR data, and the frameworks existed to certify that the data was accurate, appropriately permissioned and traceable if questions were asked later.

When an agent takes that seat, the framework is exposed. Humans and agents both make mistakes. The difference is that the audit machinery was designed around human users, so without deliberate tooling an organisation can simply lose sight of what an agent did, on data it should have been able to track and audit just as rigorously.

The safeguards are only as reliable as the governance rules they have been given to apply

Safeguards exist, and they inherit the same weakness

It is entirely possible to build an agent that flags uncertainty, pauses before acting on ambiguous data, or escalates to a person when its confidence is low. Clough is clear that this is a solved design problem.

It is also clear about the catch. Doing any of it requires deliberate governance choices that most organisations have not yet made, and even an agent built with those safeguards is only as reliable as the governance rules it has been handed to apply.

Where the underlying rules are vague, the safeguard inherits the vagueness. An agent instructed to escalate when data is ambiguous needs a definition of ambiguous that somebody wrote down.

The delegation has already happened outside work

The corporate question is arriving late, because consumers have already moved.

Research conducted by EY found that 16 per cent of people globally report delegating to AI systems that act on their behalf without human intervention. That is not a survey about attitudes to a future technology. It is a description of current behaviour.

The detail is more striking than the headline number. Ten per cent have used an agent to buy products for them. Eleven per cent allow AI to manage purchases and refill shopping carts automatically. Eleven per cent have let an agent carry out banking and financial tasks without their direct input. Nine per cent have travelled in a self-driving vehicle.

People are handing over purchasing and banking decisions at roughly the rate they are handing over their physical safety.

Why this cannot be sequenced later

The instinct in most large organisations will be to deploy first and formalise the governance afterwards, on the grounds that the technology is moving quickly and the rules can catch up.

That ordering works for tools. It does not work for actors.

A tool produces an output that a person then decides to use, and the decision point is where accountability attaches. An agent that approves a transaction has already acted, and if no record exists of what data it relied on or why it proceeded, there is nothing to review when the question arrives. The governance gap does not sit in the future. It sits in the logs that were never written.

For any organisation that wants to move quickly on AI without quietly accumulating risk, Clough's position is that the governance question is not one that can be deferred. The agents are already acting.