How to govern agentic AI in the enterprise

At PegaWorld, I had the opportunity to moderate a discussion with leaders from Navy Federal Credit Union, Achmea, and Blue Shield of California on a question many organizations are now wrestling with:

How do you move fast with Agentic AI without losing control?

One theme came through consistently: the organizations succeeding with agentic AI aren’t removing governance - they’re redesigning it.

Traditional governance models assume predictable workflows, fixed decision paths, and periodic review cycles. Agentic systems operate differently. They adapt, reason, and act at runtime. That means governance must shift from approvals and checkpoints to guardrails, observability, accountability, and shared ownership.

A few lessons that stood out:
:white_check_mark: Govern the platform and constraints, not every individual decision
:white_check_mark: Start with assistive use cases and earn trust through measurable outcomes
:white_check_mark: Treat AI agents as digital workers with identities, permissions, and accountability
:white_check_mark: Move from periodic compliance reporting to continuous visibility

The organizations moving fastest aren’t the ones with the fewest controls. They’re the ones that have embedded control directly into execution.

Curious how others are approaching governance as they move from AI assistants to truly agentic systems.

Read my full Pega Blog and let me know what you think!

Thank you for highlighting this! One of the biggest misconceptions about agentic AI is that governance can be relaxed as autonomy increases. In practice, the opposite is true.

As agents take on more complex tasks, organizations need stronger guardrails around accountability, observability, decision rights, and human oversight to maintain predictable outcomes.

This aligns closely with the principles I discussed in these two Blog Posts

Before You Deploy AI: The Predictability Checklist You Need | Pega

The AI Governance Checklist You Need Before You Scale | Pega

What I find particularly interesting is how governance is evolving from a review function into an operational capability.

How are other practitioners approaching this balance between increasing agent autonomy and maintaining enterprise-grade governance?