AI agent governance has become an operational question. Artificial intelligence now plays an operational role in companies. It reads email, accesses management systems, changes records in CRMs and ERPs, executes orders, sends notifications. It does so autonomously, often in the background, often without anyone having defined precisely what it can and cannot do.
This is the structural change crossing organisations in 2026, and most small Italian companies are facing it without having recognised it as such.
A number worth keeping in mind
According to December 2025 ISTAT data, Italian companies with at least ten employees that report using at least one artificial intelligence technology went from 8.2% to 16.4% in twelve months. A clean doubling. This acceleration is outpacing the ability of organisations to define adequate operating rules for the new tools they have adopted.
IBM, in its cybersecurity forecast for 2026, found that 13% of companies have already reported a security incident directly linked to AI use. Among those affected, 97% identified the main cause as the lack of controls over AI agent access. The root cause is simple: nobody had established what that agent could touch.
What business AI agents concretely are
An AI agent is a software system that, given a goal, plans a sequence of actions and executes them using real tools: it reads and writes files, queries databases, interacts with external applications, sends communications. Unlike a traditional program, it decides autonomously how to reach the result, without following a fixed flow.
Enterprise platforms have already normalised this. SAP presented its Autonomous Enterprise framework, in which specialised agents manage finance, supply chain and human resources processes autonomously. ServiceNow made its platform headless: agents can execute workflows directly over protocol, without going through any human interface. Microsoft launched Agent 365, which assigns each AI agent a unique digital identity — a badge — and tracks every action it takes inside the organisation.
These are products in commercial distribution today.
The problem nobody names: the agent's identity
When an employee logs into the management system, they use their credentials. They leave traces. They operate within defined permissions. If they do something unusual, there is a log, a responsibility, a physical person behind the action.
An AI agent works differently. It often uses shared access tokens, inherits the permissions of the user who activated it, or is configured with broad privileges so that it works well — without anyone having assessed the real perimeter of what it can reach. The result is that an agent built to automate handling customer requests can, in principle, access the entire company address book, read accounting documents or send communications in the company's name.
This is the default configuration of most tools on the market today, because ease of setup is a competitive advantage for whoever sells them.
Ungoverned proliferation: a problem already present in SMEs
The phenomenon large organisations' IT teams call AI sprawl — the uncontrolled multiplication of AI agents and tools inside a company — hits small businesses hard too, where the roles meant to govern it are missing.
A sales manager activates an AI agent to handle quote follow-ups. An administrative office integrates an AI tool with invoicing software. Another function connects an AI assistant to the shared email inbox. Each of these integrations, taken alone, can look reasonable. Together, without a map of who accesses what, they are an unmapped risk surface.
Applying to automatic agents the same principle valid for any collaborator — define permissions before assigning responsibilities — is the starting point of any sensible governance.
What a minimal governance requires
Precise questions need answers for every AI agent active in the company. With which credentials does it operate? Inherited from a human user, or its own? Who authorised access to the systems it uses? Is there a log of the actions it performs, and who reads it? What happens if that agent is compromised or starts behaving abnormally? Who has the ability to deactivate it?
These are corporate governance questions that require a deliberate decision by the people leading the organisation, regardless of the software vendor.
The signal large companies have already absorbed
The fact that Microsoft, SAP and ServiceNow launched, within months, products explicitly dedicated to controlling AI agents answers a real question that emerged from their enterprise customers' experience: AI agents without governance create exposures that traditional security systems struggle to detect.
In large organisations these tools come with dedicated budgets and specialised teams. In smaller companies the same problem arrives anyway — often through native integrations in platforms already in use, activated with one click — but the structure to manage it has to be built deliberately.
The exposure is comparable. The difference lies in the ability to recognise it before it becomes an incident.
Governance only makes sense against a concrete map, and the risks of automating business processes are the starting point.
Have a project in mind?
Do you know where to start?
The goal is to pin down the problem, the priorities and the timing.
Book a first callFrequently asked questions
What are business AI agents?
Business AI agents are software systems that, given a goal, plan and execute sequences of real actions autonomously: they access databases, send communications, change records in management systems and interact with other applications. Unlike traditional programs, they decide autonomously how to reach the result without following a predefined flow.
What are the risks of AI agents in business processes?
The main risk concerns access management: many AI agents operate with shared tokens or privileges inherited from the user who activated them, without a defined perimeter. This can let an agent access data far beyond its stated purpose. According to IBM, 97% of companies that suffered AI-related security incidents identified the lack of access controls as the main cause.
How do you control AI agent governance in a company?
A minimal AI agent governance requires answering precise questions for each active agent: with which credentials it operates, who authorised access to the systems it uses, whether there is a log of actions and who monitors it, and who can deactivate it if it behaves abnormally. These are organisational decisions, not exclusively technical ones.
Sources
ISTAT — enterprises and ICT, December 2025 data on artificial intelligence use: https://www.istat.it/it/archivio/imprese
IBM — X-Force Threat Intelligence Index 2026, cybersecurity forecast: https://www.ibm.com/reports/threat-intelligence
SAP — Autonomous Enterprise framework: https://www.sap.com/products/artificial-intelligence.html
Microsoft — Agent 365 and agent identity: https://www.microsoft.com/en-us/microsoft-365
ServiceNow — AI agents platform: https://www.servicenow.com/products/ai-agents.html