.jpg)
A POINT OF VIEW
Governing Agents Isn't a New Discipline: It's Re-Tooling the One You Already Have
The framework for governance doesn't change when you add agents. The measurement tools do — and that gap is where most enterprises are quietly getting stuck.
Written by: Jason Talley, Managing Director Launch Consulting
The first time you stand up an autonomous agent with real access to production systems, your instinct might be to write a new governance policy. You assume that a new risk category demands a new rulebook. This instinct feels safe. In our experience, agents don’t demand a new discipline. It’s really the oldest discipline in management — governing actors whose behavior you cannot fully predict — with exactly one difference that matters: the instruments that are used to govern human actors don’t apply to agents.
That reframe has become the most useful thing I can offer another leader who is anxious about agents in their business. You have spent your entire career governing non-deterministic actors. They are called people. The framework you use for them — ownership, performance, access, role definition, vendor oversight — is the framework for agents. What changes is not the questions you ask. It's the gauges you read to answer them.
This distinction is becoming one of the defining challenges of enterprise AI adoption. Organizations are racing to deploy copilots, autonomous agents, and intelligent workflows, but many are still managing them with operating models built for traditional software. The result isn't simply increased technical risk—it is slower adoption, inconsistent business outcomes, and growing hesitation from executive leadership. Governance, therefore, should not be viewed as a compliance exercise layered onto AI after deployment. It is one of the management capabilities that determines whether AI becomes an enterprise advantage or remains trapped in disconnected pilots that never produce measurable business value.
Walk into most enterprises today and you'll find the same scene. Leadership has convened a committee to draft an “AI agent policy.” They're waiting for a standard to arrive, a framework to descend, a vendor to tell them what good looks like. Meanwhile, three floors down, employees have already wired up agents to their email, their codebase, and their customer data — without asking. The governance conversation is happening in a room the actual risk left months ago.
The teams that stall are the ones trying to reinvent governance from first principles. The teams that move treat it as a re-tooling problem, because they already own the hard part. They have managed people for decades. They know how to assign accountability, measure performance, and control access. They are not starting from zero. They are swapping instruments on a machine they already know how to drive.
The organizations seeing the greatest return from AI are approaching governance differently. Rather than creating entirely new oversight structures, they are modernizing existing management disciplines so they can support autonomous systems operating at machine speed. That shift matters because AI transformation is fundamentally a management framework. The technology may be new, but sustainable business value comes from evolving how the enterprise manages work, accountability, and decision-making alongside it.
There's a trap waiting in that swap, and I've written about it before. When you put new gauges on the dashboard, the gauges themselves can become the goal. Harris and Tayler called it surrogation in Harvard Business Review — the moment a metric quietly replaces the strategy it was meant to represent. It is twice as dangerous with agents, because an agent will optimize relentlessly toward whatever you measure, with none of the judgment a person uses to know when the measure has stopped making sense.
When a measure becomes a target, it ceases to be a good measure. — Goodhart's Law
Across every successful enterprise, governance exists for a single purpose: enabling people—and increasingly intelligent systems—to make decisions that advance the business while appropriately managing risk. That objective has not changed with the arrival of AI agents. What changes is how organizations measure, observe, and govern autonomous behavior that can scale far beyond any individual employee.
Strip away the technology and every well-run team rests on five principles. Every person has an manager who is accountable for them. That manager sets goals and reviews performance. You govern what people can access rather than scripting their every move. You write the role down, and you keep watch on the contractors and vendors you depend on. Point those same five principles at an agent and not one of them breaks. Every agent needs a named owner, objectives and monitoring, scoped access, a written role, and continuous vendor oversight. The framework is portable. Hold onto it — it's the part you don't have to invent.
Here is where the work actually lives. The principles transfer cleanly; the instruments do not. An agent is not a person, and the tools we built to measure people quietly assume things — memory, judgment, a conscience, a calendar — that an agent does not have. Five gauges have to change.
1. From the Org Chart to the Agent Registry
The principle: every actor has an accountable owner.
For people, HR maintains an org chart and everyone has a manager of record. For agents, that instrument becomes a live inventory — an agent registry with a named human owner attached to every entry. The change is one of cadence and discovery: an agent can be stood up in minutes by anyone with a login, so the “org chart” has to be discovered continuously, not refreshed once a year. Most enterprises I talk to cannot name the agents running in their business this morning.
For executive leadership, this visibility becomes the foundation for every other governance decision. Organizations cannot evaluate risk, prioritize investments, or measure business value from systems they cannot inventory. Just as finance requires an accurate balance sheet before making capital allocation decisions, enterprise AI requires a living inventory of autonomous actors before it can be governed effectively.
And the owner is always a human. Air Canada learned this in a tribunal that held the airline liable for its chatbot's wrong answer. You do not get to disclaim an actor you deployed.
2. From the Annual Review to Continuous Evaluation
The principle: owners measure performance.
For people, you can wait for a quarterly cycle, a self-assessment, and an honest conversation. An agent cannot sit for a review, cannot tell you truthfully how it's doing, and can drift overnight when the model beneath it updates. So the instrument becomes an eval suite, behavioral regression tests, and drift monitors that run on their own, and the cadence collapses from quarterly to continuous. You are still asking the same question — is this performing — but you answer it with telemetry instead of a one-on-one.
This continuous visibility also changes how executives evaluate AI investments. Rather than relying on anecdotal success stories, leadership teams gain objective evidence of whether agents are improving productivity, accelerating workflows, reducing operational costs, or introducing new risks. Governance becomes a source of business intelligence—not simply operational oversight.
Just remember Goodhart on the way in: the eval score is a proxy, not the point.
3. From Trust-but-Verify to Least Privilege
The principle: manage access, not every action.
With a trusted employee you extend latitude and verify later, because a person has judgment and bears accountability for their choices. An agent has neither. It will follow a malicious instruction buried in a web page or an email as readily as a legitimate one — what Simon Willison named the lethal trifecta: private data, untrusted input, and a way to act, all at once. So the instrument shifts from an HR policy and good faith to least-privilege, just-in-time, scoped credentials enforced by the system itself. You would never give a new hire root access to production on day one and then never check in. Yet teams hand agents broad tokens and no monitoring every day. That is precisely how an AI coding agent deleted a live production database during a code freeze. The principle was sound. The instrument was missing.
Organizations often assume governance slows innovation. In practice, the opposite is true. When security, access controls, and accountability are designed into the operating model from the beginning, leaders gain the confidence to deploy AI more broadly across the enterprise. Strong governance becomes an accelerator because it reduces uncertainty around scale.
4. From the Job Description to the Versioned Spec
The principle: write the role down.
For people, a job description and an SOP, read on day one and revisited rarely. For agents, a versioned spec: the one job and what “done” means, the hard constraints it must never cross even if asked, the tools and scopes it may use, the identity it acts as, and the data it may touch. The difference is that a job description is read; a spec is executed, every single run. Capture it once, then track against it forever.
Standardized specifications also make enterprise AI repeatable. Instead of rebuilding governance for every new use case, organizations establish reusable patterns that allow successful agent deployments to scale across business functions with greater consistency and significantly less operational friction.
Write this down with discipline and a surprising share of the incidents that make headlines simply become impossible.
5. From the Annual Vendor Review to the Continuous Supply Chain
The principle: watch your third parties.
You review contractors and vendors on a cycle — annually, at renewal, when something breaks. The models and tools underneath an agent change weekly, sometimes silently. So vendor oversight becomes continuous version monitoring, and the supply-chain risk is arguably higher than with any contractor you've ever hired, because a model you didn't choose to change can change the behavior of every agent built on it overnight.
As enterprises increasingly depend on foundation models, APIs, and external AI services, governance extends beyond internal technology teams. Executive oversight now includes understanding how external changes affect business operations, customer experiences, compliance obligations, and enterprise risk. AI supply chains deserve the same executive visibility organizations already expect from their physical and digital supply chains.
The organizations that succeed won't necessarily build better agents—they'll build better systems for governing them.
I want to be careful not to oversell the comparison, because it breaks in exactly the places that should make you tighten the controls, not loosen them. An employee scales linearly and carries judgment, context, and accountability. An agent scales instantly, carries none of those, and answers for nothing. A bad hire damages one team. A bad agent — over-permissioned, unmonitored, and fast — can damage everything it can reach, at machine speed, before anyone is in the room to notice. The reframe is freeing because it means you don't have to invent a philosophy of machine oversight before you can act. It is not freeing in the sense of letting you skip the instruments. You get to skip the existential debate. You do not get to skip the gauges.
This is why Launch views governance as an enabler of enterprise AI—not a barrier to it. Organizations that embed governance into their operating model move faster because they spend less time reacting to preventable failures. They can expand AI into higher-value workflows with greater confidence, knowing accountability and oversight have already been designed into the system.
The companies that will struggle with agents are not the ones with the least technology. Kodak invented the digital camera. Blockbuster could have bought Netflix. Neither failed for lack of capability; they failed because they kept reading a changed world with yesterday's instruments. The same trap is open right now, and it looks like a governance committee measuring agents with an org chart and an annual review.
The greatest danger in times of turbulence is not the turbulence — it is to act with yesterday's logic. — Peter Drucker
For executives, the goal is not to create another governance committee or produce another policy document. It is to establish enough operational discipline that AI can expand safely as adoption accelerates. Organizations that begin with visibility, accountability, and measurable performance create a foundation that supports long-term AI scale rather than repeatedly pausing innovation to address preventable governance issues.
None of this requires a platform purchase or a new policy binder to begin. It requires four moves, in order.
Crisis of the Wrong Instrument
You already know how to govern unpredictable actors. You've done it your whole career. Govern your agents like the workforce they have quietly become. Keep the principles. Change the gauges.
The organizations that realize the greatest business value from AI will not necessarily be the ones deploying the largest number of agents. They will be the ones that build the management systems capable of governing those agents at enterprise scale. Trust, accountability, and measurable performance are not obstacles to innovation—they are prerequisites for sustained adoption.
From our work with enterprise organizations, we've seen that successful AI transformations rarely fail because the technology isn't capable. They stall because enterprise management systems fail to evolve alongside it. Governance is one of the clearest examples of that reality. Leaders who modernize their governance capabilities now will be positioned to expand AI confidently across the enterprise. Those relying on yesterday's management systems will continue struggling to move beyond isolated pilots and incremental wins.
So I'll leave you with the question I keep asking executive teams: Which governance instrument is your organization missing first—the inventory, the evaluation, or the controls that allow you to scale AI with confidence?
A POINT OF VIEW
Governing Agents Isn't a New Discipline: It's Re-Tooling the One You Already Have
The framework for governance doesn't change when you add agents. The measurement tools do — and that gap is where most enterprises are quietly getting stuck.
Written by: Jason Talley, Managing Director Launch Consulting
The first time you stand up an autonomous agent with real access to production systems, your instinct might be to write a new governance policy. You assume that a new risk category demands a new rulebook. This instinct feels safe. In our experience, agents don’t demand a new discipline. It’s really the oldest discipline in management — governing actors whose behavior you cannot fully predict — with exactly one difference that matters: the instruments that are used to govern human actors don’t apply to agents.
That reframe has become the most useful thing I can offer another leader who is anxious about agents in their business. You have spent your entire career governing non-deterministic actors. They are called people. The framework you use for them — ownership, performance, access, role definition, vendor oversight — is the framework for agents. What changes is not the questions you ask. It's the gauges you read to answer them.
This distinction is becoming one of the defining challenges of enterprise AI adoption. Organizations are racing to deploy copilots, autonomous agents, and intelligent workflows, but many are still managing them with operating models built for traditional software. The result isn't simply increased technical risk—it is slower adoption, inconsistent business outcomes, and growing hesitation from executive leadership. Governance, therefore, should not be viewed as a compliance exercise layered onto AI after deployment. It is one of the management capabilities that determines whether AI becomes an enterprise advantage or remains trapped in disconnected pilots that never produce measurable business value.
Walk into most enterprises today and you'll find the same scene. Leadership has convened a committee to draft an “AI agent policy.” They're waiting for a standard to arrive, a framework to descend, a vendor to tell them what good looks like. Meanwhile, three floors down, employees have already wired up agents to their email, their codebase, and their customer data — without asking. The governance conversation is happening in a room the actual risk left months ago.
The teams that stall are the ones trying to reinvent governance from first principles. The teams that move treat it as a re-tooling problem, because they already own the hard part. They have managed people for decades. They know how to assign accountability, measure performance, and control access. They are not starting from zero. They are swapping instruments on a machine they already know how to drive.
The organizations seeing the greatest return from AI are approaching governance differently. Rather than creating entirely new oversight structures, they are modernizing existing management disciplines so they can support autonomous systems operating at machine speed. That shift matters because AI transformation is fundamentally a management framework. The technology may be new, but sustainable business value comes from evolving how the enterprise manages work, accountability, and decision-making alongside it.
There's a trap waiting in that swap, and I've written about it before. When you put new gauges on the dashboard, the gauges themselves can become the goal. Harris and Tayler called it surrogation in Harvard Business Review — the moment a metric quietly replaces the strategy it was meant to represent. It is twice as dangerous with agents, because an agent will optimize relentlessly toward whatever you measure, with none of the judgment a person uses to know when the measure has stopped making sense.
When a measure becomes a target, it ceases to be a good measure. — Goodhart's Law
Across every successful enterprise, governance exists for a single purpose: enabling people—and increasingly intelligent systems—to make decisions that advance the business while appropriately managing risk. That objective has not changed with the arrival of AI agents. What changes is how organizations measure, observe, and govern autonomous behavior that can scale far beyond any individual employee.
Strip away the technology and every well-run team rests on five principles. Every person has an manager who is accountable for them. That manager sets goals and reviews performance. You govern what people can access rather than scripting their every move. You write the role down, and you keep watch on the contractors and vendors you depend on. Point those same five principles at an agent and not one of them breaks. Every agent needs a named owner, objectives and monitoring, scoped access, a written role, and continuous vendor oversight. The framework is portable. Hold onto it — it's the part you don't have to invent.
Here is where the work actually lives. The principles transfer cleanly; the instruments do not. An agent is not a person, and the tools we built to measure people quietly assume things — memory, judgment, a conscience, a calendar — that an agent does not have. Five gauges have to change.
1. From the Org Chart to the Agent Registry
The principle: every actor has an accountable owner.
For people, HR maintains an org chart and everyone has a manager of record. For agents, that instrument becomes a live inventory — an agent registry with a named human owner attached to every entry. The change is one of cadence and discovery: an agent can be stood up in minutes by anyone with a login, so the “org chart” has to be discovered continuously, not refreshed once a year. Most enterprises I talk to cannot name the agents running in their business this morning.
For executive leadership, this visibility becomes the foundation for every other governance decision. Organizations cannot evaluate risk, prioritize investments, or measure business value from systems they cannot inventory. Just as finance requires an accurate balance sheet before making capital allocation decisions, enterprise AI requires a living inventory of autonomous actors before it can be governed effectively.
And the owner is always a human. Air Canada learned this in a tribunal that held the airline liable for its chatbot's wrong answer. You do not get to disclaim an actor you deployed.
2. From the Annual Review to Continuous Evaluation
The principle: owners measure performance.
For people, you can wait for a quarterly cycle, a self-assessment, and an honest conversation. An agent cannot sit for a review, cannot tell you truthfully how it's doing, and can drift overnight when the model beneath it updates. So the instrument becomes an eval suite, behavioral regression tests, and drift monitors that run on their own, and the cadence collapses from quarterly to continuous. You are still asking the same question — is this performing — but you answer it with telemetry instead of a one-on-one.
This continuous visibility also changes how executives evaluate AI investments. Rather than relying on anecdotal success stories, leadership teams gain objective evidence of whether agents are improving productivity, accelerating workflows, reducing operational costs, or introducing new risks. Governance becomes a source of business intelligence—not simply operational oversight.
Just remember Goodhart on the way in: the eval score is a proxy, not the point.
3. From Trust-but-Verify to Least Privilege
The principle: manage access, not every action.
With a trusted employee you extend latitude and verify later, because a person has judgment and bears accountability for their choices. An agent has neither. It will follow a malicious instruction buried in a web page or an email as readily as a legitimate one — what Simon Willison named the lethal trifecta: private data, untrusted input, and a way to act, all at once. So the instrument shifts from an HR policy and good faith to least-privilege, just-in-time, scoped credentials enforced by the system itself. You would never give a new hire root access to production on day one and then never check in. Yet teams hand agents broad tokens and no monitoring every day. That is precisely how an AI coding agent deleted a live production database during a code freeze. The principle was sound. The instrument was missing.
Organizations often assume governance slows innovation. In practice, the opposite is true. When security, access controls, and accountability are designed into the operating model from the beginning, leaders gain the confidence to deploy AI more broadly across the enterprise. Strong governance becomes an accelerator because it reduces uncertainty around scale.
4. From the Job Description to the Versioned Spec
The principle: write the role down.
For people, a job description and an SOP, read on day one and revisited rarely. For agents, a versioned spec: the one job and what “done” means, the hard constraints it must never cross even if asked, the tools and scopes it may use, the identity it acts as, and the data it may touch. The difference is that a job description is read; a spec is executed, every single run. Capture it once, then track against it forever.
Standardized specifications also make enterprise AI repeatable. Instead of rebuilding governance for every new use case, organizations establish reusable patterns that allow successful agent deployments to scale across business functions with greater consistency and significantly less operational friction.
Write this down with discipline and a surprising share of the incidents that make headlines simply become impossible.
5. From the Annual Vendor Review to the Continuous Supply Chain
The principle: watch your third parties.
You review contractors and vendors on a cycle — annually, at renewal, when something breaks. The models and tools underneath an agent change weekly, sometimes silently. So vendor oversight becomes continuous version monitoring, and the supply-chain risk is arguably higher than with any contractor you've ever hired, because a model you didn't choose to change can change the behavior of every agent built on it overnight.
As enterprises increasingly depend on foundation models, APIs, and external AI services, governance extends beyond internal technology teams. Executive oversight now includes understanding how external changes affect business operations, customer experiences, compliance obligations, and enterprise risk. AI supply chains deserve the same executive visibility organizations already expect from their physical and digital supply chains.
The organizations that succeed won't necessarily build better agents—they'll build better systems for governing them.
I want to be careful not to oversell the comparison, because it breaks in exactly the places that should make you tighten the controls, not loosen them. An employee scales linearly and carries judgment, context, and accountability. An agent scales instantly, carries none of those, and answers for nothing. A bad hire damages one team. A bad agent — over-permissioned, unmonitored, and fast — can damage everything it can reach, at machine speed, before anyone is in the room to notice. The reframe is freeing because it means you don't have to invent a philosophy of machine oversight before you can act. It is not freeing in the sense of letting you skip the instruments. You get to skip the existential debate. You do not get to skip the gauges.
This is why Launch views governance as an enabler of enterprise AI—not a barrier to it. Organizations that embed governance into their operating model move faster because they spend less time reacting to preventable failures. They can expand AI into higher-value workflows with greater confidence, knowing accountability and oversight have already been designed into the system.
The companies that will struggle with agents are not the ones with the least technology. Kodak invented the digital camera. Blockbuster could have bought Netflix. Neither failed for lack of capability; they failed because they kept reading a changed world with yesterday's instruments. The same trap is open right now, and it looks like a governance committee measuring agents with an org chart and an annual review.
The greatest danger in times of turbulence is not the turbulence — it is to act with yesterday's logic. — Peter Drucker
For executives, the goal is not to create another governance committee or produce another policy document. It is to establish enough operational discipline that AI can expand safely as adoption accelerates. Organizations that begin with visibility, accountability, and measurable performance create a foundation that supports long-term AI scale rather than repeatedly pausing innovation to address preventable governance issues.
None of this requires a platform purchase or a new policy binder to begin. It requires four moves, in order.
Crisis of the Wrong Instrument
You already know how to govern unpredictable actors. You've done it your whole career. Govern your agents like the workforce they have quietly become. Keep the principles. Change the gauges.
The organizations that realize the greatest business value from AI will not necessarily be the ones deploying the largest number of agents. They will be the ones that build the management systems capable of governing those agents at enterprise scale. Trust, accountability, and measurable performance are not obstacles to innovation—they are prerequisites for sustained adoption.
From our work with enterprise organizations, we've seen that successful AI transformations rarely fail because the technology isn't capable. They stall because enterprise management systems fail to evolve alongside it. Governance is one of the clearest examples of that reality. Leaders who modernize their governance capabilities now will be positioned to expand AI confidently across the enterprise. Those relying on yesterday's management systems will continue struggling to move beyond isolated pilots and incremental wins.
So I'll leave you with the question I keep asking executive teams: Which governance instrument is your organization missing first—the inventory, the evaluation, or the controls that allow you to scale AI with confidence?