Urgent.News

What's breaking now, across thousands of outlets.

AI

Deploying AI agents safely

Every South African enterprise needs a practical governance framework for safe, auditable agentic AI deployment.

Deploying AI agents safely

A staggering 95% of business leaders report negative impacts from enterprise AI implementation, with financial loss being the most frequent result. Agentic AI, capable of reading, writing, executing workflows and processing transactions under one broadly authorized identity, exacerbates these risks. However, safe deployment frameworks do exist, yet most organizations fail to utilize them.

In my experience consulting for telecommunications and financial services firms, the conversation around agentic AI follows a predictable trajectory. An executive initiates a proof of concept, technical teams construct agents with access to multiple systems, and governance/risk teams scrutinize the agent's capabilities. The issue typically lies not with the AI itself, but its architectural design.

These agents are often granted excessive permissions, lack meaningful boundaries, and operate without a systematic framework for determining appropriate autonomy based on the risk profile of their tasks.

KPMG's Q4 2025 AI Pulse Survey reveals that 65% of global enterprise leaders cite agentic system complexity as their primary deployment barrier, while 75% identify security, compliance and auditability as the most critical agent requirements. A common failure mode, dubbed the "super-agent," has emerged: an agent designed to handle all tasks, accessing customer data, updating records, sending communications, initiating transactions, and triggering downstream workflows under a single widely permitted identity.

This concept resembles granting every new employee master keys to every room in a building, expecting them to only open the necessary doors. The principle of least privilege in agent design is fundamentally a POPIA architecture requirement. Super-agents exhibit two structural flaws leading to governance failures: super-agency (unrestricted interaction with any system) and over-privilege (excessive access rights beyond those required for specific tasks).

These flaws render systems unpredictable, unauditable, and potentially non-compliant in regulated industries.

Research by Infosys in August 2025 indicates that 86% of executives acknowledge agentic AI as introducing additional risks and compliance challenges due to this dynamic. The impact of a misconfigured super-agent extends to the entire system it can reach, whereas a focused agent with least-privilege access impacts only one task. Governance decisions should be made during the design phase, not deployment phase.

The alternative to purposefully designed AI with clear boundaries is not reduced capability, but more tightly engineered AI.

My approach to agent design begins with the principle of high cohesion, borrowed from software engineering: each agent should focus on a single task, granted only the necessary access, and designed to seamlessly hand off to the next agent in a governed workflow. Rather than a single super-agent performing all tasks, a coordinated team of specialized agents, each executing a specific function, is preferable.

Agents are classified using a two-dimensional risk-capability quadrant. The first axis measures risk level - the potential damage if the agent behaves unexpectedly. Does it access sensitive or irreversible data? The second axis evaluates capability level - the degree of autonomous decision-making the agent requires. Does its behavior follow predetermined scripts or dynamically determine actions, tools and processes? Four distinct agent profiles emerge, each with unique governance requirements.

Low-capability, low-risk agents, such as knowledge base retrieval bots, can function like traditional software with persistent, static credentials and existing governance controls. High-capability, high-risk agents, like an accounts payable automation that analyzes financial data and initiates payments, require ephemeral design, dynamic access controls evaluated at each tool call, and mandatory human checkpoints before any consequential action.

Recent survey data confirms this framework is becoming standard practice: 60% of leading enterprises now restrict agent access to sensitive data without human oversight. South Africa's regulatory environment necessitates compliance with POPIA, which mandates purposeful, proportionate and accountable automated processing of personal data.

An agent with access beyond its specific task scope is non-compliant, regardless of whether it utilizes that access. The principle of least privilege in agent design aligns with POPIA requirements. A well-governed agentic architecture, complete with detailed audit trails documenting each agent's actions - the triggers, accessed data, and decisions made - is essential to meet these regulations.

Implementing this audit trail from the outset is not merely administrative overhead, but the difference between a deployable system and one confined to the proof-of-concept phase. Governance is not the brake, but the engine of safe agentic AI deployment.

Written by urgent.news from ITWeb's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at itweb.co.za →

More in AI

More from Thursday 27 August →