
For the past two years, enterprise AI governance has focused on a familiar question: can a human trust what a model produces? That framing assumes there is still a pause between output and consequence.
Agentic AI removes the pause. When a system can alter a customer record, approve a refund, route a payment, call an API or provision access, an error is no longer merely something to review. It becomes an action already taken. The risk has moved from content to execution.
That shift sits at the centre of Optro’s new report. Its headline finding is uncomfortable: one in three organisations already uses AI in critical resilience workflows, yet 30 per cent have never tested for agentic AI failure. Enterprises appear to have developed an appetite for autonomous execution before building the muscle to recover when autonomy goes wrong.
The confidence-control gap
The most revealing number is not an incident rate but a perception gap. While 58 per cent of leaders believe governance controls are keeping pace with AI adoption, only 18 per cent report active risk mitigations.
Over the previous 12 months, 40 per cent of organisations reported inaccurate AI outputs, 27 per cent data breaches and 26 per cent regulatory action tied to AI use. These figures do not prove that autonomous agents caused every outcome, but they do challenge the idea that written policies and oversight committees amount to operational control.
There is an important caveat. Optro combines findings from four surveys, totalling 1,928 risk, audit, compliance, security and resilience professionals across North America, the UK, Ireland, Germany and the UAE. The samples and questions differed, and no APAC market was represented. APAC leaders should therefore treat the findings as a warning signal, not as regional adoption or incident data.
The geographic gap is material, particularly for a region where regulatory maturity, digital infrastructure and enterprise risk practices vary widely.
Even with that limitation, the structural contradiction is hard to dismiss. A policy can tell an employee what not to do but it cannot interrupt an agent operating at machine speed. A quarterly control review can discover a pattern but it cannot reverse thousands of transactions already executed.
According to Optro’s general manager of AI governance Guru Sethupathy, governance models built for static manual processes cannot keep pace with autonomous systems of action. The issue is not simply more governance. It is governance that can operate at runtime.
Shadow AI is becoming shadow authority
Optro’s sharpest observation is that agents are non-human identities. They authenticate, inherit permissions, retrieve data and act across systems. The report says 85 per cent of organisations have integrated AI into core operations, but only a quarter have comprehensive visibility into how employees use it.
In a chatbot era, that gap produced shadow AI. In an agentic era, it produces shadow authority: software exercising corporate power without appearing on the organisation chart or, sometimes, in the asset inventory.
Every enterprise agent should therefore have a unique identity, a named owner, a stated purpose, tightly bounded permissions, transaction limits, an expiry date, a tamper-evident activity trail and a tested revocation path. This is not theoretical. The US National Institute of Standards and Technology’s AI Agent Standards Initiative is already prioritising agent authentication and identity infrastructure. Identity and access management, traditionally designed around employees, contractors and service accounts, now has to govern systems whose behaviour can change with context.
Accountability also cannot be reduced to placing a human somewhere in the loop. If one employee must approve hundreds of machine-generated actions per hour, oversight becomes ceremonial. Enterprises need to decide in advance which decisions require human approval, which can run within hard limits and which should never be delegated. They must also allocate responsibility across the model provider, agent platform, system integrator, business owner and data custodian before an incident; not negotiate it afterwards.
Why APAC cannot wait for harmonised rules
Singapore has moved early. Its updated Model AI Governance Framework for Agentic AI, published in May 2026, organises enterprise practice around four dimensions: bounding risks upfront, making humans meaningfully accountable, implementing technical controls and enabling end user responsibility. That approach reinforces Optro’s central thesis, but with an important practical emphasis: accountability must be designed into permissions, monitoring, testing and escalation, not declared in a policy after deployment.
For regional enterprises, the challenge is cross-border. An agent may be configured at a Singapore headquarters, invoke a service hosted elsewhere, process Australian customer data, support an Indian operation and affect a European customer. Meanwhile, the EU AI Act entered its general enforcement phase in August 2026, even as some high-risk system deadlines remain later. A fragmented set of jurisdiction-specific checklists will not follow the workflow. A durable evidence trail, spanning what the agent knew, what it accessed, what it did and who authorised it, can.
Governance only wins when it is executable
Optro argues that accountability can become a competitive advantage. That is plausible but only if governance is treated as infrastructure rather than paperwork. The winning control plane will combine a live inventory of agents, risk tiers, least-privilege access, continuous monitoring, pre-set spending or action limits, independent kill switches and resilience tests that simulate prompt injection, credential compromise, model drift and third-party tool failure.
Boards should ask for time-to-containment and time-to-evidence, not merely the number of AI policies approved.
In the agentic era, trust is not a sentiment attached to a model but an operational property of the surrounding system. The deeper divide will be between enterprises that can bound autonomous action and those that discover their limits through failure.












