PwC says organisations moving towards agentic AI need to rethink governance on three fronts: who is accountable, how the operating model is structured, and how oversight continues after deployment.
The consultancy argues that early human-in-the-loop review remains useful for testing how agents behave in live conditions, checking outputs and preserving accountability. But it says that approach will not scale once the number, speed and complexity of agents rise. In its place, PwC...
Continue Reading This Article
Enjoy this article as well as all of our content, including reports, news, tips and more.
By registering or signing into your SRM Today account, you agree to SRM Today's Terms of Use and consent to the processing of your personal information as described in our Privacy Policy.
points to more distributed human responsibility, with each agent assigned a business owner and boards expected to oversee whether governance is effective. Executive teams, it says, should set ownership, escalation routes and decision rights rather than attempt to supervise every action directly.
That shift reflects a broader change already being discussed across the AI governance field. Berkeley’s Centre for Responsible, Decisive and Explainable Artificial Intelligence has argued that human-in-the-loop controls become unwieldy in high-volume environments, and that organisations need more proactive models for autonomous systems. Other commentators have likewise warned that governance designed for advisory AI does not cope well once systems can act, transact or invoke tools on their own.
PwC says one practical answer is to make agent activity easier for people to review. That means designing interfaces that show inputs, outputs, the path taken by the system and the rationale behind a recommendation. The firm also says organisations should maintain a minimum decision record covering the delegated objective, the action taken, evidence or reasoning, any exception flags, the accountable owner and the outcome of any escalation.
The second shift is operational. As agentic AI spreads, governance has to move in step with innovation and with the growing volume of machine-led activity. PwC says even cautious adopters need to understand the technology well enough to defend against cyber threats and other adversarial risks. It argues that autonomous systems should be observable, measurable and auditable throughout their lifecycle, with the same seriousness that firms apply to human workforces.
In practice, that means giving every agent a verified identity, a defined role, access limits and auditable logs. It also means tightening oversight as autonomy increases, especially where agents interact with customers, staff, sensitive data, financial decisions or regulatory obligations. McKinsey has described a similar direction of travel, suggesting that the emerging “agentic organisation” will need embedded guardrails and monitoring agents that watch other agents in real time.
PwC’s third point is that governance cannot stop at launch. It says organisations need a balance between design-time controls and continuous monitoring once systems are live. That requires enough evidence of actions, tool use, exceptions and outcomes to support investigation and intervention where needed. The firm says full logging may be appropriate in some cases, but acknowledges that privacy, cost and feasibility may limit how much can be retained.
It also notes that AI can be used to assess AI, for example through LLM-as-a-judge techniques, though those systems themselves need controls over calibration, bias and reproducibility. And it says the funding model must change too: oversight should be treated as an ongoing business cost, not a one-off project expense, with lifetime spending covering development, testing, management and optimisation.
The underlying message is that agentic AI governance will have to be continuous, automated and coordinated if organisations want to keep pace with increasingly independent systems without giving up control.
Source: Noah Wire Services