
As digital labor becomes a core component of the agentic enterprise, it’s a good strategy to treat AI agents like interns, not executives.
That’s the analogy that Chris Selland, go-to-market lead at Akumina, uses to explain his approach to making sure AI agents perform as expected without any trade-offs in privacy and security, or other costly errors.
“Until an intern is trusted, the best practice is to give them a very narrow scope of work, clear boundaries, and constant supervision,” Selland says. “Only as the AI agent proves its reliability do you slowly expand its ‘circle of trust’ — and always with oversight.”
Selland is among the IT leaders and influencers from Foundry’s Expert Contributors Network who responded to the question: “How can organizations mitigate risks as they develop and deploy AI agents?”
Other experts, such as Daniel Jacobs, founder and CEO at Starkhorn, agreed with Selland that starting narrow and small is a strong approach. Proving reliability in low-risk environments before expanding autonomy honors the legitimate caution that employees and customers alike feel when they sense control slipping away from human hands.
“The most important act an organization can take before deploying AI agents is to slow down long enough to ask not just ‘What can this do?’ but also ‘What could this do to us?’” he says.
Why AI governance starts with data
The rapid adoption of agentic AI is outpacing the governance structures designed to contain it, says Javier Campos, Group CTO and chief AI officer at Cape.io. That asymmetry represents the most consequential risk that enterprises face today.
“Autonomous agents that can reason, plan, and execute multistep workflows introduce a fundamentally different risk profile from traditional automation,” Campos says. “Their action-space — the tools, systems, and data they can access — combined with the degree of autonomy granted by their instructions, creates a surface area for error, hallucination, and unintended consequence that scales with every new capability.”
That said, organizations can mitigate the risks associated with AI agents the same way they do with any new innovation: by embedding governance into the architecture, including defining role-based data access at the outset, according to Michael Bertha, partner and central office lead at Metis Strategy.
“AI agents should operate within defined guardrails,” Bertha says.
Those guardrails should be informed by the lineage and provenance of the data feeding AI agents, suggests Peter Nichol, product leader for data and analytics at a large CPG and health company.
“Think of it like a kitchen,” Nichol says. “Before a chef uses an ingredient, they check three things: the label, the source, and the timestamp. AI systems need the same discipline with data. When feeding AI agents, the business definition, the system of origin, and the data freshness must be clear. The business meaning of the metric must be defined, the source system verified, and the data must be current and complete.”
These simple checks prevent lineage gaps from undermining the insights AI is expected to deliver, Nichol adds.
If an agent is pulling in data from different sources, you also check that each source doesn’t use different definitions for key terms such as “order,” “sale,” or “resolved.” Otherwise, semantic drift is the result, ending in confused and upset customers, says Dr. Martin De Saulles, principal analyst with Information Matters.
“Having a useful conversation with someone is impossible if they keep changing the meaning of the words they use,” he says. “AI agents are no different, and losing customer trust through inconsistent answers can happen in an instant.”
The roles of access control, auditability, and observability
Beyond using the right technologies and tools, Scott Schober, president and CEO at Berkeley Varitronics Systems, says basic human judgement is also critical.
“If you wouldn’t hand a stranger the keys to your server room, don’t hand an AI agent unrestricted access to your data either,” he says.
In that sense, AI vendors need the same scrutiny as any third-party with network access, and an AI agent’s actions should be auditable after the fact, he says.
“Observability also matters,” adds Will Kelly, a writer who focuses on AI and the cloud. “Logging agent behavior and decisions helps teams refine prompts, detect drift, and maintain trust in the system. The organizations that deploy AI agents safely are those that integrate them into existing DevOps and governance practices rather than treating them as experimental side projects.”
Tom Allen, founder of The AI Journal, points out that many leading vendors have governance capabilities already built into their platforms.
“Data classification, access controls, audit logs, and policy engines should be used to define where agents can read, write, or automate workflows,” he says.
Test, retest, and test again
Testing and validating AI agents is the natural next step. This includes stress-testing — before deploying — against common cyberattacks, such as prompt injection vulnerabilities, says Robert Siciliano, CEO at Protect Now. He also recommends maintaining a consistent “human in the loop” once AI agents are put to work.
This could mean “requiring human approvals for critical AI agent decision-making when impacting finance, security, or client information,” he says.
This human-in-the-loop approach is essential for AI agent deployments to ensure that digital labor adheres to brand and safety guidelines.
Even when IT leaders take all those steps, managing and mitigating the risks of AI agents is never a “one-and-done” activity, says Elitsa Krumova, a global thought leader and B2B tech influencer specializing in emerging and future technologies.
It takes ongoing interdisciplinary oversight, strict sandbox testing, and constant real-time monitoring to keep risks at bay over the long term. The good news is: You can do all that and still realize the potential of AI in the enterprise.
“Treat AI agents as evolving dynamic units requiring consistent risk management strategies with a greater level of adaptiveness and the ability to evolve, rather than fixed measures,” Krumova says. “That will prevent inadvertent consequences for organizations, while fostering innovation.”
By leveraging BigQuery and Salesforce Data 360 together, organizations can apply consistent security policies across the entire agentic life cycle. Zero-copy integrations between these platforms are integral for AI agents because they provide instant access to real-time enterprise data without the need to build traditional, expensive data pipelines. Learn more about how Google Cloud and Salesforce co-innovations provide the governance needed for the agentic era.

