Governing AI agents in a company requires clarity on four questions: which tasks an agent can undertake, which actions it is authorized to perform, when human approval is required and who is accountable for the outcome. This article proposes setting authority limits, keeping action logs and evaluating both workflow quality and risk, rather than measuring AI usage alone.
Recent reports point to the same shift. Companies are no longer only experimenting with generative AI. Many have expanded access to sanctioned AI tools, started customizing agents for their own workflows and placed high expectations on productivity gains. Deloitte’s 2026 State of AI in the Enterprise reports that worker access to sanctioned AI tools rose by about 50% in one year, from below 40% to around 60%. The same report notes that 85% of companies expect to customize agents for their own needs, but only 34% say they are using AI to deeply reimagine the business.
The issue is the gap between ambition and operating capability. Microsoft’s 2026 Work Trend Index argues that organizational factors such as culture, manager support and talent practices explain more of AI impact than individual effort alone. In practical terms, even an employee who uses AI well can be blocked if workflows, data, decision rights and quality standards have not been redesigned.
Why do AI agents need dedicated governance?
In the early stage, many companies use AI as a personal assistant: drafting, summarizing, translating, classifying information or supporting analysis. These tasks are relatively controllable when humans review the output. But when AI agents enter multi-step workflows, call tools, make recommendations, send requests or update data, the nature of risk changes. Error no longer appears only in a single answer. It can move through a process.
Deloitte warns that AI agents are scaling faster than guardrails. In a 2026 multicountry survey, only 21% of enterprises said they had a mature governance model to manage the risks of agentic AI. IBM also describes an “AI control gap”: two-thirds of surveyed CIOs and CTOs said they were accountable for AI systems they did not fully control, while only 11% said they were completely prepared for the scale of AI agent deployment.
Example
A customer service unit may use an agent to classify complaints, suggest responses and route cases to technical teams. If the agent only prepares suggestions for human approval, the risk is manageable. If it can update order status, send compensation promises or trigger refunds, the company needs clear authority limits, action logs, mandatory checkpoints and final human accountability.
Why is prompt training not enough?
A common response is to organize prompt training or tool-use workshops. This is necessary, but it is not enough. When AI enters operations, the important capability is not only knowing how to ask the model a question. It is knowing how to redesign work. Managers must decide which tasks AI should support, which tasks require human judgement, which outputs must be verified and which metrics should be used to evaluate impact.
PwC’s 2026 Global AI Jobs Barometer suggests that the labour market is increasingly rewarding AI-related skills as well as human skills such as judgement, creativity and leadership. This implies that AI does not simply replace work. It changes the standard of capability. The valuable professional is not the person who uses the most tools, but the person who can combine tools with expertise, context and decision responsibility.
Three questions companies should ask
The first question is where AI is being used in the value-creating workflow. Counting AI accounts or usage volume is not enough. Companies need to examine specific workflows such as sales, customer service, data analysis, recruitment, training, reporting, compliance control or market research. In each workflow, AI should be linked to processing time, output quality, cost, risk and user experience.
The second question is who is accountable when AI contributes to a decision. Accountability cannot be delegated to the tool. Companies need to distinguish the process designer, operator, approver, data reviewer and person ultimately accountable to customers or regulators. When accountability is vague, AI may increase speed while reducing control.
The third question is how the organization learns from AI use. A mature organization does not only record errors. It asks why the error occurred: poor input data, unclear instructions, agent overreach, missing checkpoints or superficial human approval. These lessons must become new operating standards rather than isolated incident fixes.
Implications for Vietnamese companies
For Vietnamese companies, the opportunity is clear, but the risk is practical. Many organizations still have fragmented data, processes that depend heavily on individual experience and quality standards that are not fully documented. If AI agents are introduced too quickly into such environments, the company may automate existing ambiguity. If AI is treated as an opportunity to standardize workflows, clean data and clarify accountability, it can become a driver of management improvement.
A suitable approach is to begin with high-frequency workflows where data are relatively clear and risks are controllable. Companies can test AI for summarizing customer feedback, preparing management reports, analyzing training needs, reviewing internal documents or helping employees prepare first drafts. Impact should then be measured through concrete indicators: time saved, error rate, satisfaction, rework and decision quality.
Conclusion
AI agents may change how organizations operate, but value does not appear automatically because the tool becomes smarter. Value comes from redesigning work, setting authority limits, controlling data, clarifying accountability and learning from implementation. In the next stage, advantage will not belong to the company that uses AI the most. It will belong to the company that turns AI into a controlled management capability.
Author: Assoc. Prof. Nguyen Hai Ninh.
References
Deloitte. (2026, January 21). From ambition to activation: Organizations stand at the untapped edge of AI’s potential. https://www.deloitte.com/us/en/about/press-room/state-of-ai-report-2026.html
Deloitte. (2026, April 24). Business and IT leaders report AI agents are scaling faster than their guardrails. https://www.deloitte.com/us/en/insights/topics/emerging-technologies/ai-agents-scaling-faster.html
IBM. (2026, June 8). New IBM study finds CIOs and CTOs face growing AI control gap as enterprise deployment scales. https://newsroom.ibm.com/2026-06-08-new-ibm-study-finds-cios-and-ctos-face-growing-ai-control-gap-as-enterprise-deployment-scales
Microsoft. (2026, May 5). Agents, human agency, and the opportunity for every organization. https://www.microsoft.com/en-us/worklab/work-trend-index/agents-human-agency-and-the-opportunity-for-every-organization
PwC. (2026, June 15). AI reshapes global labour market into two distinct paths, rewarding human skills. https://www.pwc.com/gx/en/news-room/press-releases/2026/pwc-2026-ai-jobs-barometer.html
