Lawless vs. Lawful Agents and The Real Cost of Speed
To achieve true velocity, CIOs must anchor their agents directly to the system of record.
Gabe Monroy
Chief Technology Officer
Workday
To achieve true velocity, CIOs must anchor their agents directly to the system of record.
Gabe Monroy
Chief Technology Officer
Workday
In part one of this series, I laid out three ways to build enterprise agents without giving up speed or safety, and showed how Workday's guardrails keep rules, approvals, and audit trails intact no matter your front door. In this post, I dig into why "lawless" agents put enterprise compliance at risk, and why the fix is running AI inference directly on your native governance layer—the only real foundation for a lawful agent.
If you sit in enterprise boardrooms today, the pressure weighing on CIOs comes down to two things: velocity and ROI. Boards expect a mature agentic AI strategy and a definitive timeline for deploying autonomous systems that deliver measurable business impact.
In the rush to production, a critical architectural blind spot has emerged. The prevailing market narrative rests on a simple formula. Agents, plus tools, plus data are enough. While no vendor explicitly states it, nearly every product pitch assumes it. The idea is that you drop your corporate data into a cloud data lake, wire up an off-the-shelf Large Language Model (LLM), hand it a toolbox of enterprise actions, and agility follows.
It won’t. It does the opposite. Having spent my career building developer platforms and cloud infrastructure for some of the world's largest workloads, I have learned that when enterprise software touches employees, customers, and finance, the physics change. There is zero tolerance for hallucination or drift when human livelihoods and corporate balance sheets are on the line.
Report
To understand this friction, look closely at the anatomy of an agent. At its foundation, an LLM is probabilistic, generating tokens based on mathematical likelihoods rather than hard-coded rules. The tech industry’s primary answer for introducing rules is tool-calling, which hands the model a set of APIs to take action in the real world.
While tool-calling makes a single action deterministic—where the tool reliably executes a defined instruction the same way each time—the overarching decision layer remains probabilistic. The agent must still decide which tool to call, when, and with what arguments.
Because a generic tool executes whatever instructions it is handed, tool-calling doesn’t solve the governance problem. It shifts the problem to the tool boundary, which is left exposed and ungoverned, a risk category that enterprise teams are increasingly expected to manage through formal AI risk management frameworks and open, secure AI infrastructure.
Wrap that probabilistic model in an agentic framework, assign it an objective, and you create a highly capable, autonomous, goal-seeking entity, with one flaw. There’s no native concept of corporate governance.
Consider a manager asking an off-the-shelf agent to onboard an international contractor. Operating in a structural vacuum, the agent will optimize entirely for task completion. Every individual tool call might succeed, but along the way, the agent can bypass regional labor laws, tax withholdings, and worker classification checks. It does this not out of malice, but because nothing in its architecture understands that these rules exist. A lawless agent completes tasks through whichever systems aren’t paying close attention to the rules. On the surface, it looks like an agility win. In reality, it is a ticking regulatory time bomb.
A lawless agent completes tasks through whichever systems aren’t paying close attention to the rules. On the surface, it looks like an agility win. In reality, it is a ticking regulatory time bomb.
When IT leadership catches this lawless behavior, the default engineering instinct is to patch the vulnerability from the outside. Teams resort to building external LLM gateways, layering on policy middleware, or stuffing massive corporate policies into an already overcrowded context window.
None of these fixes hold. A prompt is a request, not a guarantee. Fast-forward 18 months, and your engineering teams will have spent millions manually reconstructing organizational structures, routing logic, and security permissions inside a makeshift, isolated AI stack.
This is the “shadow ERP” trap, where enterprise agility goes to die. Companies end up maintaining a fragile, buggy copy of the same business logic they already owned inside their system of record. It’s no shortcut when it leads to endless maintenance costs and fragmented governance.
To make an agent lawful by design, enterprise safety must become core infrastructure, wired directly into the inference engine and the execution runtime. Fully controlling what an agent can see, do, and touch requires running AI inference on top of the platform that already provides enterprise governance:
The truly difficult part of enterprise AI isn’t reasoning; it’s compliance. A single payroll run sits on top of shifting withholding and wage rules across thousands of global jurisdictions. No standalone model can recreate that machinery. Your enterprise already knows this, which is why you invested in a system of record rather than writing a custom payroll engine. Routing agents through external middleware quietly reverses that foundational decision. If you want a lawful agent, you must run it where the laws already live.
If you want a lawful agent, you must run it where the laws already live.
Every critical guardrail depends entirely on live enterprise state—the organizational graph, active entitlements, and business processes as configured. Attempting to rebuild these elements from the outside causes the physics of software to catch up with you. What the agent sees degrades into a lagged snapshot, and what it touches relies on risky, static API keys. Distance downgrades guardrail integrity.
Distance also costs speed. Agentic loops are inherently chatty, requiring dozens of tool calls to complete a single task. Every time a call crosses an external trust boundary, it must re-prove who is asking Inside the native platform's perimeter, that security context is ambient. The architectural choice that makes agents lawful is the same choice that makes them fast.
Call it the “Proximity Principle.” AI inference belongs directly on the platform that governs it,because both guardrails and operational speed decay with every hop in between.
When the next agentic pitch reaches your desk, look past the demo and ask one question: Where do the guardrails run? If the answer is an external layer your own team must build and maintain far from your system of record, you are building a shadow ERP. To achieve true velocity, anchor your agents directly to the system that already holds your enterprise laws. That’s how today’s CIOs go fast—safely.
Report