Brave New Rules for AI Agents
How far agents can scale depends on accurate context, permissions at every action, and visible cost.
Yasmeen Ahmad
SVP and General Manager, Workday Data Cloud
Workday
How far agents can scale depends on accurate context, permissions at every action, and visible cost.
Yasmeen Ahmad
SVP and General Manager, Workday Data Cloud
Workday
Every week brings another headline about the AI race: faster models, broader scope, more agents deployed. Today's foundation models are capable of complex, multi-step work. The hurdle is not the capabilities to scale. The hard part is trust. We are hearing the same thing from leaders: they are not sure the value is worth the risk.
Here’s why. The most powerful autopilot agents are already here, but are lawless: ungrounded in current business data, ungoverned in what they can touch, and unaccountable for what they do. An agent you can't trust is an agent you can't put into production.
Fortunately, there’s a solution.
We already have the environment for trusted execution. It’s called the system of record - the place where business has long executed its most critical actions. This is the clear path from pilot to production, and it's been sitting in plain sight the whole time.
An agent you can't trust is an agent you can't put into production.
Report
Most agents in use today are reasoning on data that's stale or disconnected from the real system, they're running with permissions broader than any single person would ever hold, and nobody can see what they cost until the bill arrives. However, they can move safely from pilot to production when three things are true.
Current, trusted context. An agent is only as good as what it knows at the moment it acts. In the enterprise, that context lives at the edge, in the system of record, where transactions post, effective dates change, and the org chart updates every day. A copy in a data lake or a nightly extract is stale by the time an agent reads it. If your agent is operating on a copy of your data, it is operating on an echo.
Permissions scoped to the person. When an agent acts for a human, it should carry that employee’s authority and nothing more. Shared API keys and service accounts hand agents wider reach than any single human user has. In a 2026 survey of 300 CIOs, security was cited by 39% as the top concern for enterprise-wide AI adoption.
Visibility into usage-based spend. Agents consume cost every time they reason and act. Without real-time insight, IT learns what an agent costs after the bill arrives.
Three shifts are making this possible: where agents act, what they know, and who they answer to.
The enterprise market is moving past sidecar copilots that summarize text or suggest next steps. Leaders want agents that execute multi-step operational tasks like halting an invalid payroll run, reallocating project resources, or authorizing a vendor payment.
Action depends on a system of record, alongside the business logic, transactional locking, and capabilities that make an action valid. To support agentic execution, enterprise architecture has to converge, bringing agents to the live system of record with instant, zero-copy access to data where it lives. An agent can't do that from a 24-hour-old batch extract in an external data lake. Data lakes are where data goes to rest. You cannot execute an action where data goes to rest — you can only execute where operational reality lives.
Foundation models are brilliant at language, but enterprise logic trips them up. Effective-dated history, matrixed hierarchies, and strict accounting constraints confuse them. Point a model at flat SQL tables or a static data dictionary, and it has to guess at relationships, connections, and reporting lines. This is where hallucinations begin. Even a routine employee transfer can involve a future-dated assignment, a pending compensation change, and a regional compliance rule, none of which a model can see on its own.
Enterprises need a context layer: a unified, living fabric that brings temporal awareness, enterprise hierarchies, business logic, and execution boundaries directly into the AI loop. With that context in the loop, agents stop guessing and act with the accuracy the business actually requires.
Traditional permissions govern data at rest. But agents don’t just read—in the new era of agentic IT, they execute.
Traditional permissions govern data at rest. They answer whether an identity can read a table or a column. But agents don’t just read—in the new era of agentic AI, they execute.
When an agent acts headlessly with a backend API key, human custody disappears and the liability lands on the enterprise. Employees sense the risk. In a global survey of 2,950 business and IT decision-makers, only 24% said they were comfortable with AI agents operating in the background without human knowledge.
Security must attach to the action, the context, and the identity at every step of the execution chain. At the moment of execution, that means confirming the action sits within the agent's delegated authority, checking real-time purchase order thresholds, applying the right cost center matrix, and validating the effective-dated regional policy that governs the change.
Security must attach to the action, the context, and the identity at every step of the execution chain.
Once you hand authority to a system that acts on its own, you need to be certain you can govern it. A lawless agent reaches its goal by any path available. A lawful agent reaches the same goal inside the rules the business has already set: its security policies, approval chains, and regulatory obligations. The two can use the same model and the same prompt. What separates them is where they run and what governs them.
Expecting agents to be lawful by default comes with real trade-offs.
Scaling agents takes work across architecture, security, and finance. Here's where I expect the value to show up first:
Run at the edge, where business happens. Agents will have live access to a single source of truth so every decision reflects the current state of the business. By keeping reasoning close to data and rules, they will inhabit the places people already work, whether that's a collaboration tool, a copilot, or a custom enterprise portal.
Inherit access at every action. Agents will inherit access at every action, not hold it permanently. While humans will confirm every step forming the audit trail, agents can run in the background with their own scoped identity, and a named owner who is accountable for what they do.
Monitor cost alongside latency and accuracy. Agent consumption will be treated like any other cloud spend. Leaders can estimate before they commit, watch usage as it happens, set budgets and alerts per agent, and connect spend to the value each agent delivers.
The next phase of enterprise AI will be decided by trust, not intelligence. The models are already good enough. CIOs who build governance into the foundation, grounding agents in live context, attaching security to every action and keeping spend in view, will be the ones whose agents reach production and stay there.
Report