Insights

    Agentic AI

    Gartner's other warning: one governance policy across all agents causes the failure

    Devence Lab

    · 2 min read

    Share
    Gartner's other warning: one governance policy across all agents causes the failure
    Photograph · Unsplash

    The advice to govern agents uniformly sounds prudent and produces the opposite of safety. The reason is that an agent's risk is set by its authority, and authority is not uniform.

    Alongside the widely quoted 40% figure, Gartner makes a second argument that gets far less attention: applying uniform governance across AI agents will itself lead to enterprise agent failure.

    That reads as counterintuitive. Consistent policy is normally the mature answer. Here it is the trap.

    Risk scales with authority, not with the technology

    Two agents can share a model, a framework and a deployment pipeline while differing by orders of magnitude in what they can cause. One drafts internal summaries. The other moves money. Their technical profile is identical and their risk is not remotely comparable.

    A uniform policy has to pick a single point on that range. Pick the strict end and the summariser drowns in approval workflow nobody needed, which teaches the organisation that agent governance is theatre to be routed around. Pick the permissive end and the payment agent ships with controls designed for a text generator.

    Uniform policy is calibrated for the average agent. No agent is average, and the ones that hurt you are furthest from it.

    What differentiated governance looks like

    Tier by blast radius, not by technology. Ask what the worst single action this agent can take is, whether it is reversible, and how long before someone notices. Those three answers place it in a tier, and each tier gets a proportionate control set.

    Read-only agents need little beyond logging and data-handling rules. Agents that write to systems of record need scoped credentials, action logs and a rollback path. Agents touching money, safety or externally binding commitments need approval gates with real independent evidence, plus the assumption that they will be attacked specifically.

    The organisational benefit

    Tiering has a second effect that matters as much as the risk calibration. It makes the cost of autonomy visible at design time — asking for more authority means accepting a heavier control set, which forces teams to justify why the agent needs it.

    Under a uniform policy that conversation never happens, because authority is free and the controls are the same either way. That is how an agent ends up with production write access it was never designed to need, which is the origin story of most of this year's incidents.

    Sources

    1. Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent FailureGartner
    2. Securing AI agents: When AI tools move from reading to actingMicrosoft Security

    Written by the Devence Lab research team.

    Share

    Collaborate

    We share findings with partners operating in the same constraint space.

    Get in touch