Skip to content

7 May, 2026

  • Saved Articles
  • My Account
  • Subscribe
  • Log In
  • Log Out

Board Agenda

  • Governance
  • Strategy
  • Risk
  • Ethics
  • News
  • Insight
    • Categories

      • View all
      • Governance
      • Strategy
      • Risk
      • Ethics
      • Board expertise
      • Finance
      • Technology
    • share buyback

      The high cost of neglecting internal audit

      When internal controls fail, the results are felt not only in heavy fines, but in...

      early-stage startups

      What does governance mean for early-stage startups?

      Robust governance is a key strategic asset, even—or especially—in the early days of an organisation’s...

      cybersecurity

      5 steps to stay ahead of AI cyber risk

      Technology is moving faster than the law—and most boards—can keep up with. Start adapting now,...

  • Comment
      • View all
    • share buyback

      The high cost of neglecting internal audit

      When internal controls fail, the results are felt not only in heavy fines, but in...

      chairs universal

      The chair’s influence isn’t universal

      How much sway does the chair of a board really have? Much depends on their...

      AI agents

      The AI risk faced by every board right now

      Even if no one in the organisation planned their arrival, AI agents are already present...

  • Interviews
      • View All Interviews
      • Podcasts
      • Webinars
    • future-ready

      Is your board ‘future-ready’?

      The survival of a business in uncertain times depends on its ability to pivot as...

      investor confidence

      Lack of audit reform ‘will hit investor confidence’

      Government's failure to push ahead with audit reform is a risk to UK investments, the...

      stewarding AI

      AI is a ‘special case for governance’

      As AI use in the boardroom grows, it’s essential to focus on the ethical and...

  • Board Careers
      • View All
    • UK and US CEO

      Corporate shift toward experienced CEOs

      Leadership succession shows fewer first-time chief executives, especially in the US, according to turnover figures.

      female CEO

      Number of women in leadership stays unchanged

      In 2021, there were only eight female CEOs in the FTSE 100—a figure that is...

      female NED

      UK female non-executives earn £73k less than male NEDs

      Although the UK’s average gender pay gap on boards is shrinking, it is still one...

  • Resource Centre
      • White Paper Downloads
      • Book Reviews
      • Board Advisory & Corporate Services
    • European Corporate Governance Barometer 2026

      EcoDa's report highlights emerging governance challenges for European boards, such as technology, cyber risk and...

      Redefining Leadership in the Age of AI

      Henley Business School report on how technology is changing organisations, and what this demands of...

      Global Corporate Governance Trends for 2026

      Russell Reynolds Associates interviewed leadership advisers and governance experts for its Global Corporate Governance Trends...

  • Events
  • Search by topic
    • Governance
    • Strategy
    • Risk
    • Ethics
    • Regulation
    • ESG
    • Investor Relations
    • Careers
    • Board Expertise
    • finance
    • Technology

The AI risk faced by every board right now

by Bill Lewis

Even if no one in the organisation planned their arrival, AI agents are already present and working in the systems you trust.

AI agents

Image: RerF_Studio/Shutterstock.com

Favorite

Most boards still talk about AI as if it arrives through a clear, visible decision. Someone proposes a project, IT reviews it, security people check it, legal function looks at the contract and the executive team discusses it. The board gets sight of it if it is big enough. That is no longer the full picture.

A new kind of software is starting to appear inside the systems companies already use and trust. These tools do more than answer questions. They can read information, make recommendations, trigger actions, and in some cases act on their own. These are AI agents.

AI agents present a fundamental business risk that requires board-level awareness and governance.

The deeper vulnerability is that agents may enter, expand, or be enabled below board level without ever being surfaced to the board as a distinct governance issue. That is what makes them insidious: they can create real business risk before the board fully understands they are there. This is not just a technology risk. It is a fundamental business risk that requires board-level awareness and governance.

No need to ask

There is an even sharper point. AI agents do not always arrive because the customer asked for them. Vendors can now ship agent functionality inside software suites the company already licenses and trusts, often without any fresh, explicit approval moment from the customer each time that functionality appears. In Microsoft’s own documentation, ready-to-use agents are provided by default in Microsoft 365 Copilot, and some agents are available by default in Copilot Chat. Microsoft also says Copilot Chat is pinned by default for most eligible users.

If no one can clearly say where the agents are… then the organisation is vulnerable.

Google’s Gemini Enterprise documentation says agent owners can, by default, share agents within the organisation without prior admin approval unless admins change that setting. That matters. Because some agents may be visible from the start. Others may sit inside a wider software release, waiting to be enabled, connected to data, or given permission to act. Some may already be active inside the company’s technology stack while only IT, or perhaps only part of IT, is fully aware of them.

Microsoft’s admin documentation is explicit that admins can enable, disable, assign, block and remove agents centrally, which underlines the point: these are now operating capabilities inside the enterprise stack, not just experimental tools at the edge. And the threat does not care how it entered. If an agent can read sensitive data, influence decisions, trigger actions, move information between systems, or act autonomously, then it creates risk. If no one can clearly say where the agents are, what they are allowed to do, and who is controlling them, then the organisation is vulnerable.

Board accountability

That is not an IT detail. It is not a side issue for innovation teams. It is not something that can be left to product managers and administrators alone. It is a board-level business risk. Why? Because when something goes wrong, the accountability does not sit abstractly with “the technology”. It sits with the enterprise, with the company that allowed the agent into its environment, with the leadership team that failed to see it clearly, and with the board that did not insist on governance equal to the risk.

The vendor proof points now matter because they show that this is not theory. Microsoft said on 9 March this year that it now has visibility into more than 500,000 AI agents across its own company, and that over the previous 28 days, those agents had been generating more than 65,000 responses a day for employees.

In the same announcement, Microsoft said this showed it was no longer simply experimenting, but embedding these capabilities into everyday work. Google Cloud’s partner article explicitly says its aim is to help System Integrator partners build, scale, and manage enterprise-grade agent systems for enterprise clients. Salesforce announced six new healthcare agents on 5 March.

Taken together, those signals point in one direction. Agents are no longer confined to a few experiments run by specialist teams. They are starting to spread through large organisations through the normal software stack: enterprise suites, cloud platforms, partner ecosystems, admin settings, and easy-to-use build tools. Microsoft’s February security report goes further: it says more than 80% of Fortune 500 companies now use active AI agents built with low-code or no-code tools, and argues that observability, governance and security are becoming central enterprise issues as a result.

It is a dangerous position when AI agents can already sit inside finance, workflow systems, cloud platforms, HR, and regulated environments.

This is why the board conversation needs to change. The conversation is not ‘Do we have an AI strategy?’, but rather ‘Where are the agents? What can they do? Who controls them?’ Those are now the serious questions. Because if the board cannot get clear answers, then it is not governing the risk. It is guessing. And that is a dangerous position when agents can already sit inside customer service, finance, workflow systems, cloud platforms, HR processes, and regulated environments. Microsoft’s own description of agent adoption spans sales, finance, security, customer service, and product innovation; Salesforce’s healthcare launch shows the same direction of travel in a regulated sector.

Three questions to ask immediately

Three questions follow on from the above. First: where are the agents? Which systems already contain them? Which teams are using them? Which partners have introduced them? Which ones are sanctioned, and which ones are not? Microsoft says many organisations still struggle to answer basic questions, such as how many agents are running, who owns them, and what data they touch.

The second question is: what can they do? Can they only draft text? Or can they read sensitive data, make recommendations, trigger workflows, move information between systems, or act autonomously? Google defines AI agents as software systems that pursue goals and complete tasks on behalf of users, with autonomy to make decisions, learn, and adapt.

Third, ask: who controls them? Who approved them? Who gave them access? Who set the rules? Who checks the logs? Who is accountable if they make a bad decision, mishandle sensitive information, or expose the business? Microsoft’s governance guidance is explicit that ownership, accountability, policy, and oversight now have to be treated as part of the enterprise AI control problem, not as an afterthought. If those answers are unclear, the business is more exposed than it thinks.

The danger is not some dramatic science-fiction scenario. The danger is something much simpler: agents are becoming easier to introduce into the business than they are to see, understand and control. That is how real enterprise risk builds: quietly, inside trusted systems, below board level—and before the board has fully caught up. So the right question now is not whether AI matters. It is whether the company can see, understand and control the agents that are already starting to appear inside its business. If it cannot, then the next AI risk may not be coming. It may already be there.

Bill Lewis is a chair, non-executive director, and senior business adviser

  • Facebook
  • Twitter
  • Google+
  • LinkedIn
  • Mail

Related Posts

  • Boards ‘should discuss AI at every meeting’
    March 19, 2026
    AI and boards

    More than 70% of boards fail to give enough attention to artificial intelligence oversight, survey reveals.

  • The paradox of cyber risk and business growth
    August 1, 2024
    cyber risk and business growth

    Risk consensus and confidence in cybersecurity allow boards and organisations to innovate and drive the business forward.

  • OpenAI reinstalls Sam Altman as chief executive
    November 23, 2023
    OpenAI reinstalls

    The CEO’s departure and return have raised questions about the state of governance at the trailblazing ChatGPT creator.

  • UK companies face a clear cyber risk
    June 20, 2025
    clear cyber risk

    Boards need a laser focus on digital risks—and the UK needs stronger audit, governance and reporting legislation.

Search


Follow Us

Most Popular

Featured Resources

wef global risks 2025

The Global Risks Report 2025

The 20th edition of the Global Risks Report reveals an increasingly fractured global...
Supply chain management cover

Strategic Oversight in Supply Chain Management: A Guide for Corporate Boards 2025

Supply chains have become complex, interdependent and opaque and—according to research...

Cyber Security: What Boards Need to Know

Maintaining firewalls, protecting servers and filtering malicious emails rarely make...

C-suite barometer: outlook 2025 - UK insights

Forvis Mazars draws UK insights from its global study and looks at UK executives’...

The IA’S Principles Of Remuneration 2024 2025

This guidance from the Investment Association is aimed at assisting remuneration...
Diligent 2024 leadership tech cover

Leadership, decision-making & the role of technology: Business survey 2024

This research report by Board Agenda and Diligent sheds light on how board directors...

Director Reference Guide: Navigating Conflict in the Boardroom

The 'Director Reference Guide' on navigating conflict in the boardroom provides practical...
Nasdaq 2024 governance report cover

Nasdaq 2024 Global Governance Pulse

This Nasdaq survey gathered data from more than 870 board members, executives, and...

Becoming a non-executive director (4th edition)

Board composition is the subject of much debate, while the role of the non-executive...
art & science brainloop new cover

The Art & Science of Creating an Effective Board

Boards are coming under more scrutiny and pressure than ever before from regulators,...
SAA First time NED guide

First Time Guide for Non-Executive Directors

The role of the non-executive director has never been more vital: to advise, support,...

SUBSCRIBE TODAY

Stay current with a wide-ranging source of governance news and intelligence and apply the latest thinking to your boardroom challenges. Subscribe


  • Editors & Contributors
  • Editorial Advisory Board
  • Board Advisory & Corporate Services
  • Media Marketing Solutions
  • Contact Us
  • About Us
  • Board Director Network
  • Terms & Conditions
  • Privacy Policy
  • Cookies

Copyright © 2026 Questor Media Group Ltd.

  • Terms & Conditions
  • Privacy Policy