Governing agentic AI: when guard rails drive growth
Human judgment is an indispensable feature, not a brake, in agentic operations
PICTURE a junior product manager working on a report on his laptop. Meanwhile, in the background, an autonomous artificial intelligence (AI) agent files expenses, schedules meetings and drafts a client memo. The efficiency is impressive, but the agent sends calendar changes to the wrong distribution list due to a misconfigured permission. This mistake then becomes a reputational issue for its firm.
This is the paradox of agentic AI – where the same autonomy that lifts productivity can also scale errors. As organisations move rapidly from assistive AI tools to agents that plan, act and iterate on their behalf, the core question shifts from “Is the answer right?” to “Who is responsible for what the system just did?”
Now, more than ever, a clear operating model for agentic AI – one that is principles-based, autonomous and accountable with runtime control – is imperative. Smart rules do not slow agentic AI; they accelerate responsible deployment by making accountability and controls explicit. Singapore’s Model AI Governance Framework for Agentic AI offers that clarity to turn caution into forward motion.
The framework recognises that agents introduce new types of risk and require different control mechanisms. It gives enterprises a shared language to assess risks, align expectations and design proportionate safeguards. It offers operational guidance for first and second lines of defence, and recognises that agents will sit in different workflows of an organisation.
In practice, agentic operations with a human in the loop often fall into three modes – human and agent collaborate, agent operates with human approval, or agent operates with human observation. Each mode implies different failure patterns, audit needs and escalation thresholds.
By matching the degree of oversight to the degree of autonomy, organisations can keep risks proportionate with greater efficiency.
Risks business leaders should plan for
AI adoption is only gaining momentum. A McKinsey-Economic Development Board (EDB) report stated that nearly half of South-east Asian companies surveyed have reported moving beyond AI pilots. The same report also showed that nine in 10 organisations said they are looking to experiment with agentic AI in 2026.
Business leaders should plan for both hard risks (for example, permission escalation, data leakage or cascading error) and human risks (deskilling, over‑delegation and erosion of judgement). The remedy is not to enumerate every safeguard, but to make the operating envelope explicit: defining which actions an agent may take on its own, which require explicit approval, and which are out of bounds in all circumstances.
Two practices can help. Schedule scenario‑based reviews that simulate unexpected cases an employee should recognise, such as a wrong segment, a sensitive topic or an unexpected surge in activity. Next, teach employees to exercise caution and refuse an agent’s suggestion in contexts like suitability, conduct and fraud.
Human judgment is essential in the age of AI. It is an indispensable feature, not a brake.
Why AI governance is crucial for agentic AI
With responsible and clear parameters governing humans and AI interactions, there is great potential to reap benefits, such as enhanced customer experience and improved resource allocation, while remaining firmly anchored in safety, accountability and trust.
In the case of banking, consider an agent that prepares and sends client service updates for different customer segments. A proportionate approach would involve several key steps.
First, scope the autonomy. Classify the use case by autonomy or equivalent principles, and specify the actions that must always require human approval. Define autonomous versus suggestion‑only actions, and restrict tools and data to just enough context. Prescribe hard prohibitions for critical actions such as payment initiation and deal booking.
Second, make accountability clear. Assign an authority from the business function for intervention. Build review checkpoints into the runbook. Accountability should also be visible to employees and customers.
Third, use runtime control mechanisms. Design ways to pause or slow an agent. Isolate it when needed and review what happened afterwards. Implementation will vary by domain and maturity. Progressive and proportionate adoption as use cases mature is what matters.
Fourth, enable responsible use. Clearly disclose when an agent is responding and ensure that escalation to a human is easy. Capture client feedback to refine tone, suitability and boundaries.
In any agentic workflow, policy lives in the runtime, not a document. When uncertainty spikes, the agent should default to suggestion mode; and when anomalies appear, the accountable owner should be able to halt autonomy quickly.
Lessons from testing and implementation
Clarity, accountability and proportionate controls are the focus of UOB’s approach. Our experience of implementing agents shows that the industry must prioritise their AI readiness starting from the strategic foundation, ensuring that the governance framework, policies (operational rules) and model risk approaches (methods of identifying and mitigating risks) adapt to agentic use cases.
From an operationalisation lens, guard rails and responsible use of AI must be built into workflows early, rather than as an afterthought. As we extend model risk assessment to agentic use cases, we are also refining the level of human involvement and oversight.
These learnings underline a broader insight for any organisation: responsible AI is not about slowing innovation, but about designing systems that are trustworthy, practical and sustainable. Implementing guard rails early and deliberately is crucial in fostering confidence in AI use and ensuring accountability.
The road ahead
Strong guard rails do not slow innovation. Principles‑based clarity shortens debates, aligns expectations across teams, and provides organisations with confidence to move quickly. A framework that matches controls to autonomy levels lowers the cost of experimentation while protecting stakeholders.
As teams adopt autonomy‑based thinking across more workflows, organisations can expect more autonomy paired with finer‑grained oversight. For firms operating across borders, the goal is regional convergence on compatible principles, while factoring in local nuance.
Above all, culture will continue to matter. Successful organisations will pair controls with a people‑first ethos that rewards judgement and treats escalation as normal.
Decide now what your agents may never do alone, and who owns the judgment call. Done right, guard rails can drive growth.
The writer is head of enterprise AI at UOB