Trending Topics

Why the next wave of AI is about trusted action, not text generation
This article is part of our Opinions section, where we invite industry professionals to share their views on the most pressing technology questions of our time.
For the past three years, enterprise AI investment has revolved around one central question: How good is the output?
The conversation was dominated by generated summaries, content drafts, recommendation engines, copilots, and search augmentation. Organisations evaluated AI systems largely on the quality, speed, and fluency of what they produced. And to be fair, the gains were meaningful. Teams moved faster. Knowledge became more accessible. Workflows that once took hours could suddenly happen in minutes.
But this first wave of enterprise AI is cresting, and as a result, some important things are being revealed.
The next competitive divide in AI will not be determined by which organisation has access to the most powerful model. It will be determined by which organisations can trust AI to take action safely inside real business operations. This distinction matters more than many enterprises currently realise.
We are moving from systems that generate information to systems that execute work. AI is no longer confined to drafting an email or summarising a support ticket. Increasingly, agentic systems are triggering workflows, generating regulated documents, updating CRM records, initiating approvals, orchestrating downstream systems, and making operational decisions across environments.
At that point, the question changes completely. The issue is no longer simply whether the output is accurate. The issue becomes whether the action itself is governed.
That is where the next major enterprise AI challenge begins.
Recent research reflects this growing gap. McKinsey’s 2026 AI Trust Maturity Survey found that, while organisations are rapidly expanding AI adoption, only about one-third report strong maturity in governance, strategy, and agentic AI oversight. In other words, AI capabilities are accelerating faster than the operational structures designed to control them.
That imbalance should concern every enterprise leader.
Action changes the risk profile entirely
When AI generates text, humans still sit between the system and the outcome. Someone reviews the draft. Someone approves the recommendation. Someone decides whether the output becomes real.
Action-based AI compresses or removes that buffer. Once an AI system can initiate workflows, generate customer-facing documents, trigger approvals, modify records, or orchestrate systems across environments, the risk profile changes fundamentally. Governance is no longer a secondary consideration layered on after deployment. It becomes part of the architecture itself.
This is especially important because AI agents are not static software processes. They operate dynamically. They interpret goals, chain actions together, adapt to context, and interact across systems in ways traditional automation tools were never designed to handle.
As organisations adopt more agentic workflows, they are introducing non-human actors into regulated operational environments. That means enterprises must rethink permissions, accountability, identity, and oversight.
The old model of trust (a user login attached to a static role) is no longer sufficient. Now organisations must answer far more complex questions:
- What systems can this agent access?
- What actions is it authorised to perform?
- What data can it retrieve or modify?
- What business rules constrain execution?
- How are approvals enforced?
- What audit trail exists after the action occurs?
- Who is accountable when something goes wrong?
These are governance questions, not model questions.
And right now, many enterprises are significantly more mature in AI experimentation than they are in AI execution governance.
Regulated industries are feeling the pressure first
The governance gap becomes most visible in highly regulated industries because the consequences are immediate.
In financial services, healthcare, insurance, and legal operations, ungoverned AI action is not simply a technical risk. It is a compliance, reputational, and operational risk.
A document generated outside approved systems may violate retention requirements. An automated workflow that bypasses approvals may expose the organisation to audit risk. A customer communication initiated by an AI agent without proper controls can introduce legal liability.
The challenge is not theoretical anymore.
Industry reporting already shows that executives understand the risk. According to analysis on agentic AI adoption in financial services, 86% of financial services leaders acknowledge that agentic AI introduces new compliance and governance concerns, yet responsible AI investment continues to lag behind broader AI adoption initiatives.
I’ve seen versions of this challenge repeatedly in enterprise environments.
Teams move quickly to pilot AI experiences because the front-end productivity gains are obvious. But once those initiatives touch regulated workflows — contracts, approvals, onboarding, servicing, claims, policy documentation, financial communications — organisations suddenly realise their governance models were designed for human users and deterministic automation, not adaptive AI actors.
The enterprises making real progress are not necessarily the ones deploying the most experimental AI systems. They are the ones designing operational frameworks that allow AI to participate safely inside governed business processes.
The organisations getting this right are anchoring AI inside trusted systems
The answer is not to slow down AI adoption. It is to route AI action through systems that enterprises already trust.
That means AI should not become a parallel operational layer sitting outside governance infrastructure. It should operate through the platforms where governance already exists: CRM systems, ERP platforms, workflow engines, approval frameworks, permission models, and audit systems.
This is where the conversation around enterprise AI becomes much more practical. The most effective agentic AI architectures separate intelligence from execution. For instance, AI can determine what should happen next for specific customers:
- Which customer requires follow-up
- Which policy document should be generated
- Which renewal packet should be initiated
- Which case needs escalation
But execution itself should still flow through governed systems that enforce business rules, permissions, approvals, compliance policies, and auditability.
This distinction is critical. The organisations succeeding with agentic AI understand that governed execution is the real differentiator. Not the prompt, the interface, or even the model itself.
Three principles for moving from AI output to trusted AI action
As enterprises transition from generative AI experimentation into operational AI deployment, I believe three principles will define successful implementations.
1. Route AI through existing governance systems, not around them
Every disconnected AI workflow creates new exposure.
When organisations allow sensitive processes to happen outside approved systems, they weaken visibility, permissions enforcement, auditability, and compliance controls. The strongest AI architectures are those that keep execution anchored within trusted operational platforms.
AI should initiate workflows through systems that have already been vetted for governance, not bypass them.
2. Treat AI agents as first-class operational identities
AI agents should not be treated like invisible background automation. They require identity governance.
Organisations need visibility into where agents operate, what permissions they hold, what systems they can access, and how those permissions evolve over time. The same rigour applied to privileged human users must now extend to AI actors.
That includes authentication, authorisation, monitoring, logging, and lifecycle management. Ultimately, regulated environments cannot afford anonymous execution.
3. Separate intelligence from execution
This may become the defining architectural principle of enterprise AI.
AI is extremely effective at identifying patterns, prioritising actions, generating recommendations, and accelerating decision-making. But the actual execution of business-critical processes should still be subject to operational controls.
This separation creates defensibility. It allows enterprises to benefit from AI speed and flexibility while preserving accountability, explainability, and integrity. And in regulated industries especially, that balance matters.
Why the future of AI belongs to the platforms we can defend
The first wave of enterprise AI was about generating information faster. The next wave will be about executing business actions safely. That is a much more difficult problem to solve, and a far more important one. Because once AI moves from assisting work to performing work, trust becomes operational.
The organisations that win in this next phase will not simply be the ones with the most advanced models. They will be the ones who build governed execution frameworks capable of supporting AI at enterprise scale.
In the years ahead, enterprises will not differentiate themselves based on whether they use AI. Nearly everyone will. The real divide will emerge between organisations that can operationalise trusted AI action and those that cannot.
