No Result
View All Result
SUBSCRIBE | NO FEES, NO PAYWALLS
MANAGE MY SUBSCRIPTION
NEWSLETTER
Corporate Compliance Insights
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe
Jump to a Section
  • At the Office
    • Ethics
    • HR Compliance
    • Leadership & Career
    • Well-Being at Work
  • Compliance & Risk
    • Compliance
    • FCPA
    • Fraud
    • Risk
  • Finserv & Audit
    • Financial Services
    • Internal Audit
  • Governance
    • ESG
    • Getting Governance Right
  • Infosec
    • Cybersecurity
    • Data Privacy
  • Opinion
    • Adam Balfour
    • Jim DeLoach
    • Mary Shirley
    • Yan Tougas
No Result
View All Result
Corporate Compliance Insights
Home Risk

Your Next AI Risk Is Inside the Systems You Trust the Most

If an organization is not inventorying and analyzing its AI agents, it isn’t managing risk

by Bill Lewis
May 11, 2026
in Risk
robot and human hand touching

Organizations have treated new technology as something visible and reviewable. That model is breaking down because of platforms’ built-in AI agents, business advisor Bill Lewis explains. For these agents, compliance teams must be building visibility, assigning ownership, documenting permissions and making sure default settings do not quietly become policy.

Most compliance teams are still preparing for AI as if it arrives through a formal proposal. That is no longer the main risk.

A new class of software is appearing inside the enterprise systems companies already use and trust — Microsoft 365, Google Workspace, Salesforce and others. These tools do more than answer questions. They can read information, make recommendations, trigger workflows, move data between systems and, in some cases, act with a degree of autonomy that creates real compliance exposure before anyone knows it.

Many organizations are not prepared for the way agentic AI is entering business: quietly, through routine software changes, default settings, partner ecosystems and embedded capabilities that do not always trigger the same scrutiny as a new standalone deployment.

For compliance and risk teams, this matters. If an AI capability can access sensitive data, influence decisions, initiate actions or operate inside a regulated workflow, it must be governed.

Traditionally, companies treated new technology as something visible and reviewable. A business team would request it, IT would assess it, security would review it, legal would check the contract, and leadership would decide whether the risk was acceptable. That model is breaking down. Agentic capabilities can appear inside tools already approved by organizations. In some cases, they may be available before internal approval or compliance review.

This trend has created a risk blindspot and a governance problem. If an organization does not have a clear inventory of where AI agents exist, what they are allowed to do, which systems they touch and who controls them, then it cannot honestly say it is managing the risk. It is simply assuming the risk is under control because the software came from a trusted vendor.

Why the risk is different now

The threat is not that AI agents are mysterious or futuristic. The threat is that they are becoming ordinary.

Microsoft has said it now has visibility into more than 500,000 AI agents inside its own company and that those agents were generating tens of thousands of employee responses each day. Google products allow agent sharing within organizations unless administrators change defaults. Salesforce has continued expanding agentic offerings into regulated sectors, including healthcare.

These are not edge cases; they are signals of how enterprise software is changing. The compliance challenge is that these tools do not need to be malicious to create risk. A well-intentioned agent that can read confidential information, summarize sensitive records, trigger a workflow or transfer data between systems can still create serious problems if no one has defined boundaries, oversight, auditability or accountability.

In other words, the risk is not just what the agent is. It is what the organization has allowed it to become.

a chip in birdcage
Governance

Responsible AI Governance Starts With Ownership

by Diana Kelley
April 30, 2026

AI governance must be collaboration among IT, HR, legal, compliance and leadership

Read moreDetails

New questions and governance

Compliance, risk, legal, executive and board oversight is necessary with systems deploying AI agents. An AI agent that mishandles sensitive information or behaves unexpectedly is not just a technology incident. It is an enterprise governance failure.

Organization leaders must ask: Which systems contain agents? Which teams are using them? Which are sanctioned? Leaders also have to ask what can these AI agents do? Are they limited to drafting text, or can they access regulated data, recommend actions, trigger workflows, move information or act autonomously? Finally, leaders need to know: Who controls the AI agents? Who approves them? Who sets the rules? Who reviews the logs? Who is accountable if something goes wrong?

If those answers are unclear, an organization is exposed.

Existing governance frameworks simply were not designed for software that spreads through normal enterprise tasks without a distinct launch moment while having the ability to make and act on decisions. That means compliance leaders need to move from a project-based mindset to an inventory-based mindset. This starts by asking the questions above.

An inventory-based approach toward AI agents is especially important in regulated environments, where the combination of sensitive data, workflow automation and delegated authority can create exposure under privacy, security and sector-specific obligations.

A company does not need to wait for a catastrophic incident to discover that an agent has been over-permissioned.

The practical takeaway

The right response is not panic; it is achieving clarity. Compliance teams should assume that AI agents are already entering the enterprise through trusted software and should treat them as a live governance category. That means building visibility, assigning ownership, documenting permissions and making sure default settings do not quietly become policy. 

This article was first published on LinkedIn; it is adapted here with permission.
Tags: Artificial Intelligence (AI)Risk Assessment
Previous Post

Compliance Frameworks Miss Invisible Forces, but They Matter the Most

Next Post

‘Blame the Bot’ Won’t Cut It in Front of Regulators

Bill Lewis

Bill Lewis

Bill Lewis is a senior business adviser with over 35 years of international board-level leadership across five continents. He serves as a chairman, non-executive, fractional CEO and CEO mentor through Linacre Capital Partners, which he co-founded in 2014.

Related Posts

robot fallen over

‘Blame the Bot’ Won’t Cut It in Front of Regulators

by Jonny Frank, Nathan Gibson, Michael Costa and Kashif Sheikh
May 11, 2026

Responsible automation requires human judgment, independence and evidence

brain obscured behind glass

Why Experience Still Matters in an Automated Finance World

by Ryan Padget
May 8, 2026

AI is reshaping workflows in finance, but the judgment that protects organizations remains deeply human

magritte son of man deepfake

Deepfakes Are Now a Board-Level Risk & Regulators Are Watching

by Matt Flegg
May 1, 2026

Recent UK regulatory developments are making deepfake risk a board-level disclosure and accountability issue, not just an IT problem

news roundup bundled papers

GCs Say Global Conflicts Are Increasing Enterprise Risk

by Staff and Wire Reports
April 30, 2026

In-house counsel raises cool; ethical leadership on board agenda for just 35% of directors

Next Post
robot fallen over

‘Blame the Bot’ Won’t Cut It in Front of Regulators

No Result
View All Result

Privacy Policy | AI Policy

Founded in 2010, CCI is the web’s premier global independent news source for compliance, ethics, risk and information security. 

Got a news tip? Get in touch. Want a weekly round-up in your inbox? Sign up for free. No subscription fees, no paywalls. 

Follow Us

Browse Topics:

  • CCI Press
  • Compliance
  • Compliance Podcasts
  • Cybersecurity
  • Data Privacy
  • eBooks Published by CCI
  • Ethics
  • FCPA
  • Featured
  • Financial Services
  • Fraud
  • Governance
  • GRC Vendor News
  • HR Compliance
  • Internal Audit
  • Leadership and Career
  • On Demand Webinars
  • Opinion
  • Research
  • Resource Library
  • Risk
  • Uncategorized
  • Videos
  • Webinars
  • Well-Being
  • Whitepapers

© 2026 Corporate Compliance Insights

Welcome to CCI. This site uses cookies. Please click OK to accept. Privacy Policy
Cookie settingsACCEPT
Manage consent

Privacy Overview

This website uses cookies to improve your experience while you navigate through the website. Out of these, the cookies that are categorized as necessary are stored on your browser as they are essential for the working of basic functionalities of the website. We also use third-party cookies that help us analyze and understand how you use this website. These cookies will be stored in your browser only with your consent. You also have the option to opt-out of these cookies. But opting out of some of these cookies may affect your browsing experience.
Necessary
Always Enabled
Necessary cookies are absolutely essential for the website to function properly. These cookies ensure basic functionalities and security features of the website, anonymously.
CookieDurationDescription
cookielawinfo-checbox-analytics11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Analytics".
cookielawinfo-checbox-functional11 monthsThe cookie is set by GDPR cookie consent to record the user consent for the cookies in the category "Functional".
cookielawinfo-checbox-others11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Other.
cookielawinfo-checkbox-necessary11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookies is used to store the user consent for the cookies in the category "Necessary".
cookielawinfo-checkbox-performance11 monthsThis cookie is set by GDPR Cookie Consent plugin. The cookie is used to store the user consent for the cookies in the category "Performance".
viewed_cookie_policy11 monthsThe cookie is set by the GDPR Cookie Consent plugin and is used to store whether or not user has consented to the use of cookies. It does not store any personal data.
Functional
Functional cookies help to perform certain functionalities like sharing the content of the website on social media platforms, collect feedbacks, and other third-party features.
Performance
Performance cookies are used to understand and analyze the key performance indexes of the website which helps in delivering a better user experience for the visitors.
Analytics
Analytical cookies are used to understand how visitors interact with the website. These cookies help provide information on metrics the number of visitors, bounce rate, traffic source, etc.
Advertisement
Advertisement cookies are used to provide visitors with relevant ads and marketing campaigns. These cookies track visitors across websites and collect information to provide customized ads.
Others
Other uncategorized cookies are those that are being analyzed and have not been classified into a category as yet.
SAVE & ACCEPT
No Result
View All Result
  • About
    • About CCI
    • Writing for CCI
    • NEW: CCI Press – Book Publishing
    • Advertise With Us
  • Explore Topics
    • See All Articles
    • Compliance
    • Ethics
    • Risk
    • Artificial Intelligence (AI)
    • FCPA
    • Governance
    • Fraud
    • Internal Audit
    • HR Compliance
    • Cybersecurity
    • Data Privacy
    • Financial Services
    • Well-Being at Work
    • Leadership and Career
    • Opinion
  • Vendor News
  • Downloads
    • Download Whitepapers & Reports
    • Download eBooks
  • Books
    • CCI Press
    • New: Bribery Beyond Borders: The Story of the Foreign Corrupt Practices Act by Severin Wirz
    • CCI Press & Compliance Bookshelf
    • The Seven Elements Book Club
  • Podcasts
    • Great Women in Compliance
    • Unless: The Podcast (Hemma Lomax)
  • Research
  • Webinars
  • Events
  • Subscribe

© 2026 Corporate Compliance Insights