Enterprises in the US, Canada, UK and Germany are handing autonomous AI the keys to core workflows faster than they can answer a basic question: who is accountable when it acts on its own?
Optro’s latest report, “When AI leaves the chat and enters the workflow”, warns that as organisations move from conversational generative AI to autonomous agents embedded in business processes, the old question — can we trust what AI produces? — is being overtaken by a harder one: how do you govern something that acts?
Adoption outruns governance as incidents mount
One in three organisations already use AI in critical resilience workflows, yet agentic AI failure — loss of control or autonomous decision-making failures — is the disruption scenario they test least, with 30% never testing for it at all.
Distributed ownership, periodic review cycles and policy-based controls that strain under supervised AI are “structurally incapable” of governing systems acting autonomously at machine speed, the report argues.
The consequences are already visible: in the past 12 months, 40% of organisations reported inaccurate AI outputs, 27% reported data breaches and 26% reported regulatory action tied to AI use.
Confidence is outpacing control. While 58% of leaders believe their governance controls are keeping pace with AI adoption, only 18% have active risk mitigations in place.
Nearly two-thirds of organisations experienced an AI agent-related incident in the past year, resulting in data exposure, operational disruption and financial losses, and almost half of security decision-makers name agentic AI as a top security concern.
Agents are non‑human identities without inventory
Autonomous agents authenticate, access systems and act, making them non‑human identities that often sit outside IT’s view.
Although 85% of organisations have integrated AI into core operations, only a quarter have comprehensive visibility into how employees are using it, meaning business units are deploying agents that IT does not know exist.
Regulators, meanwhile, still expect a named, accountable human behind every decision affecting a customer, a market or a filing; “AI decided” is not defensible.
Implications for Asia: redesign accountability now
For Asian enterprises watching Western peers, the report frames this as a closing window: organisations that redesign accountability now do so on their own terms; those that wait will do it later under enforcement, remediation or after an incident.
“The reality today is that agentic AI adoption is fast outpacing governance,” said Guru Sethupathy, GM of AI governance at Optro.
“Redesigning governance isn’t about pulling back on innovation; it’s about building the control structure to give organizations the confidence to scale AI faster and more reliably than the competition.”
“The teams that get agentic compliance right will build governance and accountability frameworks for how an agent behaves and what it’s able to touch,” said Mark Taylor, director, Information Security Risk Management at Newell Brands.
“Establishing that structure proactively positions organizations to scale AI safely, prevent future incidents, and execute with either humans in the loop or on the loop where appropriate.” Mark Taylor
For COOs in Asia, the lesson from the US, Canada, UK and Germany is clear: competitive advantage will accrue to those that treat accountability as a design constraint for agentic AI, not an afterthought.


