← All insights

Agentic AI: New Governance Challenges for Boards and Executives

Published: 28 January 2026

Agentic AI: New Governance Challenges for Boards and Executives

Agentic AI systems independently build multi-step action plans, use tools, and carry out operational actions. This sets them apart from classic and generative AI. They do not just analyse. They act, partly on their own. Research is moving fast, but no generally accepted standard exists yet.

This shifts responsibility structurally. Decision logic and risk rules are already fixed at the design and architecture stage. That makes agentic AI a strategic topic at board level.

Relevance for the board

1. Risk and control architectures are changing: Autonomous or semi-autonomous systems can take actions that are harder to predict and harder to trace. Multi-agent environments create additional emergent interactions that today’s control systems often miss. Standards such as the NIST AI RMF or ISO/IEC 42001 offer initial orientation, but only partially cover agentic AI.

2. Responsibility and liability stay unchanged: Legally, responsibility remains with the company and its governing bodies. Ex-post attribution becomes more complex, because actions no longer arise exclusively from linear, pre-approved processes. Governance must define responsibilities clearly across the entire lifecycle.

3. Strategic design, not an operational IT question: With agentic AI, risk tolerances, decision logic and escalation rules are pushed forward into the technical layer. The question of how much autonomy a system gets, and where human oversight is mandatory, belongs at board level.

Key governance action areas

1. Ex-ante risk assessment: Boards need clear criteria to determine which processes suit agentic AI systems. What matters is the degree of autonomy, reversibility, access to sensitive data, and potential for harm.

2. Effective human accountability: Autonomy requires clear intervention and escalation paths. Risks such as automation bias must be factored in. For irreversible or liability-relevant actions, human sign-off is mandatory.

3. Technical enforcement of governance: Governance has to be enforced technically, for example through control boundaries, structured testing and continuous monitoring. What counts is the effectiveness of the controls, not technical depth for its own sake.

4. The role of users and skills development: Users are part of the governance system. Transparency, training and clear accountability are essential. At the same time, there is a risk of skills erosion as agentic AI takes over more operational tasks.


Decision questions for the board

  • Where is agentic AI strategically useful, and where do we draw clear limits?
  • Which actions may systems perform autonomously, and which require sign-off?
  • Are roles, responsibilities and control mechanisms clearly defined across the lifecycle?
  • Do we have effective technical and organisational early-warning systems in place?
  • Are management and control functions sufficiently skilled, or is training needed?

Conclusion. Agentic AI is a governance and steering question. Its lasting value does not come from technical capability. It comes from clear guardrails and robust governance structures.

If agentic AI is not yet an explicit board-level topic, it is worth a closer look. I help leadership bodies strengthen their decision-making capacity around AI and position governance questions strategically.