AI Agents Need Governance Before They Need Scale 

Artificial intelligence has entered a new phase. For several years, organizations focused on models, copilots, automation, and productivity. Attention is now turning to AI agents. 

The category is broad. Many current systems remain tightly scoped by copilots or workflow orchestrators. Others can act across tools and processes with greater authority. The degree of autonomy matters because it determines the access, control, and assurance an organization requires. 

That is why the question now dominating many executive conversations is not the most important one. 

“How quickly can we scale AI agents across the business?” 

Before organisations focus on scaling AI agents, they should ask whether they are prepared to govern them. The challenge ahead is not primarily technology deployment. It is accountability, oversight, trust and organizational readiness. 

The Scale Narrative 

Much of the industry discussion around AI agents is still framed as a scale problem: deploy more agents, automate more processes, reduce more manual effort, increase efficiency, accelerate productivity. Those objectives are understandable. Organizations have always looked to technology to improve how work gets done. 

Scale is nevertheless a poor primary measure of success. The assumption is that if a small number of agents creates value, hundreds or thousands will create more. Early cloud and robotic process automation programmes showed what happens when deployment outruns the operating model: fragmented ownership, inconsistent controls and process weaknesses that were already present, now running at higher speed. 

The risk is no longer analogical. In May 2026 Gartner warned that applying the same controls to every agent, regardless of autonomy and access, is a path to failure. It also forecast that by 2027 two in five enterprises will demote or withdraw autonomous agents after governance gaps appear in production. 

Technology adoption rarely fails because organizations lack technical capability. It fails when organizational capability does not evolve at the same pace. Governance, accountability, risk management, operating models, decision rights and oversight become the limiting factors. AI agents are unlikely to be an exception. 

From Automation to Autonomy 

Traditional automation has generally operated within defined boundaries. Rules are established. Inputs are understood. Outcomes are intended to be predictable. That did not prevent RPA programmes from failing for organizational reasons. It did mean the failure modes were familiar. 

AI agents introduce a different dynamic. They may interpret information, coordinate activities, prioritize actions, recommend decisions, initiate workflows, or engage multiple systems to pursue an objective. 

The organizational implications increase with the authority a system receives. A read-only assistant, an agent that recommends action, an agent that acts after approval, and an agent operating within delegated guardrails should not be governed in the same way. 

The more decision-making and execution authority entrusted to systems, the greater the need for clarity around accountability and governance. This is where the conversation often becomes uncomfortable. 

Technology can automate tasks. It cannot assume responsibility. 

No matter how autonomous a system becomes, accountability remains with people. Boards remain accountable to stakeholders. Executives remain accountable for outcomes. Leaders remain accountable for governance decisions. Autonomy changes how work is performed. It does not change who owns the consequences 

The Real Challenge Is Governance 

When organizations discuss AI agents, the conversation often centers on capability. What can the agent do? How accurate is it? How many tasks can it perform? How quickly can it be deployed? Those questions matter. They are not sufficient. 

The questions that determine whether autonomy creates value or risk sit with leadership, risk and the operating model: 

  • Who owns decisions influenced by the agent? 
  • Who is accountable when outcomes differ from expectations? 
  • How are decisions reviewed and challenged? 
  • How are risks identified and escalated? 
  • What level of transparency exists, and what assurance is in place? 

An Australian Operating Context 

For organizations operating in Australia, this is not an abstract international debate. The National AI Centre’s current guidance is no longer the 2024 Voluntary AI Safety Standard. It is the October 2025 Guidance for AI Adoption, which sets out six essential practices: decide who is accountable; understand impacts and plan accordingly; measure and manage risks; share essential information; test and monitor; and maintain human control. 

Those practices sit on top of law that already applies. Privacy, consumer, records and directors’ duties do not pause because a system is described as an agent. Agents do not create a new accountability regime. They stress-test the one organizations already have, including in public sector settings, where residual accountability remains with accountable authorities, not with the tool. 

Governance Is Not a Barrier to Innovation 

In some organizations governance is treated as bureaucracy: committees, documentation and compliance obligations. That interpretation misses its purpose. 

Effective governance creates confidence. It establishes clarity around decision-making, defines accountability, provides transparency and enables trust. Most importantly, it allows organizations to innovate without accumulating unmanaged risk. 

Without it, organizations may move quickly in the short term and slow down later as inconsistency and uncertainty accumulate. With it, leaders understand the boundaries within which innovation can safely occur. That means classifying agents by autonomy, impact, data access and action authority, then applying proportionate controls. 

Design-time approval establishes purpose, ownership, testing and permitted access. Runtime controls provide monitoring, traceability, intervention, escalation and rapid rollback when behavior moves outside agreed boundaries. 

Governance should not be viewed as a prerequisite that delays adoption. It is the capability that enables scale with confidence. 

Agents Do Not Stay in One System 

AI agents inherit the access of the cloud estate they sit on. A deployment that looks local rarely stays local. Once an agent can initiate work, it can cross processes, data stores and control boundaries that the original business case never named. 

Consider a finance agent authorized to reconcile accounts, initiate payment workflows or flag customer credit exceptions. A local efficiency decision may alter customer treatment, liquidity, fraud exposure, regulatory reporting or operational risk in another domain. 

The control question is therefore not only whether the agent performs its assigned task. It is whether leaders can see, attribute, challenge and reverse effects that travel across the operating model. That is a cloud and AI strategy problem: identity, access, placement and accountability have to follow the action, not the team that sponsored the pilot. 

Trust Is an Organizational Outcome 

Trust cannot be engineered solely into a model. Transparency, explainability, monitoring, security, auditability and reliability all matter. People nonetheless trust systems when they understand how decisions are governed, who is accountable, and how exceptions are handled. 

The organizations most likely to succeed with AI agents will not be those with the most advanced technology alone. They will be those able to demonstrate how autonomous systems are governed, monitored, reviewed and, when required, stopped. 

Executive Implications 

For executive leaders, the rise of AI agents should change the operating agenda, not merely the technology roadmap. 

  • Measure readiness and outcomes, not agent count. Deployment volume is an activity metric. Value, control and the ability to intervene are the results that matter. 
  • Name an accountable owner for every agent that can act. If no executive will put their name against the outcome, the agent is not ready for production authority. 
  • Classify agents by autonomy and access, then apply proportionate controls. A read-only assistant and an agent that can change records or move money should not pass through the same gate. 
  • Put design-time approval and runtime intervention in place before scale. Purpose, ownership, testing and permitted access belong at design time. Monitoring, exception handling, audit trails and a tested rollback path belong at runtime. 
  • Maintain an enterprise agent inventory. Record identity, owner, purpose, systems touched, data scope, authority level and a kill path. You cannot govern agents you cannot name. 

Governed Autonomy Before Autonomous Scale 

The potential of AI agents is significant. Deployment volume is not a substitute for organizational readiness. Sustainable value depends on whether decision rights, controls, operating models and the cloud estate evolve alongside the technology. 

The organizations that lead will know which agents may observe, advise, act with approval, or act within delegated boundaries. They will govern each accordingly. They will match authority with accountability, access with control, and speed with the ability to intervene. 

The critical question is not how many AI agents an organization can deploy. The critical question is whether it can govern them. 

That answer will determine whether autonomy becomes a source of sustainable value or unmanaged risk. 

Autonomy can be delegated. Accountability cannot. 

Further Reading & References 

The following sources support the argument. They are offered as working references for executives, not as a reading list to be completed before action. 

Evidence and risk 

Gartner, May 2026 — Applying uniform governance across AI agents, regardless of autonomy and access, will lead to enterprise failure. Forecast: by 2027, 40 percent of enterprises will demote or decommission autonomous agents after governance gaps appear in production. 

https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure

NIST AI Risk Management Framework — Risk management, accountability, measurement and oversight for AI systems. 

https://www.nist.gov/itl/ai-risk-management-framework

OECD AI Principles — International principles on accountability, transparency, human oversight and robustness. 

https://oecd.ai/en/ai-principles

ISO/IEC 42001:2023 — The first international management system standard for organizational AI governance. 

https://www.iso.org/standard/81230.html

Australian guidance 

Guidance for AI Adoption — Current Australian Government guidance. Six essential practices for responsible AI governance and adoption. 

https://www.industry.gov.au/publications/guidance-for-ai-adoption

Guidance for AI Adoption: Foundations — Practical guidance for organizations starting out or using AI in lower-risk settings. 

https://www.industry.gov.au/publications/guidance-for-ai-adoption/guidance-ai-adoption-foundations

Guidance for AI Adoption: Implementation — Detailed guidance for more complex or higher-risk use. 

https://www.ai.gov.au/staying-safe-and-responsible/essential-ai-practices/guidance-ai-adoption-implementation-guidance

Voluntary AI Safety Standard — The earlier voluntary standard that has evolved into the Guidance for AI Adoption. 

https://www.industry.gov.au/publications/voluntary-ai-safety-standard

Responsible AI 

Microsoft Responsible AI — principles and approach — Vendor-published governance principles. Cited as one industry approach, not as a recommended platform. 

https://www.microsoft.com/en-us/ai/principles-and-approach

Microsoft Responsible AI tools and practices — Includes the Responsible AI Standard and related assessment materials. 

https://www.microsoft.com/en-us/ai/tools-practices

ISACA artificial intelligence resources — Assurance, audit, risk and digital trust material for AI-enabled organizations. 

https://www.isaca.org/resources/artificial-intelligence

Related My Tech Stuff reading 

Ambient Intelligence: When AI Moves Off the Screen — August 2026. Governance when AI becomes less visible and more embedded in work. 

The Sentient Data Stack — July 2026. Governing cloud data systems that begin to shape outcomes. 

AI-Driven Autonomous Clouds — March 2026. Autonomy in infrastructure and the operating model required to control it. 

Cloud in Healthcare: How Australia is Using AI to Transform Digital Health 

What if your next medical breakthrough isn’t a new drug or device— 
but the cloud infrastructure running quietly behind the scenes? 

Australia’s healthcare system is undergoing a quiet revolution. And at the heart of it isn’t just AI, or machine learning, or cutting-edge telehealth tools—it’s the rapid evolution and reach of cloud computing. 

From telemedicine in remote towns to real-time hospital analytics in the CBD, cloud infrastructure is no longer an IT decision. It’s a care decision. And it’s accelerating faster than most organisations are ready for. 

The Rise of Cloud in Australian Healthcare 

Cloud computing in Australian healthcare has gone from experiment to essential. 

In 2022–23, 20% of all GP services were delivered via telehealth—phone and video are now a standard part of care delivery, particularly in rural and aged care settings. 

Electronic Health Records (EHRs) are evolving from static repositories to dynamic, AI-ready platforms. 

Predictive analytics is helping hospitals forecast admissions, manage resources, and reduce waiting lists. 

But with every new capability comes a challenge: integration, security, governance, and compliance. 

Cloud has shifted from a back-end technology to a strategic engine for growth and innovation. It’s becoming the backbone of modern health delivery—and the risk and compliance surface has expanded accordingly. 

AI in Action: Smarter, Faster, Fairer Care 

Australia is at the forefront of AI and ML innovations in healthcare. 

  • AI triage bots are helping assess symptoms and direct patients to appropriate care pathways. 
  • Machine learning models are predicting patient deterioration in emergency rooms. 
  • Natural language processing is accelerating clinical documentation, giving practitioners more time with patients. 
  • Computer vision is assisting radiologists in detecting anomalies more quickly and accurately. 

These use cases are not hypothetical. They are operational today—and they rely on scalable, secure cloud environments. 

However, these technologies are only as strong as the infrastructure they run on. And in healthcare, that infrastructure must meet an exceptionally high bar. 

The Privacy and Compliance Tightrope 

Healthcare cloud adoption in Australia must navigate a complex environment of privacy laws, ethical obligations, and system-wide compliance expectations. 

Technology teams supporting healthcare are not simply managing digital records—they are stewards of public trust. 

The Privacy Act 1988  and the My Health Records Act 2012  impose clear responsibilities around data sovereignty, consent, and transparency. 

The Australian Digital Health Agency maintains national standards for interoperability, access controls, and cybersecurity. 

Accreditation frameworks such as ISO/IEC 27001  and IRAP (Information Security Registered Assessors Program) are becoming mandatory in procurement processes. 

Choosing the wrong cloud partner is not just a technical oversight. It becomes a compliance issue, a reputational risk, and an ethical liability. 

Choosing the Right Cloud Partner for Healthcare in Australia 

For healthcare leaders, selecting a cloud partner in healthcare is no longer a purely operational decision—it is a strategic one. 

At a minimum, ensure your cloud solution offers: 

  • Data residency within Australia 
  • IRAP-assessed infrastructure 
  • Proven interoperability with national digital health systems 
  • Capacity to support AI and machine learning workloads 
  • Transparent security protocols, SLAs, and audit trails 

Above all, choose a partner who understands that in this sector, the goal is not disruption. The goal is safe, sustainable, patient-focused innovation. 

Final Thought 

If you’re leading technology in a healthcare organisation, the question is no longer whether cloud and AI should be adopted. 

The real question is: are we building the kind of infrastructure that can support the next decade of health innovation? 

Because in the end, this is not just about platforms and data. It is about empowering clinicians. It is about faster, more informed decisions. And ultimately, it is about improving lives—quietly, securely, and intelligently in the background. 

Let’s build that future—thoughtfully, together. 

Resources 

1. MBS Telehealth Post-Implementation Review Final Report 
https://www.health.gov.au/sites/default/files/2024-06/mbs-review-advisory-committee-telehealth-post-implementation-review-final-report.pdf 

2. Patient Experiences in Australia 
https://www.abs.gov.au/statistics/health/health-services/patient-experiences/latest-release 

3. Australia Telehealth Market Report 2025–2034 
https://www.expertmarketresearch.com.au/reports/australia-telehealth-market 

4. Privacy Act 1988 
https://www.oaic.gov.au/privacy/privacy-legislation/privacy-act-1988 

5. My Health Records Act 2012 
https://www.legislation.gov.au/Details/C2012A00184 

6. IRAP – Information Security Registered Assessors Program 
https://www.cyber.gov.au/acsc/view-all-content/programs/irap 

7. ISO/IEC 27001 – Information Security Management 
https://www.iso.org/isoiec-27001-information-security.html 

8. FHIR (Fast Healthcare Interoperability Resources) 
https://www.hl7.org/fhir/ 

9. Real-Time AI for Patient Deterioration Prediction

Source: National Library of Medicine (PubMed)

https://pubmed.ncbi.nlm.nih.gov/37150397/

10. AI Chatbots in Australian Healthcare

Source: University of Melbourne, Pursuit
https://pursuit.unimelb.edu.au/articles/the-promise-and-peril-of-ai-chatbots-in-healthcare

11. Computer Vision in Radiology (SA Medical Imaging)

Source: Adelaide Now (News Corp Australia)
https://www.adelaidenow.com.au/news/south-australia/artificial-intelligence-advising-on-xray-diagnoses-in-sa-medical-imaging/news-story/ae20cc4c30320354069d586ca1d23846

Harnessing the Power of Teamwork: The Secret Ingredient to Successful Sailing

Sailing is a thrilling and adventurous pastime that has captivated enthusiasts for centuries. For many sailors, the allure of being out on the open water, feeling the wind in their hair and the sun on their faces, is an unmatched experience. But there’s more to sailing than just enjoyment – there’s a valuable lesson in teamwork. This past Saturday, I had the pleasure of racing as part of a crew on a sailboat, and it reaffirmed my belief in the power of teamwork not just on the water, but everywhere.

The Essence of Teamwork in Sailing

Sailing a boat, especially during a race, is a complex and demanding task that requires the seamless coordination of multiple roles. From trimming the sails and adjusting the course to monitoring the weather conditions and making tactical decisions, every crew member plays a crucial role in the success of the journey.

When you’re part of a sailing crew, you quickly learn that no individual can single-handedly manage the boat. It takes a collective effort, with each person contributing their skills and knowledge, to navigate the vessel efficiently and safely. The importance of teamwork in sailing can be distilled into three key aspects: communication, trust, and collaboration.

  1. Communication
    Clear and effective communication is the backbone of any successful sailing team. Crew members must constantly relay information to one another, from changes in wind direction to potential obstacles ahead. Timely and accurate communication is crucial in making quick decisions, especially when racing against other boats or dealing with unpredictable weather conditions. Good communication also helps to foster camaraderie, enabling the crew to work together more effectively.
  2. Trust
    Sailing a boat at high speeds and in challenging conditions requires a tremendous amount of trust in your fellow crew members. You need to have confidence that each person will fulfill their role competently and that they will have your back when you need support. This trust is earned over time, through practice and experience, and it’s essential to the crew’s overall success.
  3. Collaboration
    When a sailboat crew works together in harmony, the result is a finely-tuned machine. Each crew member must be aware of the others’ responsibilities and be prepared to step in and assist when necessary. This collaborative mindset is the key to overcoming challenges, adapting to changing conditions, and ultimately, winning races.

Being part of a sailboat crew has taught me the importance of teamwork in a way that few other experiences can. Out on the water, the stakes are high, and every decision counts. By fostering a strong team dynamic through communication, trust, and collaboration, a sailing crew can overcome obstacles, adapt to changing circumstances, and reach their destination successfully.

Whether you’re a seasoned worker or new to a workforce, never underestimate the power of teamwork. So, the next time you’re part of a team, remember to support one another, communicate openly, and work together – and you’ll find that success is smooth sailing.

Spinning ever faster

The world’s not spinning any faster… but working in IT these days sees my thoughts spinning faster than ever. I’m a career IT guy and I have to stay on top of this stuff. Not just for my career, but it’s just who I am. It’s in my DNA.

I’ve done this tech stuff for a long time, and I’m pretty quick on the uptake. But it’s getting crazy out there. The rate of tech advance increases day by day, creating new or deeper specializations over time. It’s a time-consuming effort to maintain the general knowledge to manage IT well.

Mind you, that general knowledge is actually highly specialized tech knowledge. And very valuable it is too. So, in an effort to make it more accessible for myself, I’m gong to start writing down my thoughts. Maybe even organizing them.

And perhaps they will be useful not just for me. So here we go…