← All posts AI Governance

Govern Your AI Agents Before They Run Riot

Quick answer

BCG's August 2026 research shows centralised AI governance cuts agent deployment from weeks to a day. UK SMEs should inventory their AI tools, tier agents by risk, and log what each agent actually does.

Why proper AI agent governance makes you faster, not slower — and the three simple things UK SMEs should do about it.

By Matty Hatton·24 August 2026·4 min read

I see this all the time with UK SMEs. Someone in ops starts using an AI copilot. Someone in sales wires an agent into the CRM. Finance are quietly pasting spreadsheets into a chatbot because it's quicker than asking IT.

Six months later, AI is running through half the business and not one person can tell you what it can touch, who owns it, or what it did last Tuesday.

Sound familiar? BCG put out some research this month on exactly this, and it's worth ten minutes of your time.

What the research says

BCG's August 2026 piece, "Enterprise AI Control Plane", has a blunt headline finding: AI agents are scaling faster than enterprise governance. Teams are deploying agents quicker than anyone can keep track of them, and those control gaps are where the risk lives.

But here's the bit that surprised me. BCG reckons a centralised governance layer — one place that knows what runs, what it can access, how it acts and who owns the risk — can cut agent deployment from weeks down to a day. That's a 10x speed-up.

Governance done properly makes you faster, not slower. The bottleneck was never the rules — it's the not knowing.

Why it matters

The industry numbers back this up. Surveys suggest roughly 79% of enterprises have adopted AI agents in some form, but only around 11% are running them in production. That gap isn't down to lack of enthusiasm. It's trust. People won't let an agent anywhere near a live process if they can't see what it's doing or prove it behaved itself.

And if you're a manufacturer running Infor LN or any ERP, an agent touching orders, stock or customer data with no audit trail is a proper nightmare waiting to happen.

What to actually do

You don't need an enterprise control plane. You need the SME version, and it's dead simple:

  • Keep an inventory. One page: every AI tool and agent in the business, who owns it, what data it touches. Takes an afternoon to set up and saves months of grief.
  • Tier by risk. An agent drafting emails? Crack on. An agent touching ERP data, customer records or anything that leaves the building? That one gets a human check before it acts.
  • Log what agents do. Anthropic's own engineering guidance says the same — start simple, make actions visible and reviewable. If you can't reconstruct what an agent did yesterday, you can't trust it today.

Governance isn't a brake. Done right, it's the thing that lets you put your foot down.

References & Further Reading

  1. BCG, Enterprise AI Control Plane: The CIO's Guide to Governing and Accelerating AI Agents (August 2026)
  2. Anthropic, Building Effective Agents
  3. USETECH, 10 AI Trends Shaping Enterprise Technology in 2026

Got agents already running wild?

I help UK SMEs get their data and AI house in order — inventory, governance, agent audit trails, the lot. Sorted properly, without the enterprise red tape.

Let's have a chat

Matty Hatton is the founder of Digital Adaption, an ERP and data consultancy based on the Wirral. He has spent 15 years delivering ERP transformations for manufacturers, including leading the data migration on a £4.5m consolidation of four legacy systems onto a single Infor LN cloud instance for a 220-user group. He holds an MSc in Digital Transformation and IT Strategy from Manchester Metropolitan University and is Microsoft PL-200 certified.

LinkedIn | Get in touch

Got a version of this problem?

Start with a 30-minute data risk call.