The rise of the agentic enterprise
Guest blog by Lucie MacNeill, Marketing Lead at Condatis #AISecurity
For the past two years, enterprise conversations about AI have largely focused on productivity and conversational AI.
Can AI help employees work faster? Can it reduce administrative effort? Can it improve efficiency?
The answer has overwhelmingly been yes.
Across every sector, organisations have adopted AI assistants, Copilots and automation tools to help employees draft content, analyse information, summarise data and accelerate routine tasks. Employees are reporting productivity benefits and organisations remain enthusiastic about AI's potential. Yet many leaders are beginning to question how those gains translate into measurable business outcomes. As the economics of AI adoption come under greater scrutiny, attention is shifting from productivity alone to how AI can create new business value responsibly.
How can AI create entirely new business value responsibly?
That question represents a fundamental shift in thinking. It moves AI from being an employee productivity tool to becoming part of the operating model of the organisation itself. This is the foundation of the Agentic Enterprise.
From Productivity to Business Value
Most AI adoption today still follows a familiar pattern, humans perform the work, AI assists them. An employee asks a Copilot for help writing a document, a service desk analyst uses AI to summarise an incident, a project manager might generate a report more quickly than before. The human remains at the centre of the process, otherwise known as ‘human in the loop’.
The Agentic Enterprise takes a different approach. Rather than applying AI as a standalone assistant at the point of interaction, organisations begin embedding AI directly into core business workflows and processes. Human judgement, experience and accountability remain fundamental, but AI becomes part of how work is planned, coordinated and executed across the organisation.
The shift is not about removing people from the workflow. It is about determining where AI can add value, where automation is appropriate and where human expertise should remain central to decision-making. In this model, people and AI work together, each contributing where they are most effective.
In this model:
-
Organisations first identify where AI can create value, which workflows are suitable for automation and where human judgement should remain central. AI is a powerful tool, but it is not the right solution for every task or process.
-
Every employee becomes what Microsoft describes as a "Frontier Worker", using AI as part of their day-to-day work where it adds meaningful value.
-
Agents increasingly execute business processes
-
Organisational intelligence is created once and reused across multiple workflows
-
Data platforms become AI-ready by design
-
Governance is established centrally
-
Business processes are redesigned, not simply accelerated
The result isn’t incremental efficiency; it’s fundamentally a different way of operating.
This shift is happening against a wider AI security backdrop. In IBM’s Cost of a Data Breach Report 2026, developed with research from the Ponemon Institute, one theme is clear: as AI becomes more deeply embedded in enterprise operations, the risks are no longer limited to the model itself. They increasingly sit in the connected systems, identities, APIs and cloud environments that allow AI to act. AI risks exist with or without autonomy, but the shift from assistance to action makes control, accountability and assurance more urgent.
The Emergence of Systems of Action
Historically, enterprise technology has been built around systems of record; applications stored information, people reviewed it, interpreted it and decided what actions to take next. Agentic AI introduces a new model: the system of action.
Agents can understand context, reason over organisational knowledge, make recommendations and increasingly execute actions across business systems. However, the goal is not to remove people from the process. Instead, organisations must determine where AI is best applied within a workflow and where human judgement, experience and oversight remain essential. This is the movement from human-operated workflows towards AI-powered systems where people and AI work together to plan, decide, act and learn more effectively.
This is where the potential business value becomes significant - customer onboarding can be accelerated, operational decisions can be automated, compliance monitoring can become continuous and supply chain processes can adapt dynamically. In many cases, AI can handle routine or data-intensive activities, while people provide direction, accountability and decision-making at critical points in the workflow.
As such, the conversation moves from productivity gains to measurable business outcomes.
Why Trust Becomes the Critical Challenge
The opportunity with this is compelling, however the challenge becomes about trust. An AI assistant that drafts an email carries relatively low risk. An autonomous agent that can approve transactions, access sensitive information or execute business processes is a very different proposition.
The IBM report gives this point useful context. It suggests that many organisations are already using AI in security operations, particularly to help teams detect, investigate and respond more quickly. But the same level of maturity is not always being applied to earlier-stage controls, such as finding and fixing vulnerabilities before they are exploited. For business leaders, that creates an important tension: AI may help organisations move faster, but without stronger preventative governance, it can also expose where control models have not kept pace.
Every step towards an agentic enterprise creates a new set of questions:
-
Where is AI best used in our workflows?
-
Who has access?
-
What can the agent see?
-
What actions is it authorised to perform?
-
Who owns it?
-
Who is accountable for its decisions?
-
How is it governed?
-
How is risk monitored and controlled?
These are no longer just AI questions. They are identity, governance, security and accountability questions.
The same is true of non-human identity. The IBM report highlights that many organisations are still in the early stages of securing the machine identities that sit inside AI workflows. That matters because agents will not operate in isolation. They will connect to applications, APIs, data stores and cloud services, and those connections will need to be discovered, governed, monitored and retired with the same discipline already expected for human users.
Microsoft’s recent Humanist AI Code of Conduct reinforces this point: as AI systems become more capable and agentic, they should remain subordinate, aligned, contained and under meaningful human control. For enterprise leaders, that principle matters because agents are beginning to operate across systems, data and workflows. Governance therefore needs to define not only what agents can do, but how they are authorised, constrained, monitored, interrupted, retired and held accountable.
The reality is that AI can only scale when organisations are confident that agents operate within defined boundaries, follow organisational policy and remain visible, governable and accountable throughout their lifecycle.
So, without trust, adoption stalls and without governance, risk grows faster than value.
Identity Becomes the Control Plane
For years, digital identity has been viewed primarily as a security function; authentication, access control, user lifecycle management. However, as organisations adopt AI and autonomous agents, identity becomes something much more strategic.
Agents require access to systems, authority to perform actions and accountability and governance throughout their lifecycle. Organisations will need to manage AI agents as a new category of enterprise identity, subject to the same levels of visibility, governance and assurance expected of privileged human users.
This is why agentic AI cannot be treated as a standalone technology programme. Every useful agent depends on identity architecture: the permissions it is granted, the context it can interpret, the systems and data it can access, and the accountability model that governs its actions. The model may attract the attention, but the surrounding identity controls will determine whether AI can move from experimentation to trusted enterprise-scale adoption.
The organisations that succeed in the next phase of AI adoption will be those that answer a sharper question: do we know who or what is acting, what it is authorised to do, what evidence supports its decisions and who remains accountable?
If the answer is no, scaling AI becomes extraordinarily difficult.
Preparing for the Agentic Enterprise
Organisations should not begin their AI journey with models, agents or technology platforms, they should begin with outcomes.
What business value are we trying to create?
Which processes should be transformed?
Which decisions should remain human-led?
What level of autonomy is appropriate?
What risks are acceptable?
Only then should technology decisions follow.
As AI moves from assistance to action, organisations need governance frameworks that define ownership, authority, accountability and control before autonomous agents become embedded within critical operational workflows.
The Opportunity for Business Leaders
Most organisations already have employees experimenting with AI and many are evaluating agents.
Technology teams are exploring automation opportunities at pace, the challenge is no longer whether AI will become part of the enterprise – because it will.
The real challenge is whether leadership teams can establish sufficient trust, governance and accountability before AI becomes embedded within the fabric of the organisation.
Organisations that succeed will not necessarily be the first to adopt AI. They will be the first to scale it with confidence. That confidence will be built on foundations that have always mattered: identity, governance, security, accountability and trust.
In the age of the agentic enterprise, those foundations are becoming more strategic than ever.
What to do next?
Organisations should start by challenging assumptions and asking what business value AI is expected to create, which decisions should remain human-led and what level of autonomy is appropriate. From there, they can connect IT, security, data, governance and business teams around a practical path to the agentic enterprise. Trusted advisers such as Condatis can help organisations define that path through Identity, Governance & Trust, so AI-enabled operations can scale with stronger trust, control and accountability.
Cyber Resilience Programme activities
techUK brings together key players across the cyber security sector to promote leading-edge UK capabilities, build networks and grow the sector. techUK members have the opportunity to network, share ideas and collaborate, enabling the industry as a whole to address common challenges and opportunities together. Visit the programme page here.
Upcoming events
Latest news and insights
Learn more and get involved
Cyber Resilience updates
Sign-up to get the latest updates and opportunities from our Cyber Resilience programme.
Meet the team
Jill Broom
Head of Cyber Resilience, techUK
Jill leads the techUK Cyber Resilience programme, having originally joined techUK in October 2020 as a Programme Manager for the Cyber and Central Government programmes. She is responsible for managing techUK's work across the cyber security ecosystem, bringing industry together with key stakeholders across the public and private sectors. Jill also provides the industry secretariat for the Cyber Growth Partnership, the industry and government conduit for supporting the growth of the sector. A key focus of her work is to strengthen the public–private partnership across cyber to support further development of UK cyber security and resilience policy.
Before joining techUK, Jill worked as a Senior Caseworker for an MP, advocating for local communities, businesses and individuals, so she is particularly committed to techUK’s vision of harnessing the power of technology to improve people’s lives. Jill is also an experienced editorial professional and has delivered copyediting and writing services for public-body and SME clients as well as publishers.
- Email:
- [email protected]
- Website:
- www.techuk.org/
- LinkedIn:
- https://www.linkedin.com/in/jill-broom-19aa824
Read lessmore
Annie Collings
Senior Programme Manager, Cyber Resilience, techUK
Annie is the Programme Manager for Cyber Resilience at techUK. She first joined as the Programme Manager for Cyber Security and Central Government in September 2023.
In her role, Annie supports the Cyber Security SME Forum, engaging regularly with key government and industry stakeholders to advance the growth and development of SMEs in the cyber sector. Annie also coordinates events, engages with policy makers and represents techUK at a number of cyber security events.
Before joining techUK, Annie was an Account Manager at a specialist healthcare agency, where she provided public affairs support to a wide range of medical technology clients. She also gained experience as an intern in both an MP’s constituency office and with the Association of Independent Professionals and the Self-Employed. Annie holds a degree in International Relations from Nottingham Trent University.
- Email:
- [email protected]
- Twitter:
- anniecollings24
- LinkedIn:
- https://www.linkedin.com/in/annie-collings-270150158/
Read lessmore
Olivia Staples
Junior Programme Manager - Cyber Resilience, techUK
Olivia Staples joined techUK in May 2025 as a Junior Programme Manager in the Cyber Resilience team.
She supports the programs mission to promote cyber resilience by engaging key commercial and government stakeholders to shape the cyber resilience policy towards increased security and industry growth. Olivia assists in member engagement, event facilitation and communications support.
Before joining techUK, Olivia gained experience in research, advocacy, and strategic communications across several international organisations. At the Munich Security Conference, she supported stakeholder engagement and contributed to strategic communications. She also worked closely with local and national government stakeholders in Spain and Italy, where she was involved in policy monitoring and advocacy for both public and private sector clients.
Olivia holds an MSc in Political Science (Comparative Politics and Conflict Studies) from the London School of Economics (LSE) and a BA in Spanish and Latin American Studies from University College London (UCL).
Outside of tech, Olivia enjoys volunteering with local charities and learning Norwegian.
- Email:
- [email protected]
Read lessmore
Authors
Lucie MacNeill
Product Marketing Lead, Condatis
Lucie MacNeill is Product Marketing Lead at Condatis, responsible for their decentralised identity service, Condatis Credential Gateway. With over 7 years’ experience developing brand and positioning strategies across companies such as Skyscanner and Flo Health, Lucie specialises in mission-driven marketing with her current focus; building trusted digital relationships.