Skip to main content

AI Readiness & Strategy

Agentic AI Is the Easy Part. Trusting It to Act Is the Hard Part.

Agentic AI capability is now commodity. The authority to act is not. What a named owner signs for before an agent commits the organisation to something.

By Sandeep Sudarshan14 min read
The same enterprise records feeding two paths: an advisory path where the answer passes a human check before anything happens, and an agentic path with no checkpoint, where the action is written straight into the system of record
88%
Organisations using AI in at least one function (McKinsey, 2025)
7%
Organisations reporting AI fully scaled (McKinsey, 2025)
95%
GenAI pilots with no measurable P&L impact (MIT, 2025)
4
Conditions a named owner signs for before an agent acts

Agentic AI is limited less by model capability than by authority. Before an agent acts on enterprise data, a named person has to be accountable for what it does, and that accountability rests on four things: governed data, permissions that are enumerated rather than inherited, a known cost of reversal, and the ability to detect a wrong action without being told about it.

Every enterprise leadership conversation this year eventually lands on agentic AI. Agents that do not just answer questions but take actions — process a claim, reroute a shipment, approve a transaction, update a system of record — without a human in the loop for every step.

The appetite is real. The readiness usually is not. McKinsey's 2025 global survey found 88% of organisations using AI in at least one function and about 7% reporting it fully scaled. MIT's 2025 study of enterprise generative AI put roughly 95% of pilots at no measurable impact on the P&L. Those figures describe systems that mostly advise. Agents that act raise what is at stake without changing what is underneath.

Key idea

The part that is not on anyone's price list

A model, an orchestration framework and a set of tool integrations can all be bought this quarter. The basis on which a named person lets software commit the organisation to an action cannot be, and that is the part most agentic business cases leave out.

Capability got cheap and authority did not

What this means for you: the part of an agentic programme you can buy is now the cheap part, and the part you have to build internally decides whether it ships.

Agentic AI describes software that plans and executes multi-step work against real systems rather than returning text for a person to act on. The distinction that matters commercially is not how the plan is produced. It is that the last step writes somewhere.

Three years ago the capability was the constraint. It is not any more, and it is worth being specific about that: whether a team builds on LangGraph, Azure AI Foundry, Amazon Bedrock Agents or an in-house stack, the planning loop, the tool contracts and the memory design are now well-documented engineering rather than research. Our own agentic AI practice spends far less time on that layer than it did.

What has not moved is the basis on which an organisation permits software to act in its name. That is an accountability question, and no purchase order settles it.

What changesAdvisory AIAgentic AI
Where the output landsOn a screen, in front of a personIn a system of record, or with a counterparty
Who catches an errorThe reader, usually within secondsNobody, until something downstream disagrees
How a failure surfacesVisibly and at onceAt reconciliation, often weeks later
What is at riskOne answer, one decisionEvery record touched, and everything derived from them
Who is accountableThe person who acted on the adviceThe person who granted the authority
What has to be true firstThe reader knows the subjectGoverned data, enumerated permissions, known reversal cost, detection

The question that actually decides it

What this means for you: the evaluation criteria most agentic programmes run on do not contain the question that determines whether the thing ever reaches production.

Most organisations evaluating agentic AI are asking which platform, which model, which vendor. Those questions have answers, the answers are comparable on a slide, and procurement is comfortable with them.

The question that actually determines success is simpler and less exciting: can this agent be trusted to act on our data without a human checking its work every time?

That trust does not come from the model. It comes from what sits underneath it — the definitions the agent reads, the ownership behind those definitions, the lineage that says where a record came from, and the limits on what the agent is permitted to touch.

The same wrong output on two paths: on the left a person reads it and the error stops there, on the right nobody reads it, the record changes, and reporting, reconciliation and the next agent all inherit it

A wrong answer from a copilot is a visible event. Someone reads it, recognises it as wrong, and discards it. That person between the output and the consequence is doing quiet, unpaid quality control, and it is the reason advisory AI survives a shaky data foundation at all.

Remove that person and the economics invert. An agent acting on bad data writes the consequence into a system of record, and everything downstream inherits it as fact rather than as a suggestion. It fails quietly, confidently, and at scale.

Failure mode

The failure mode is silence, not error

An agent reading contested definitions does not stop and raise the contradiction. It picks an interpretation and proceeds. In our engagements the resulting problems surface at month-end reconciliation rather than at the point of the error, by which time the affected records are numerous and the agent has been trusted for weeks.

What you are actually signing

What this means for you: the sign-off on an agentic use case is a transfer of authority, and it is worth knowing what four things you are asserting when you give it.

Trust in an agent is not a property of the model and it is not established by a vendor assurance. It decomposes into four conditions. An initiative that cannot answer all four is not ready, whatever it is built on.

01

The data is owned

The agent reads definitions somebody owns by name, from sources with known lineage, validated on the way in rather than audited afterwards. Where two systems disagree about what a customer is, the agent will pick one and act on it without telling you which.

02

The authority is enumerated

What the agent may do is listed, and everything else is refused by default. Authority granted by omission is the common failure: an agent that can do whatever its service account can do holds the permissions of the person who configured it, not the permissions of the task.

03

The reversal cost is known

For every action the agent can take, somebody has established what it costs to undo — in money, in time, and in the conversation with a customer or counterparty. Actions that cannot be undone belong behind a human decision until the rest has earned its trust.

04

You would find out

A wrong action becomes visible without a person happening to notice it. This is the condition programmes skip first and the one everything else depends on, because an agent you cannot monitor is an agent you cannot correct.

Two of those are engineering problems with well-understood answers, and this is not the article that solves them. The gates an agent should pass on the way from retrieval to autonomy, and the evidence each one requires, are worked through in our production agentic AI deep-dive. If the question is whether your organisation is in a position to start at all, the five-dimension readiness framework scores it. The architecture those answers converge on, and what UK and EU regulation adds to it, sits in autonomous enterprise architecture and the GenAI governance operating model.

Authority to act resting on four stacked conditions — governed data, scoped authority, reversibility and detection — with detection marked as the one that does not bend, and missing any one meaning the agent is not ready

The commercial point is the one those pieces do not make. Conditions one and three are not engineering deliverables at all. They are somebody's name against a definition and somebody's number against a reversal, and no platform decision produces either.

Capability is procurement. Authority is accountability, and accountability does not transfer by buying anything.

Sequencing beats selection

What this means for you: the order in which you fund the work predicts the outcome more reliably than which platform you pick.

We have said this before about AI broadly, and it becomes non-negotiable once the agent acts rather than advises. The organisations getting real value from agentic AI are not the ones with the newest model. They are the ones that did the unglamorous work first: rationalising which systems actually hold reliable data, building a governed foundation, and only then layering autonomous decision-making on top of it.

Skip that step and what reaches production is something else entirely.

You are not deploying an intelligent agent. You are deploying a fast, confident way to scale existing data problems.

The sequencing argument is often heard as a delay tactic, and the two are worth separating. Sequencing correctly does not mean agentic work waits for a finished data governance programme — that finish line does not exist, because definitions move as long as the business does. It means the authority granted to an agent never runs ahead of the assurance underneath it.

Where the opportunity sits right now

What this means for you: your sector's history with regulation is a better predictor of how quickly you can grant an agent authority than your current AI budget.

The sectors moving fastest on agentic AI tend to be the ones whose data was already disciplined for other reasons. Banking and financial services is the clearest example. Regulatory reporting forced governed, lineage-traced data years before AI made it valuable, and those organisations are now collecting a return on an investment they made for an entirely different reason.

Sectors sitting on rich but fragmented data have the larger long-term opportunity and a longer run-up to it. Manufacturing is the clearest case: decades of operational data across plant systems, maintenance records and supply-chain platforms that were never reconciled to each other because nothing previously required it.

Banking and manufacturing on the same three stages: banking has governed data and scoped authority already settled by regulatory reporting and can grant authority now, manufacturing has both still to build, and the two run in parallel rather than in a queue

That is not a reason to wait. It is a reason to sequence correctly — fix the foundation in parallel with piloting agentic use cases in the areas where the data is already trustworthy, rather than either freezing entirely or granting authority everywhere at once.

In practice that means finding the domains inside your own estate that already look like banking: the ones where a regulator, an auditor or an expensive incident already forced the definitions to be settled and owned. Those domains usually have a data contract in all but name — an agreed shape, an owner, and a failure that lands on somebody. That is where an agent can act now. The rest of the estate is a roadmap, not a blocker.

Readiness signal

A domain ready for delegated authority

One owner who can settle a disagreement about a definition without escalating. A data contract, or its equivalent, that fails loudly upstream rather than silently downstream. A reconciliation somebody already runs and actually reads. Where a domain has these three, an agent can hold scoped authority there while the rest of the estate is still being repaired.

When withholding authority costs more than granting it

What this means for you: the trust apparatus can be disproportionate to the exposure, and insisting on all of it everywhere is its own kind of failure.

The argument so far runs one way, so it is worth stating the cases where it is the wrong argument.

Where the action an agent takes is cheap to reverse and small in value — a ticket reclassified, a draft prepared, a record flagged for review — the cost of the approval process can exceed the cost of being wrong several times over. Holding those behind a human queue does not buy safety. It buys latency, and it trains the organisation to route everything through people who then stop reading carefully.

Where the alternative is not a careful human but an unexamined legacy rule, the comparison is also not the one people think they are making. A batch job written in 2014 that nobody can explain is making autonomous decisions already. It simply does not get called an agent, and nobody signs for it annually.

In practice

What we do in that situation

In our engagements the workable split is by reversal cost rather than by capability. Actions that are cheap to undo get scoped authority early, with detection in place. Actions that reach a customer, move money or cannot be restored stay behind a person until the evidence from the first group justifies moving the line.

None of that is a licence to skip the foundation. Each is an argument about proportion, not about whether the conditions apply. The condition that does not bend is detection: shipping an agent whose mistakes are invisible is not a trade any deadline justifies.

The conversation to have before the pilot

What this means for you: there is one question that separates an agentic business case that survives its first bad week from one that does not, and it takes about a minute to ask.

Before any agentic AI initiative gets greenlit, the question worth putting on the table is not what this agent can do.

The question is what happens the first time it acts on bad data, and how we would even know.

If that answer is not clear, the agent is not ready, and the data is what needs the investment first. If it is clear, the follow-up questions are short: who owns the definitions this agent reads, what exactly is it permitted to do, what does each of those actions cost to reverse, and who is named against that grant.

None of those are questions for a vendor. They are questions for the person whose signature ends up on the business case, which is the reason they tend to arrive late in an evaluation that started with a platform comparison. Ask them first and the platform question becomes easier, because most of the answers stop depending on it.

Our AI readiness and data strategy work usually starts here rather than with a technology selection, and where the exposure is regulated, security and compliance sets the line before anything is granted.

Frequently Asked Questions

What is agentic AI and how is it different from a copilot?

Agentic AI describes software that plans and executes multi-step work against real systems, rather than returning text for a person to act on. A copilot proposes and a person disposes. The difference matters because the person reviewing a copilot's output is also catching its errors, and an agent removes that reviewer from the path between a mistake and its consequence.

Why does agentic AI fail on ungoverned data?

Because the failure is silent. An agent reading inconsistent definitions or unreconciled records does not stop and flag the contradiction; it picks an interpretation and acts on it, writing the result where everything downstream treats it as fact. The problem surfaces at reconciliation rather than at the point of error, by which time many records are affected.

What does an agent need before it can be trusted to act autonomously?

Four things: data whose definitions somebody owns by name and whose lineage is known; authority that is enumerated, with everything else refused by default; a known cost of reversal for every action it can take; and detection, so a wrong action becomes visible without a person happening to notice. An initiative that cannot answer all four is not ready for autonomy.

Which sectors are ready for agentic AI today?

Sectors whose data was already disciplined for other reasons are ready first, with banking and financial services the clearest example — regulatory reporting forced governed, lineage-traced data long before AI made it valuable. Sectors with rich but fragmented data, manufacturing in particular, have a larger long-term opportunity but need foundational work before authority can safely be granted.

Should we wait for the data foundation before piloting agents?

No. Waiting for a finished data foundation means waiting indefinitely, because definitions move as long as the business does. Pilot agentic use cases in the domains where definitions are already owned and trusted, while foundation work proceeds elsewhere. What should never run ahead of the foundation is the authority granted to the agent.


Unolabs is a Data and AI first engineering consultancy, headquartered in the United Kingdom with engineering operations in Pune and active engagements across the UK, Australia, and Hong Kong. We help enterprises build the architectural foundation for autonomous AI execution — governed data platforms, semantic intelligence, and agentic systems that enterprises can stand behind.

If you are deciding whether an agent can be trusted to act on your data, book a discovery call and we will work through it with you.

Engineered Updates

More Where
This Came From.

New architectural deep-dives land every two weeks. Pick your channels and we will send them as they publish.

Personalise Channels

We strictly run a zero-spam transmission architecture.

Continue reading

See what your agent would actually be allowed to do

Bring the agentic use case closest to funding. We will walk it back through the data it would read, the actions it could take, and what each one costs to reverse.

Assess Agentic Authority