AI Agent Governance: Before You Hire an Always-On AI Agent, Decide What It’s Allowed to Touch
The most important decision about an always-on AI agent is not which one to buy. It is what the agent is allowed to see, change and send on your behalf.
That question became urgent on 29 September 2026, when OpenAI launched Dots at its DevDay event. Dots are agents that keep working in the background and can be reached through ChatGPT, Slack and Microsoft Teams, with text messaging promised soon. They are rolling out first to ChatGPT Pro and Business Premium users, while Enterprise, Edu and Healthcare customers can join a beta once a workspace admin switches it on.
OpenAI is not alone. On the same day, Meta expanded its Muse agent to small businesses, with connections to tools such as QuickBooks, Shopify, Slack and Stripe. OpenAI also says companies will be able to manage their own specialist Dots through Agent 365, Microsoft's tool for overseeing AI agents, though it has not given a timeline.
The persistent AI colleague is now a product you can switch on. But before doing so, businesses need to decide where its boundaries sit.
What is AI agent governance?
AI agent governance means defining the permissions, approval rules, accountability and boundaries an AI agent operates within, before giving it persistent access to business systems. In practice it answers seven questions: what the agent can see, what it can change, what it can send, which actions need human approval, what activity is logged, who is accountable for it and who can stop it.
It sits alongside AI agent security but asks a different question. Security is about how an agent can be attacked or hijacked, which we cover in our analysis of the SalesBleed vulnerabilities. Governance is about who decides what the agent is allowed to do, who answers for it and how its access grows over time.
What does "always-on" change?
A chat assistant acts only when someone asks, and a person reads the answer before anything happens. An always-on agent removes both of those checks. It starts work on its own and can act before anyone reviews it.
Three things follow from that:
- The agent holds standing access. It needs credentials to your inbox, calendar, messaging and business systems all the time, not for a single task.
- It reads content you did not write. Emails, shared documents and web pages can contain instructions aimed at the agent. Edgars Nemse of the GenLayer Foundation told The National that an agent able to read your inbox can also be manipulated by a malicious email. The UK's National Cyber Security Centre warns that this kind of prompt injection may never be fully mitigated, because language models do not reliably separate data from instructions.
- Mistakes compound quietly. An error in a chat reply is visible at once. An error in a background task may only surface when a client or supplier points it out. In the same report, a cybersecurity manager at SandboxAQ described an agent that got around its safeguards to reach data it was not authorised to see, with months passing before anyone noticed.
None of this is a reason to avoid agents. It is a reason to treat deployment as a design and governance exercise rather than a licence purchase.
Why does AI agent governance start with permissions, not prompts?
A great deal of attention in AI projects goes into prompts: what the agent should do, how it should respond and how its output can be improved.
For an always-on agent, there is a more fundamental question: what is it actually allowed to do?
Excessive access increases the potential impact of both malicious manipulation and ordinary mistakes. The practical response is similar to the approach businesses already apply to new staff, contractors and software services.
| Control | What it means for an agent | Question to ask |
|---|---|---|
| Least privilege | Access only to the systems and records the task needs | Could this agent do its job with read-only access? |
| Confirmation steps | A person approves actions that are costly or hard to reverse | Which actions must never happen without sign-off? |
| Audit logging | Every action is recorded with the data it used | Could we reconstruct what the agent did last Tuesday? |
| Containment | The agent runs in a bounded environment with a clear off switch | Who can stop it, and how fast? |
Dots ships with controls of its own. Users choose which apps each agent can reach and can set rules that allow, block or require approval for specific actions. OpenAI says proactive background research is limited to read-only access, and some tasks, such as changing a password, stay with the user. That is welcome, but vendor controls are generic by design.
They cannot know that your finance mailbox, patient records, pricing files or intellectual property need different treatment from everything else.
That is where AI agent governance becomes an organisational responsibility rather than simply a product feature. UK regulators see it the same way. In its January 2026 report on agentic AI, the Information Commissioner's Office says organisations stay responsible for data protection compliance for any agent they develop, deploy or integrate, and it singles out agents connected to databases they do not need for their tasks as a sign of poor implementation. The report sets out early thinking rather than formal guidance, but the direction is clear.
Should you use an off-the-shelf agent or one built around your systems?
Off-the-shelf agents suit general knowledge work: drafting, research, scheduling and summarising across standard tools. They are quick to trial and the vendor carries much of the underlying engineering.
A tailored approach earns its cost when any of the following apply:
- The work touches regulated or sensitive data, as in healthcare, pharmaceuticals or financial services.
- The agent must act inside bespoke or legacy systems that have no ready-made connector.
- You need approval rules that mirror your own processes, such as two-person sign-off above a set value.
- You must show an auditor or regulator exactly what the agent did and why.
Tailored does not have to mean building a model. In most cases, it means using a well-chosen commercial model wrapped in your own integrations, access rules, approval processes and logging.
The model is rented; the controls are yours.
Our work with Hydraclean, a water hygiene compliance specialist, follows that pattern. AI drafts each Legionella risk assessment report from structured inspection data, a compliance specialist reviews and edits it, and only then is it approved. The assessment logic and regulatory thresholds can be updated as the rules change. It is not an always-on agent, but the governance principle is the same: the approval step and the rules belong to the business, not the model. For the wider trade-offs, see our piece on off-the-shelf versus custom software.
What should you do in the first 90 days?
Good AI agent governance does not require giving an agent broad access on day one. A controlled rollout gives the organisation time to understand how the agent behaves before increasing its autonomy.
1Pick one bounded process
Choose a task with a clear start, end and owner, such as supplier query triage or meeting follow-ups.
Avoid beginning with an agent whose remit spans several departments or loosely defined business processes.
2Map the data it touches
List every system and record type the agent would reach, and identify anything sensitive, confidential or regulated.
This establishes the real data boundary before access is granted.
3Start read-only
Let the agent draft and recommend for the first month while people take the actions.
Read-only access allows the organisation to evaluate the quality of its decisions without immediately giving it the ability to modify important business information.
4Define the approval list
Write down the actions that always need human sign-off. These might include:
- Payments
- External emails
- Important record changes
- Contractual commitments
- Permission changes
- Sharing sensitive information
The important point is to define these rules before the agent encounters the decision.
5Switch on logging from day one
Every meaningful agent action should leave a record. Review the logs weekly, not only when something goes wrong.
The organisation should be able to determine what the agent accessed, what it attempted to do and what action ultimately occurred.
6Test with hostile input
Send the agent an email or document containing planted instructions and confirm that it ignores them or handles them according to your controls.
An agent that reads external content should be tested against content deliberately designed to manipulate it, not only against normal business inputs.
7Name an owner and an off switch
One person or team should be accountable for the agent and know how to suspend it.
If unexpected behaviour occurs, there should be no ambiguity about who has authority to intervene or how the agent can be stopped. Our free guide to responsible AI for UK businesses covers accountability and human oversight in more depth.
8Measure before you expand
Track time saved, error rates and how often people override the agent. Use that evidence to decide whether to widen its access or increase its autonomy.
Access should expand because the agent has demonstrated that it can operate safely and usefully within its existing boundaries, not simply because additional integrations are available.
How should businesses approach AI agent governance?
The first governance decision should not be which agent has the longest feature list. It should be where the agent's boundaries sit.
Always-on agents are likely to become a normal part of business operations, and early adopters will learn the most. But the organisations that benefit will be those that decide the boundaries first and choose the product second.
What should you be able to answer before deployment?
Before an always-on agent goes live, a business should be able to answer seven questions:
- What can the agent see?
- What can it change?
- What can it send?
- Which actions require approval?
- What activity is logged?
- Who is accountable for it?
- Who can stop it?
If those answers are unclear, the organisation is not yet deciding between AI products. It is still defining the system it actually needs.
At Imobisoft, we design and build AI solutions around the systems, data and compliance obligations our clients already have. That can mean using commercial AI models while designing the integrations, access rules, approval workflows, logging and governance around the organisation itself.
If you are weighing up an always-on agent, the starting question is not simply what it can do. It is what it should be allowed to do.
Talk to us about your AI agentsFrequently asked questions
What is AI agent governance?
AI agent governance is the set of rules, controls and responsibilities that determine what an AI agent may access and what actions it may take. For an always-on agent, this includes what it can see, change and send, which actions require human approval, how its activity is logged, who is responsible for it and how it can be stopped.
What is an always-on AI agent?
An always-on AI agent is an agent that can continue working or initiate tasks without requiring a person to start every individual interaction. Depending on its configuration, it may monitor information, work across connected applications and take actions on behalf of users or the organisation.
What are the best practices for AI agent governance?
Start with one bounded process and map the data and systems the agent needs. Apply least-privilege access, start read-only where possible, define which actions require human approval, enable logging from day one, test the agent with hostile inputs, assign a named owner and provide a clear way to suspend it. Only expand access once the agent's performance has been measured.
Who is responsible when an AI agent gets something wrong?
The organisation that deploys it. The ICO says organisations remain responsible for data protection compliance for any agentic AI they develop, deploy or integrate, and a vendor's built-in controls do not transfer that responsibility. That is why every agent needs a named owner, a record of what it did and a clear way to stop it.
Can an AI agent be manipulated by hidden instructions?
Yes. An agent that processes external content such as emails, documents or web pages may encounter malicious instructions designed to influence its behaviour. This is one reason external content should not automatically be trusted. Narrow permissions, human approval for consequential actions and adversarial testing can reduce the potential impact.
How should an always-on AI agent be contained?
An always-on agent should operate within clearly defined technical and operational boundaries. That means limiting the systems and information it can access, restricting the actions it can perform, logging its activity, defining when human approval is required and maintaining a clear off switch that an accountable person can use.
Should a business choose an off-the-shelf agent or one built around its own systems?
Off-the-shelf agents can work well for general tasks such as drafting, research, scheduling and summarisation across standard tools. A tailored approach becomes more valuable when the agent works with regulated or sensitive data, needs access to bespoke or legacy systems, must follow organisation-specific approval rules or needs to provide detailed evidence of its actions for audit or regulatory purposes. Tailored does not necessarily mean developing an AI model from scratch. It can mean using an established model with integrations, access controls, logging and governance designed specifically around the organisation.
Sources
- OpenAI introduces always-on Dots agents, VKTR, 30 September 2026
- Meta is expanding its AI agent Muse to small businesses, TechCrunch, 29 September 2026
- AI 'less safe' for keeping secrets than most people assume, The National, 4 October 2026
- ICO tech futures: agentic AI, Information Commissioner's Office, 8 January 2026
- Prompt injection is not SQL injection, National Cyber Security Centre, 8 December 2025