Governance

Governance is the real barrier to agentic AI.

Technical skills are not what is holding agentic AI back. Governance is. What regulators and auditors will ask, and how to answer before they do.

The main thing slowing agentic AI down is not the technology or the skills to use it. It is governance: who is accountable, what is recorded, and how anyone can show later what an agent did and why. Businesses that answer those questions before they deploy move faster than those that treat governance as a final review.

The numbers

Omdia's research, based on polls of MSPs and IT decision-makers in 2025, put governance and compliance at the top of the list of barriers to implementing agentic AI, named by 47% of respondents. Technical expertise gaps were named by 16%, value realization and adoption by 14%, and data and security management by 14%.

Smaller businesses say the same thing in their own words. In the Upwork Research Institute's 2026 survey of SMB leaders, data security and compliance was the top barrier to AI agents at 27%, ahead of uncertainty about return on investment at 24%.

Why governance is harder with agents

A chatbot answers questions. An agent acts: it updates records, sends documents, triggers payments. That changes the questions a business has to answer:

  • Who is accountable when an agent gets something wrong?
  • Which decisions can an agent make alone, and which need a person?
  • What exactly did the agent see, decide and do, and with which model version?
  • How would we show a regulator, auditor or client what happened?

Most organizations have good answers for their people and their systems. They do not yet have them for software that makes decisions.

Regulators are setting expectations

In insurance, the direction is clear. The NAIC adopted its model bulletin on insurers' use of AI systems in December 2023, and about half of US states have since adopted it. The bulletin expects insurers to have a written AI program covering governance, risk management, internal controls and oversight of third-party vendors. It applies to insurers rather than agencies, but those expectations flow down to anyone supporting insurer processes.

Outside insurance, the NIST AI Risk Management Framework is the most widely used voluntary US reference for structuring AI governance.

What good governance looks like in practice

Governance does not need to be a committee. For agent work it comes down to four things done every time:

  1. Named accountability. A person owns each process and each type of decision.
  2. Routing rules. Low-confidence items go to trained people. Licensed and financial decisions go to named approvers.
  3. A complete record. Inputs, steps, model versions and human approvals for every outcome, stored so later edits are detectable.
  4. Review. Someone looks at exceptions, errors and trends regularly, and has the authority to change the process.

When those four are built into the process, the conversation with legal, compliance and auditors gets much shorter.

How we built for it

We designed Agentic MSP around this barrier rather than around the technology. Every outcome has a record in the Evidence File. Low-confidence work goes to our exception desk, and your team signs off anything that needs a license or moves money. See how to build an audit trail for AI agents if you are doing this yourself.

Common questions.

What is the biggest barrier to agentic AI adoption?

In Omdia's polling of MSPs and IT decision-makers, 47% named governance and compliance as the top barrier to implementing agentic AI. Technical expertise gaps were named by 16%.

Does the NAIC AI bulletin apply to insurance agencies?

The NAIC model bulletin on the use of AI systems applies to insurers, not directly to agencies. It still sets expectations that flow down to agencies and vendors that support insurer processes.

Sources

Want this run for you.

Agentic MSP runs back-office work with governed AI agents and bills only for verified outcomes.