As AI agents gain access to increasingly large amounts of enterprise information, organizations are discovering that AI governance cannot be separated from data governance. The Forbes article argues that companies may have clear policies about how an AI model should behave, yet struggle to explain how an agent reached a particular conclusion or what information it used along the way. This becomes a major governance blind spot as AI moves from answering questions to taking actions on behalf of employees and organizations.
A central issue is data access and context. AI agents can potentially draw information from multiple enterprise systems, including documents, databases, customer records and operational platforms. If that information is outdated, poorly classified, duplicated or missing important context, an agent may produce an apparently reasonable answer based on unreliable foundations. The problem is therefore not simply whether the AI model is accurate; organizations also need to know whether the data available to the agent is trustworthy and whether the agent was actually authorized to use it.
The article also highlights the importance of traceability and accountability. Traditional data-governance practices were designed largely around people accessing information through predictable applications. Agentic AI changes this model because an AI system can dynamically retrieve information, combine sources and potentially perform actions. Organizations therefore need visibility into what data an agent accessed, what decisions it made, what permissions it exercised and why a particular action occurred. Without that audit trail, investigating an erroneous or harmful AI decision becomes extremely difficult.
Ultimately, the argument is that companies should treat data governance as foundational AI infrastructure, rather than as a separate compliance exercise. Before giving AI agents broad autonomy, organizations need accurate and well-classified data, clear access controls, provenance, monitoring and mechanisms for human review. As AI becomes more deeply embedded in business processes, the quality of governance may depend less on controlling the model itself and more on controlling the information and authority surrounding the model.