EY refers to the global organization, and may refer to one or more, of the member firms of Ernst & Young Global Limited, each of which is a separate legal entity. Ernst & Young Global Limited, a UK company limited by guarantee, does not provide services to clients.
How EY can help
-
EY's Information Technology Risk services ensure trust in data and IT systems, offering audits and controls to enhance business performance and growth.
Read more
Connect agentic-AI specific governance with existing systems
Taking a broad-based approach to governance that complements your existing organizational technology processes is key. While these six core steps establish the foundation for strong agentic AI governance, you’ll also need to consider and integrate areas like data protection, information security, risk management and more as part of the ecosystem. For example, AI agents must be built and operated in compliance with applicable data protection laws and organizational privacy impact assessment processes.
Moreover, agentic AI systems looking to use foundational models — for example, through API calling — must receive explicit permission prior to use. Agent-to-agent communication must also be authenticated and adhere to clear data access guidelines.
On the data governance side, agentic AI systems will need to follow organizational data governance policies for managing the collection, storage, processing and disposal of data used by AI agents.
The same can be said for information security measures. Your organization will also need to follow its information security processes to protect the agent ecosystem, including its orchestration layer, protocols, agent identity management and all new attack surfaces. Thinking about agentic AI implications in the context of your broader technology processes helps the enhancements you make on this front align with how the organization works and support overall effectiveness.