EY helps clients create long-term value for all stakeholders. Enabled by data and technology, our services and solutions provide trust through assurance and help clients transform, grow and operate.
At EY, our purpose is building a better working world. The insights and services we provide help to create long-term value for clients, people and society, and to build trust in the capital markets.
As enterprises move from AI that assists to AI that acts, governance is becoming a business-critical priority. Agentic AI can make decisions, execute workflows and interact with systems with limited human intervention, creating new opportunities and risks. In this episode of the EY India Insights podcast, Aditya Iyer, Partner, Risk Consulting, EY India, shares practical perspectives on building trust, accountability and control in the age of autonomous AI. Find out more about the right governance guardrails, redefine oversight, and scale Agentic AI responsibly while balancing innovation, transparency and risk management.
Key takeaways:
Agentic AI can act autonomously, but accountability must always remain with the enterprise.
For your convenience, a full text transcript of this podcast is available on the link below:
Welcome to the EY India Insights Podcast. I am Pallavi, your host for today. As organizations move from AI that assists to AI that acts, governance is becoming a critical business imperative. In this episode, we explore how enterprises can build trust, accountability and control in the age of Agentic AI. Joining us is Aditya Iyer, Partner, Risk Consulting, EY India, to share his perspectives on governance frameworks needed to scale AI responsibly.
Hi Aditya, a very warm welcome to you.
Aditya
Thank you, Pallavi.
Pallavi
Agentic AI moves beyond generating insights to taking autonomous actions. Why does this shift require Indian enterprises to rethink their traditional governance and control models?
Aditya
The biggest change is that Agentic AI is now no longer giving us an answer or a recommendation. It can take action. It can decide what should be the next step. It can call tools, connect with other systems and keep moving without any or limited human involvement. So, the governance question changes quite a bit.
It is no longer only ‘did the model give the right output’; it becomes ‘is the agent behaving the way we intended – safely and consistently over time’. For Indian enterprises, it is quite a big deal because accountability is often spread across business, technology, risk and operational teams. And as these agents become more autonomous, the impact of a mistake can also become much larger. That is why governance has to become more continuous and built into the way the agent operates, not something that we can check as an afterthought.
Pallavi
As AI agents gain the ability to make the decisions and execute workflows across the systems, how should organizations redefine accountability, oversight and human supervision?
Aditya
The first thing organizations need to accept is that an AI agent can be given authority, but it cannot be given accountability. Accountability will still sit with the enterprise. So, every agent needs clear ownership. Who owns the business process? Who owns the technology and who owns the risk? Human supervision also needs to be more thoughtful. It should not just be a checkbox where we simply say a human is somewhere in the loop.
For low-risk tasks, monitoring and exception reporting may suffice, but if the agent is taking actions that affect money, customers, compliance or reputation, then there should be adequate approval gates that are built in escalation, parts that are clearly defined, and a very clear and precise way to pause or reverse what the agent is doing.
Pallavi
Pivoting towards the guardrails, what are the most critical governance guardrails around risk, security, data access and compliance that enterprises must establish before scaling Agentic AI?
Aditya
I would keep the guardrails very practical. First, know where your agents are, what they are doing and who owns them. Second, treat agents like non-human identities, which means that they should only have access that they truly need. Third, be very clear about what data they can use, especially when personal, confidential, or regulated data is involved. From security point of view, you need controls for prompt injection, misuse of tools, data leakage and unauthorized actions. And finally, you need logs, monitoring, audit trails, testing and very essential a kill switch. The real objective is to make autonomous agents, not quietly create risk in the background. While everyone assumes that they are business as usual.
Pallavi
Many organizations still see Agentic AI as a technological transformation, so why is it equally or perhaps more, an operating model and an organization change challenge?
Aditya
Agentic AI is not just another technology rollout or a standard technology rollout. It changes how work actually gets done. If an agent can plan a task, update a record, trigger workflows, or coordinate across systems in the enterprise, then it is effectively becoming part of the operating model itself. That means that organizations have to rethink roles, approvals, controls, SOPs, as well as escalation parts.
They also need to decide what stays human-led, what becomes agent-assisted, and what can be fully agent-executed. In many cases, the hard part will not be building the agent but redesigning the way people, processes and controls work around it.
Pallavi
Looking ahead, what will distinguish the enterprises that successfully scale agent to key with trust and control versus those that struggle with risk and governance failures?
Aditya
The organizations that succeed are likely to be the ones that know exactly what their agents are doing. They will have a clear inventory, clear ownership, clear access boundaries, and continuous monitoring of these agents. They will understand which systems and data each agent touches, and what kind of business impact it could create if it goes wrong. On the other hand, organizations that struggle will likely have agent sprawl, shadow deployments, unclear accountability, and weak oversight.
So, the winners may not simply be the ones that move fastest; they will be the ones that scale with discipline, transparency, and with the right controls built in from the start.
Pallavi
Thank you, Aditya. That brings us to the end of this episode. As Agentic AI reshapes how business operate in success will completely depend not only on innovation, but also on the ability to govern AI with trust, transparency and control. And that is our key takeaway from this conversation.
Thank you so much, Aditya for joining us and sharing all your valuable insights on how enterprise can build trust, accountability and control in the age of Agentic AI.
Aditya
Thank you, Pallavi. It is a pleasure.
Pallavi
Thank you. And to all our listeners, thanks for listening to your EY India Insights podcast. Until next time, this is Pallavi, signing off.
If you would like to listen to our podcasts on the go: