The AI industry continues to make sweeping claims about autonomous agents, self-managing workflows, and enterprises that run at machine speed. The reality is more complicated. AI is generating real value, but most of that value remains tightly scoped. Coding productivity is improving. Customer support workflows are becoming more efficient. Information work is accelerating. Yet the enterprise-level gains remain difficult to identify.

Many commentators respond by arguing that organizations must adopt radically new operating models. Perhaps. But before redesigning decision rights and reporting structures, it is worth asking a more fundamental question: what exactly are we trying to enable?

The current conversation often assumes that autonomy is inherently desirable. We are skeptical. We do not maximize autonomy in human organizations. We do not encourage employees to operate without controls, accountability, or supervision. Why would we expect a different answer for software?

Autonomy is a design choice. The responsibility of the technology leader is not to maximize it, but to support, bound, and control it.

This observation leads to five questions that every organization deploying AI should be asking. Taken together, they define the foundations of bounded autonomy.

Identity: Who Or What Is It?

Most large enterprises already carry substantial technical debt in digital identity. Over-provisioned service accounts, shared credentials, weak ownership, and unclear accountability are familiar problems. Deterministic software tolerated many of these weaknesses. Goal-seeking systems turn them into active hazards.

Recent security research is increasingly focused on agent identity, privilege abuse, and tool misuse. This should surprise no one. An agent can only act through the authority it has been granted. If that authority is poorly governed, the risk follows directly.

There is also an economic dimension. Agentic systems create ongoing operational costs, making inventory and accountability prerequisites for effective TokenOps and governance.

The initial investment implication is straightforward: know the actors.

Organizations will need the equivalent of an application portfolio for agents. Agent identities should be distinct. Their sponsors should be known. Their permissions should be bounded. Every agent should trace back to an accountable human authority. They should also have an explicit lifecycle, including retirement and decommissioning. While not glamorous, inventory is still foundational.

See the AEGIS framework from our colleagues in Forrester’s Security & Risk service.

Capability: What Can It Do?

AI capability remains remarkably jagged. A system may perform brilliantly on one task and fail unexpectedly on an adjacent one. We continue to see examples of models achieving extraordinary results on sophisticated benchmarks while struggling with activities that humans find routine. Benchmark performance is useful evidence. It is not operational assurance. The “jagged technological frontier” remains very real.

The corresponding investment is to equip the actors.

This sounds revolutionary until you look closely. MCP may be new, but APIs are not. Platform engineering and reusable business services are not new. The organizations best positioned for agentic AI are the same organizations that have spent the last decade building internal platforms and treating technology capabilities as products.

The APAC fintech Lendi provides a useful example. Its AI strategy is built on substantial prior investment in platform services and reusable business functionality. Their mortgage agents succeed because they stand on top of a platform foundation.

One of the genuinely new ideas emerging in AI is the concept of reusable skills. We now have emerging standards for packaging instructions, resources, and code into portable capabilities that can be reused across agents and environments.

However, possessing a skill is not the same thing as demonstrating competence. Proficiency is established in the real world, under real constraints, serving real customers, and there is limited real world demand.

Meaning: How Does It Understand?

Semantic fragmentation is a growing AI hazard. What happens when one agent has the enterprise definition of customer, another inherits a vendor definition, and a third relies on a departmental interpretation? Human organizations have wrestled with these problems for decades. AI amplifies them.

A healthcare executive recently described this problem to us as the equivalent of drug interactions. Any individual definition may be fine. The unexpected effects emerge when the definitions interact.

The investment implication is to ground the actors with context.

Metadata, ontologies, semantic models, knowledge graphs, capability maps, and context graphs all become increasingly important. To be clear, we are looking for semantic alignment, not semantic unification.

A common objection is that increasingly capable models will simply infer meaning from messy enterprise environments. Perhaps they will infer meaning more effectively than they do today. The harder problem is authority. Which definition of “customer” is the sanctioned one for a regulated process? Which definition governs a financial report? Those are governance questions, not inference questions, and must remain deterministic.

What is needed is a dynamic, learning, navigational infrastructure: a way for humans and machines to understand how concepts (which themselves evolve and drift) relate across organizational boundaries.

Confidence: How Do We Know It’s Right?

Software engineering has long distinguished verification from validation. Building the thing right is different from building the right thing. The distinction matters even more with AI.

The investment is assurance through guardrails and evaluation, and again this is not new — precursors are clear to see in DevOps practices of continuous integration and delivery, policy as code, and the like.

One intriguing development is the growing use of AI itself as part of the evaluation process. Evaluation is the emerging control of AI output using techniques like “LLM as judge” … which can have the nifty side effect of doubling your token costs. Caveat emptor. 

We are also seeing organizations encode architectural standards, security policies, and development conventions directly into AI working environments. The objective is simple: influence outputs as they are generated rather than auditing them after the fact. As accountability requirements increase, so will the investments required to sustain confidence.

Control: How Do We Keep It Aligned?

Governance ultimately is a problem of feedback.

This has been the trajectory of enterprise IT. From agile to continuous integration to continuous delivery to DevOps and product management, all reflect the same underlying idea: faster learning through tighter feedback loops.

AI accelerates.

The most credible visions of AI autonomy center on feedback loops. The idea is that an AI system can take action, observe the consequences, evaluate the results, and incorporate what it learns into future behavior. Product leaders should recognize this immediately. It is simply the product feedback loop operating at machine speed.

Organizations need continuous visibility into agent behavior, outcomes, costs, and risks. They need the ability to intervene, redirect, and recover when systems behave unexpectedly. They need situational awareness rather than periodic inspection. And they need feedback loops capable of operating at the speed of the systems being governed. And systems to manage systems of such loops.

These are not new recommendations. Analysts and advisors, ourselves included, have pushed these categories since well before ChatGPT, and organizations that invested have benefited. What has changed is the penalty for neglect. AI shifts all of them from best practice to table stakes.

Deterministic software tolerates weak identity, poor reuse, fragmented semantics, after-the-fact assurance, and constrained visibility — not well, but we built a digital economy on those weaknesses anyway. (Massive amounts of human effort glues this stuff together.) Goal-seeking systems operating at machine speed turn these deficits into active hazards. The slack that let you defer investing in them is disappearing.

And still: the AI future remains genuinely uncertain. These capabilities benefit you across the range of scenarios, including well-considered decisions not to pursue AI aggressively at all. That is what makes them prudent, no regrets investments.*

Start with inventory and accountable identity. Build governed capabilities on that foundation. Ground them in enterprise context. Add assurance proportionate to risk. Create the visibility and feedback loops needed to steer the system in operation. The right sequence depends on where your existing debt already sits, but every one creates value today, whether the future arrives as a swarm of autonomous agents or simply a steadily expanding collection of increasingly capable software.

To explore these ideas further, join us at one of Forrester’s upcoming Technology & Innovation events in Austin, London, or New York City. You’ll gain practical guidance from Forrester analysts and peers on building the governance, capabilities, and organizational foundations required to scale AI and deliver lasting business value.

=======

*Assurance is the partial exception: evaluation infrastructure is largely AI-specific. The guardrail half (policy as code) is not. For more nuanced discussions, drop us a line.

Share