AI agents can retrieve information, make decisions, invoke tools, and complete multi-step workflows. They can also create security, compliance, operational, and financial risk. The question isn't whether an agent can perform a task — it's whether your organization can control it when the agent gets it wrong.
AI agents can retrieve information, make decisions, invoke tools, and complete multi-step workflows. They can also create security, compliance, operational, and financial risk.
The central question is not whether an AI agent can perform a task.
The question is whether your organization can control the task when the agent performs it incorrectly.
This distinction defines AI Enablement in 2026. Organizations must assess their data, processes, documentation, governance, and security before moving from isolated pilots to production automation.
Recent reporting from Forbes, CIO, Inc., and TIME identifies the same pattern. Adoption is increasing. Governance is not keeping pace.
BTG recommends using the following maturity model before authorizing an AI agent to operate inside a business-critical workflow.
The Five-Level AI Enablement Maturity Model
| Level | Organizational state | Appropriate AI agent use |
|---|---|---|
| 1. Ad Hoc | Isolated experiments. No consistent standards. | Sandbox testing only. |
| 2. Developing | Initial policies and process definitions exist. Application is inconsistent. | Narrow pilots with human approval. |
| 3. Managed | Data, processes, governance, and security controls operate consistently. | Bounded production workflows. |
| 4. Measured | Monitoring, metrics, audit evidence, and incident response are established. | Semi-autonomous workflows at scale. |
| 5. Fully Governed | Controls are automated, adaptive, and integrated into daily operations. | High-volume agent operations with controlled autonomy. |
An organization may operate at different levels across different departments.
For example, the finance department may have Level 3 data governance. Human Resources may remain at Level 1 because employee data is fragmented and access rules are unclear.
The lowest score within a critical workflow determines the acceptable level of agent autonomy.

Level 1: Ad Hoc AI Experimentation
At Level 1, employees use public AI tools or disconnected applications. Experiments are not registered. Data may be uploaded without formal approval. No central owner is assigned.
Typical conditions include:
- No inventory of AI tools or agents.
- No approved use-case process.
- No data classification standard.
- No documented business process.
- No defined escalation path.
- No reliable activity logs.
- No formal security review.
Level 1 organizations should not deploy autonomous agents into HR, payroll, finance, customer service, or production operations.
The correct action is to establish basic controls. Create an AI use policy. Identify current tools. Prohibit sensitive data from unapproved systems. Select one low-risk process for controlled evaluation.
This is the starting point for AI Enablement. It is not a production state.
Level 2: Developing AI Capability
At Level 2, leadership has identified AI opportunities. Some policies exist. Teams have begun documenting processes. Data standards may exist in individual departments.
Execution remains inconsistent.
One department may maintain accurate employee records. Another may use spreadsheets with duplicate values. One team may require human approval. Another may allow an AI tool to send external communications without review.
Suitable use cases at this level include:
- Internal knowledge search.
- Drafting standard documents.
- Meeting summarization.
- Ticket classification.
- Low-risk data extraction.
- Employee-facing assistance with human review.
Agents should not have unrestricted write access to enterprise systems at this stage.
The organization must define each agent's purpose, owner, approved data sources, allowed actions, prohibited actions, and required approvals.
Level 3: Managed AI Operations
Level 3 is the minimum target for most bounded production use cases.
At this stage, the organization has repeatable operating controls.
Data quality
Critical data has an identified owner. Quality is measured for accuracy, completeness, timeliness, and duplication. Data lineage is documented.
The organization can answer these questions:
- Where did the agent receive this information?
- When was the information last updated?
- Which system is authoritative?
- Who may access the data?
- What happens when the data is incomplete?
Agents should not compensate for unreliable source data. If the data cannot support a human decision, it cannot support an autonomous decision.
Process documentation
The target workflow is documented from start to finish. Roles, approvals, exceptions, inputs, outputs, and handoffs are defined.
A process map should include:
- Trigger.
- Required information.
- Business rules.
- Agent action.
- Human approval point.
- Exception path.
- Completion record.
This is where business process automation services become relevant. Automation should follow process analysis. It should not conceal process defects.
Governance
Every production agent requires a named business owner. The owner is accountable for performance, scope, review frequency, and retirement.
A central registry should record:
- Agent name and purpose.
- Business owner.
- Technical owner.
- Model and platform.
- Connected systems.
- Authorized tools.
- Data access.
- Autonomy level.
- Review date.
- Incident history.
Security
Each agent should have a unique identity. Access should follow least privilege. Credentials should be managed through approved identity and access controls.
Security requirements should include:
- Role-based access.
- Separate development and production environments.
- Secrets management.
- Tool allowlists.
- API restrictions.
- Activity logging.
- Human approval for high-impact actions.
- Tested shutdown and rollback procedures.
Level 3 supports controlled production automation. It does not support unrestricted autonomy.
Level 4: Measured and Auditable AI Operations
At Level 4, the organization can demonstrate that its AI controls work.
Documentation is not stored only for initial approval. It is maintained throughout the agent lifecycle.
The organization measures:
- Task completion rate.
- Exception rate.
- Human override rate.
- False positive and false negative rates.
- Response time.
- Cost per transaction.
- Security events.
- Data quality trends.
- Time to detect and resolve incidents.
Agent behavior is monitored after deployment. Logs capture inputs, outputs, tool calls, approvals, and exceptions.
The organization can reconstruct a material decision. It can identify the data used. It can identify the policy applied. It can identify the person responsible for oversight.
This is the level required for many regulated or business-critical workflows.
Examples include payroll exception handling, financial reconciliation, benefits administration, customer eligibility decisions, and production change management.

Level 5: Fully Governed AI Operations
Level 5 organizations treat AI agents as managed operational resources.
Governance is integrated into the technology environment. New agents cannot be deployed without registration. Permissions are automatically scoped. Policy violations generate alerts or block execution.
The organization uses:
- Automated policy enforcement.
- Continuous data and behavior monitoring.
- Dynamic access reviews.
- Runtime risk scoring.
- Automated rollback.
- Agent performance baselines.
- Formal retirement procedures.
- Cross-functional AI oversight.
At this level, agents can coordinate across systems. They can perform multi-step work within defined boundaries. Human involvement remains required for decisions with material financial, legal, employment, safety, or reputational consequences.
Fully governed does not mean fully autonomous.
It means autonomy is authorized, observable, reversible, and accountable.
Where Organizations Typically Stall
Most organizations do not stall because the AI model is unavailable.
They stall in the operating environment around the model.
Data is not authoritative
Critical information exists across spreadsheets, legacy applications, email, shared drives, and disconnected databases. The agent produces inconsistent results because the organization has not defined which source is correct.
Processes are not documented
Employees rely on tribal knowledge. Exceptions are handled differently by each person. The organization attempts to automate a process that has never been standardized.
Governance is treated as a policy document
A policy does not control an agent by itself. Governance requires technical enforcement, monitoring, evidence, and ownership.
Security is added after the pilot
Teams often connect an agent to systems during experimentation and plan to address permissions later. This creates unnecessary remediation work and increases risk.
The pilot has no production owner
A pilot may have a project manager and technical team. Production requires a business owner, support model, service-level expectations, incident response, and a budget.
These issues are not isolated AI problems. They are digital transformation problems.
Self-Assess Your AI Readiness
Score each category from 1 to 5.
Data
- Are critical data sources identified?
- Is data quality measured?
- Is data lineage available?
- Are access rights documented?
Process
- Is the workflow mapped?
- Are business rules documented?
- Are exceptions defined?
- Are human approvals clear?
Documentation
- Is every agent registered?
- Are system dependencies recorded?
- Are limitations documented?
- Are decisions and activities logged?
Governance
- Is a business owner assigned?
- Are allowed and prohibited actions defined?
- Are review dates scheduled?
- Is there an incident response process?
Security
- Does the agent have a unique identity?
- Are permissions limited?
- Are tool calls monitored?
- Can the agent be stopped or rolled back?
Use the lowest score as the operating limit.
A score of 1 or 2 indicates pilot-only readiness. A score of 3 supports a bounded production use case. A score of 4 or 5 supports broader deployment, subject to risk classification.
Do not average the scores. A Level 5 process with Level 1 security is not a Level 3 production workflow.
Move from Pilot to Production
Use a controlled sequence.
- Select one process. Choose a repeatable workflow with measurable business value.
- Document the current state. Capture steps, systems, data, approvals, and exceptions.
- Classify the risk. Identify financial, legal, employment, customer, operational, and security impacts.
- Define the agent boundary. Specify what the agent can access, recommend, execute, and never do.
- Run a supervised pilot. Require human approval for every material action.
- Measure results. Compare performance against the existing process.
- Test failure conditions. Include incomplete data, conflicting instructions, unauthorized requests, and system outages.
- Establish production support. Define monitoring, escalation, documentation, and rollback.
- Expand autonomy gradually. Increase permissions only after evidence supports the change.
BTG supports this sequence through business process management and digital transformation consulting, IT managed services, documentation, testing, production support, and enterprise system implementation.
The BTG Position
AI agents should not be deployed because a vendor demonstration appears successful.
They should be deployed when the organization can define the process, trust the data, control access, monitor behavior, assign accountability, and recover from failure.
That is the purpose of AI Enablement.
Use the BTG AI readiness assessment questions to begin an internal review. Then request an AI Enablement assessment from BTG.
Assess readiness before authorizing autonomy.
Sources and Further Reading
- Forbes: Agentic AI Readiness Is a Data Problem, Not an AI Problem
- CIO: Why AI Agents Will Make Your Governance Playbook Obsolete
- Inc.: Enterprise Agent Governance
- TIME: The Agentic AI Era Is Here. Humans Still Matter
- BTG Management Consulting
- BTG IT Managed Services



