30 September 2026

Reshaping workplaces through AI agents

Building trust in AI agents

Businesses have traditionally relied on automation to streamline repetitive tasks, and AI agents have taken this a step further by extending the capabilities of conventional automation. These agents are digital collaborators that can reason, interact, and make informed decisions.

AI agents can handle a wide range of tasks, like qualifying leads, managing customer conversations, generating reports, and managing workflows across applications. These capabilities have made them valuable contributors in modern workplaces.

Image 1: Traditional automation vs. AI agents

Organisations are integrating AI agents into every aspect of their operations. The focus is no longer on the capabilities of these agents but on their accountability. Businesses are increasingly recognising that responsible AI adoption requires clear accountability, oversight, and trust.

With greater autonomy comes greater responsibility. AI agents are becoming trusted participants in everyday business operations, making governance, data protection, and accountability essential.

 

Why governance matters

Traditional automation primarily relied on predefined rules to execute specific tasks. AI agents are transforming the way businesses operate by acting with greater autonomy. This enables organisations to manage complex workflows, improve productivity, and automate tasks that previously required extensive human intervention.

However, businesses need to establish clear boundaries around what AI agents can access and what they’re permitted to do. These agents often interact with sensitive business information, including customer records, financial data, internal documents, and operational systems, making controlled access to information essential.

Establishing clear boundaries, accountability, and oversight enables organisations to embrace AI with confidence while protecting their data, systems, and business operations.

 

Data: Your most valuable asset

Data is the foundation of every AI agent. AI agents rely on enterprise data, ranging from customer interactions and financial records to internal documents and business knowledge, to generate insights, make recommendations, and perform tasks.

Not all information carries the same level of risk. Some information contains personal details, while other datasets may contain confidential business knowledge or intellectual property. In any such use case, enterprise data is the most valuable asset for a business, making its protection essential.

Image 2: The data AI agents handle

Organisations must consider where their data is being processed. Publicly available AI services and large language models (LLMs) can improve productivity. However, sharing sensitive business data, such as customer information, confidential documents, financial records, or intellectual property, with these AI services can introduce security, privacy, and compliance risks. Businesses need clear policies governing what data AI agents can access, where the data is processed, and how it’s protected.

Techniques such as data masking help organisations reduce these risks. By masking personally identifiable information (PII) or limiting AI agents to only the specific information required for their functionality, businesses can reduce unnecessary data exposure. Combined with strong governance, these practices enable organisations to realise the full potential of AI agents while maintaining control over their data.

 

Understanding risk-based governance  

Not every AI agent carries the same level of responsibility or impact. An AI agent that summarises meeting notes presents a different level of risk compared to one that updates CRM records or another one that authorises financial transactions. Applying the same level of governance to every AI agent can create unnecessary business complexities or leave critical operations vulnerable to attacks.

This is where risk-based governance comes into play. Rather than adopting a one-size-fits-all approach, organisations assess AI agents based on the level of risk they introduce. The level of governance can be decided based on the data that can be accessed by these AI agents, the decisions that they influence, the actions that they perform, and the potential impact of those business operations.

For example:

  • Low-risk AI agents, such as meeting summarises or knowledge resource assistants, primarily retrieve, organise, or present information. Since they don’t directly modify business data or critical decisions, they require basic monitoring and standard access controls.

  • Medium-risk AI agents, such as CRM assistants that recommend courses of action or update customer records, interact directly with customer data that is relevant to the organization. These agents, therefore, require stronger permissions, auditability, and oversight as they directly influence business operations.

  • High-risk AI agents, such as those handling financial transactions for a business, interact with highly sensitive information and critical business operations. These agents require the highest level of governance, extensive human oversight, and clearly defined operational boundaries.

Image 3: Level of risk

By aligning governance with the level of risk, organisations can enable AI agents to deliver greater value while ensuring that higher-impact activities receive the additional safeguards that they require. This helps businesses operate with confidence.

 

 

Best practices for responsible AI governance

Building a responsible and strong AI governance strategy goes beyond implementing technology. It mandates that organisations establish clear policies, responsibilities, and boundaries that enable these agents to operate effectively while maintaining trust, accountability, and security.

Image 4: Five practices for responsible AI governance

 

Defining clear roles and responsibilities 

Every AI agent should have a clearly defined purpose. Organisations should establish clear policies, responsibilities, and safeguards that enable AI agents to operate effectively. This reduces ambiguity and helps prevent unintended actions.

Protect enterprise data

AI agents should only have access to the data required to perform their functions. Organisations should identify and classify sensitive information like personally identifiable information, financial records, legal documents, and intellectual property before allowing AI agents to access it. Techniques like data masking can help protect sensitive data while still enabling AI agents to perform their intended tasks. Limiting access to only relevant information helps safeguard business operations and strengthens privacy and security.

Keep humans in the loop

AI agents can automate day-to-day business activities and support decision-making, but they shouldn’t replace human judgement completely. Activities involving financial approvals, legal decisions, or sensitive customer interactions should include appropriate human oversight before critical actions are executed. This ensures accountability and informed decision-making.

Organisations should continuously monitor, review outputs, evaluate performance, and refine their governance policies as business needs evolve.  

Build transparency and trust

Trust is fundamental to the adoption of AI agents into workplaces. Employees and customers must be made aware of the use of AI agents, their roles and functions, the extent of their use, and when decisions involve human oversight. Being transparent about AI-assisted interactions encourages adoption and reinforces organisational accountability.

 

Choosing the right AI platform

As AI agents become woven into business workflows, organisations must look beyond productivity gains and AI capabilities when evaluating AI platforms. The right platform should be driven not only by AI innovation but also by governance, transparency, security, and observability to ensure the responsible and effective use of these agents within a business.

Different AI models excel at different things. For example, ChatGPT is well suited for general-purpose business tasks, Claude excels at providing coding assistance, and Gemini is used for tasks involving images and other forms of content. Organisations should choose the model that best fits their business needs.

Businesses should look for platforms that protect sensitive information, manage access to that sensitive information, support human oversight, and provide observability into AI-driven actions. They should also consider where enterprise data is processed, the use of techniques such as data masking to protect sensitive information, and how the platform ensures that the organization meets privacy and security requirements. This enables organisations to confidently adopt AI agents while protecting their data, people, and business operations.

 

Build AI agents that you can trust with Zoho

Zoho’s Zia Agents brings together the principles of responsible AI by combining governance, security, privacy, and observability into a unified agentic AI platform. With capabilities like data masking and secure AI infrastructure, organisations can build, deploy, and manage AI agents seamlessly.

Whether you’re exploring your first AI agent or scaling AI across your entire organization, Zia Agents provides the tools to help you innovate responsibly without compromising trust or security.

Zia Agents: Unified AI for your entire business.

 

Thanks to Zoho for sponsoring the Aotearoa AI Summit 2026

Does our AI project have what it takes to win Aotearoa’s best AI implementors award?
15Jul

Does our AI project have what it takes to win Aotearoa’s best AI implementors award?

15 July 2026 Does our AI project have what it takes to win Aotearoa’s best…

Aotearoa AI Awards celebrate New Zealand’s leading innovators, researchers, and changemakers
17Sep

Aotearoa AI Awards celebrate New Zealand’s leading innovators, researchers, and changemakers

17 September 2025 Aotearoa AI Awards celebrate New Zealand’s leading innovators, researchers, and changemakers Auckland,…

AI adoption in Aotearoa is accelerating — now it’s time to scale
15Sep

AI adoption in Aotearoa is accelerating — now it’s time to scale

15 September 2025 AI adoption in Aotearoa is accelerating — now it’s time to scale…

Tākina Convention & Exhibition Centre