A business leader and a consultant shaking hands in an office lobby

Govern AI agents by how much they can do.

Proportional controls for agents that observe, advise and act.

In short

Govern AI agents in proportion to what they are allowed to do. An agent that only reads data needs light controls. One that acts on customers without approval needs monitoring, limits and a fast way to stop it.

Executive briefing · By Aaron Goh, CEO, Azend Group · 2 October 2026 · 3 min read

Most enterprises govern AI with one policy for everything. The assistant that summarises a meeting and the agent that refunds a customer get the same review, the same approvals and the same delay. That is the wrong design. It slows simple agents, so teams build around the rules, and it under-protects the agents that can do real damage.

What does Gartner recommend?

In May 2026, Gartner warned that applying uniform governance across AI agents will lead to failure. It predicted that by 2027, 40% of enterprises will demote or decommission autonomous agents because of governance failures found after production incidents. Its answer is proportional governance: classify each agent by autonomy level and match the controls to it.

Gartner's Shiva Varma explained why: “Agents operate at different autonomy levels and across different trust boundaries.” One rulebook cannot fit both.

Four levels, four sets of controls.

The main control that each level adds.

01OBSERVEReads and summarisesControl: data scope 02ADVISEDrafts and recommendsControl: output review 03ACT WITH APPROVALActs after sign-offControl: audit trail 04ACT ALONEActs within limitsControl: monitor, stop,roll back OBSERVE01Reads and summarisesControl: data scope ADVISE02Drafts and recommendsControl: output review ACT WITH APPROVAL03Acts after sign-offControl: audit trail ACT ALONE04Acts within limitsControl: monitor, stop,roll back

Autonomy levels from Gartner's May 2026 guidance on AI agent governance.

What does each level look like in a revenue team?

  • Observe. An agent that summarises an account before a sales call. Scope what it can read, and test it.
  • Advise. An agent that drafts a follow-up for a rep to send. Watch quality, and the habit of approving without reading.
  • Act with approval. An agent that updates deal stages or issues a quote once a manager signs off. Keep audit trails and watch for approval fatigue.
  • Act alone. A customer agent answering service questions on WhatsApp at midnight. It needs live monitoring, limits on topics, a human handoff and a way to switch it off in minutes.

How does this fit Southeast Asian rules?

It lines up with Singapore's Model AI Governance Framework for Agentic AI, launched by IMDA in January 2026, which asks organisations to bound risks upfront, define checkpoints where human approval is required, and apply technical controls across the agent's life. We cover the wider picture in AI regulation in Southeast Asia.

Who decides the level?

The business owner proposes it, risk and IT agree it, and it is written down. Moving an agent up a level is a decision, not a settings change. Start most agents one level lower than you think, then promote them on evidence. Agent Hub gives one place to see every HubSpot agent and how it is performing, and our piece on who owns the agent sets out the roles.

When is an agent ready to move up a level?

When the evidence says so. Before promoting an agent, look at three things over a set period: how often its output was accepted without change, how often it handed off to a person and why, and whether any incident traced back to it. If an advise agent's drafts are sent unchanged almost every time, it may be ready to act with approval. If an agent acting alone keeps handing off the same type of case, narrow its scope rather than widening it. Write the promotion criteria down before launch, so the decision is not made on enthusiasm. Demotion should be just as easy. Gartner's prediction is a warning about agents that had to be pulled back after an incident. A planned step down is far cheaper than an unplanned one.

What to do on Monday.

  1. List every agent and AI assistant in use, including the ones teams set up themselves.
  2. Give each one an autonomy level, from observe to act alone.
  3. Check that every agent in the top two levels has an owner, an audit trail and an off switch.
  4. Relax approvals for observe and advise agents, so teams stop working around them.
  5. Set a quarterly review to promote or demote agents on evidence.

Questions.

What are AI agent autonomy levels?

Gartner describes four: observe (read only), advise (drafts for a human to act on), act with approval (executes after sign-off) and act autonomously (executes within guardrails).

What controls does an autonomous customer agent need?

Continuous monitoring, clear limits on what it may handle, a human handoff, audit logs and the ability to stop or roll back its actions quickly.

Give every agent the right limits.

A strategy call maps your agents to autonomy levels and the controls each one needs.