Enterprise AI Agents Are Doing More Than Anyone Approved

The Real Question Enterprises Are Asking

Most organizations have already decided to deploy AI agents. The open question, according to Joe Davis, EVP of AI Engineering and Delivery at ServiceNow, and Adel El Hallak, VP of Product Management at NVIDIA’s Agentic AI division, is what those agents can actually do, and at most organizations today, the honest answer is more than anyone has formally approved. Their proposed fix is a simple architectural principle: when an AI agent requests a permission, the default answer should be no.

Why This Matters for BFSI and Collections

The two describe a “lethal trifecta” that makes this urgent: an agent with unfettered internet access, an internal knowledge base, and a coding terminal all at once creates an attack surface most governance frameworks were never built to handle. For collections and financial services specifically, the piece is explicit that an over-permissioned agent handling account records, processing refunds, or executing payment actions is not just an operational risk; it is a regulatory one. As AI agents move from internal IT desks into customer-facing collections and servicing roles, the permission model behind them matters as much as the conversational capability in front of them.

What the Numbers Do Not Say Out Loud

The strongest evidence in this piece is not a theoretical framework; it is a production result: ServiceNow’s own deployment of an AI agent on its IT service desk now automates 90% of Level 1 support tickets, cutting resolution time by as much as 99% on the issues it handles. What that number does not say is how it was achieved: not by giving the agent broad access and restricting it after something went wrong, but by building every permission up from zero. The agent’s reasoning stays probabilistic (the same input will not always produce the same output), but its actions are enforced deterministically through an assigned identity that either holds a specific permission or does not. That distinction, between what an agent decides and what it is actually allowed to execute, is the real mechanism behind the resolution numbers, not the AI model itself.

The Practical Read

For BFSI and collections operations, the temptation is to treat governance as overhead that slows down AI deployment. Davis and El Hallak reframe this directly: building permissions from zero is not the cost of doing AI safely; it is the cost of doing AI at scale. A collections voicebot that can update a case, log a payment, or escalate a dispute needs the same deny-by-default architecture as any internal enterprise agent, arguably more, given the regulatory stakes attached to customer financial data. Retrofitting that governance after an incident is always harder than designing it in before the deployment scales. The organizations getting genuine value from agentic AI in regulated environments are the ones that decided, before launch, exactly what their agent is allowed to do, and built the system to enforce it rather than merely hope for it.

[Read the full report]

Related Post

Enterprises Are Underestimating Multi-Model AI Failure Rates by 2.25x

A new study evaluating 67 frontier models from 21 providers, including GPT-5.5, Claude Opus 4.8, and Gemini 3.1 Pro, found that combining multiple AI models does not create the safety net most enterprises assume. On the MATH-500 benchmark, standard correlation metrics predicted a 2.3% “co-failure rate,” the share of prompts where every model in a […]

A Tribunal Ruled an Airline’s Chatbot Was the Airline

The Trust Gap New data paints a sobering picture of where AI-driven customer service actually stands. Forrester found US CX quality fell again to a record low of 68.3 in 2025, while the CFPB reported roughly 6.6 million consumer financial complaints that same year, more than double the prior year. Separately, Salesforce research found that […]

A Bank Just Drew a Hard Line Between What Its AI Can Say & Decide To Do

The Rollout Commonwealth Bank of Australia has begun testing CommBank Companion, an AI-powered conversational assistant built directly into its mobile app, backed by roughly $1 billion in security investment. Unlike most vendor-led AI launches, this one was designed and built entirely in-house by CommBank’s own engineering and data science teams, and it is being tested […]