Institute for Operational Assurance

Flagship research programme

Assuring the Agentic Enterprise

As AI agents gain the capacity to interpret, decide and act within organisations, assurance must address not only what a model can do, but how agency operates inside real work.

Enterprise leaders reviewing privacy-obscured AI-agent oversight dashboards.

Programme status

This is a developing research programme. Its questions and themes are being defined openly; no findings, study participants or completed publications are implied.

The research question

Who assures agency inside the enterprise?

Task completion alone does not establish that activity was appropriate, authorised or aligned with organisational intent.

The programme investigates the operational conditions needed for AI-agent activity to remain within defined roles, permissions, policies, responsibilities and escalation paths as work unfolds.

The question is not only whether an agent is capable. It is whether its activity can be understood, bounded and assured in context.

Research themes

Eight questions shaping the programme

01

Role and authority

How should an agent’s role, delegated authority and prohibited actions be made operationally clear?

02

Intent and context

How can current policy, process and situational context reach an agent at the moment of action?

03

Human oversight

Which decisions require human judgement, approval or the ability to interrupt activity?

04

Assurance Points

Where can consequential activity be evaluated without creating indiscriminate checkpoints?

05

Exceptions and escalation

How should uncertainty, ambiguity and out-of-bound conditions be recognised and escalated?

06

Evidence

What records are needed to understand decisions, actions, approvals and outcomes?

07

Learning

How should operational evidence improve instructions, controls and future assurance?

08

Shared accountability

How do responsibilities remain clear across leaders, process owners, technology teams and users?

Two assurance questions

Capability is not the same as assured participation

Model assurance and operational assurance address related but different concerns. Organisations may need both.

Agency in workflow

Assure the moments where agency becomes consequential

This illustrative workflow shows where roles, boundaries, human judgement and evidence may need to meet AI-agent activity. It is not a universal control design.

Questions for practitioners

Begin with the work, not the technology alone

  1. 01

    What work has the agent been authorised to perform?

  2. 02

    Which source expresses current organisational intent?

  3. 03

    Where could an incorrect action materially affect the intended outcome?

  4. 04

    When must a person review, approve or interrupt activity?

  5. 05

    How are exceptions recognised and escalated?

  6. 06

    What evidence would allow the organisation to reconstruct what happened?

Developing research agenda

An inquiry being shaped in the open

The Institute intends to develop the programme through research papers, executive interviews, practitioner conversations and roundtables. Methods, limitations and evidence will be stated alongside any future findings.

Participation or contribution does not imply endorsement, partnership or a published finding.

Explore the community

Participate

Contribute evidence, experience or a question

The Institute welcomes relevant perspectives from people working across enterprise AI, operations, governance, risk, audit and behavioural systems.

Contribute to the research