Presented by SAP
AI governance is shifting from periodic compliance review to a critical component that’s embedded in the architectural design of an organization and operationalized at runtime. As autonomous agents execute business processes in real time, the distance between a decision and its consequences shrinks, pushing governance out of the compliance calendar and into daily operations.
"Applying traditional strategic governance to AI, the way you would with applications and systems, just doesn't work for AI agents," says Philipp Herzig, CTO of SAP. "Things happen so much faster once you introduce autonomy. The agent acts on your behalf, at times without your explicit approval. With proactive real-time operational governance, you are preventing issues rather than chasing them."
Continuous AI governance requires enterprises to answer four questions at all times:
Which AI agents exist across the enterprise, and what purpose does each serve?
What data and systems can each agent access?
How does each agent participate in business processes?
Is each agent operating within established policy?
Financial services, healthcare, pharmaceutical, and public sector organizations face the greatest urgency around these questions, with regulators already expecting documented accountability — and the AI governance capabilities these organizations build will quickly become standard in other industries.
Regulated industries are hitting the limits of traditional AI governance
The limits of traditional approaches to technology governance become most apparent in regulated industries when AI agents begin operating within existing accountability and compliance requirements. Banks apply model risk management guidance such as SR 11-7 and SR 26-2. Drug manufacturers work under GxP compliance and FDA requirements. Government agencies answer to FedRAMP, authority to operate, and data sovereignty rules.
Applying these regimes to non-deterministic systems creates an expectation most enterprises cannot yet satisfy. Regulators want organizations to reconstruct any decision an AI system made at any point in time. Given the way this technology operates, it’s not that simple
"Think about the pharmaceutical industry, where you have a chain of custody," Herzig says. "If you make drugs, you have to know every point where the product was touched. You cannot have blank spots in a regulated business process."
Satisfying industry standards takes more than a session log. Ownership has to attach to the agent and to the workflow it participates in, along with the guardrails and the delegated authority it carries in a user role. Identity and access management, a discipline built around humans, now has to account for entities that independently pursue an assigned goal — including, sometimes, finding ways around an API restriction to reach it. Permissions granted at deployment can also diverge from how an agent actually uses them over time, creating a gap between its authorized role and its real-world behavior. That makes continuous monitoring essential to ensure access remains appropriate as the agent’s activity evolves.
AI inventory and agent discovery come before control
Effective AI governance starts with a current inventory of the AI estate, and most enterprises lack one, Herzig says.
"You can't manage what you can't see," he explains. "If I can't automatically discover and maintain a working inventory of AI assets or AI agents, I don't know what I'm governing."
Discovery has to run continuously because creation and deployment happens continuously. An employee with a chat interface can stand up a functioning agent in an afternoon, and that agent starts touching real work immediately.
"Say someone decides they no longer want to handle invoices, so they build a quick agent in a copilot tool and hand the work over," Herzig says. "Now something is operating on finances and customer relationships with nobody watching it. Shadow IT used to mean prohibited software on a laptop. This version resembles an employee bringing three other people to work, pointing them at the reports, and never mentioning it to the boss."
The governance perimeter extends beyond the agents themselves. Large language models, MCP servers that interface with applications and other systems, and agent-to-agent protocols all fall within its scope. Multi-agent orchestration adds another layer of complexity, making it harder to establish responsibility when agents delegate tasks to one another. Herzig estimates that agents alone account for less than a third of what an enterprise has to cover.
The ability to contextualize AI in the broader business and architecture context is essential to understand dependencies and fully map risk and blast zones. It is only with this full transparency that organizations can holistically cover AI governance.
An inventory establishes what AI assets exist, but effective governance also requires understanding where they sit in the enterprise architecture and the business processes that depend on them. Mapping those relationships exposes dependencies — and, when something goes wrong, shows which applications, processes and systems could be affected.
"Having a registry is one thing, and positioning that estate in the context of your business is another," he says. "Knowing which agents sit inside which processes and which applications run on top of them answers the harder questions."
Runtime AI governance proves policies hold while agents execute
The EU AI Act and the NIST AI Risk Management Framework both raise the bar on documentation, risk classification and human oversight, but checklists and templates only go so far without enforcement mechanisms underneath them. SAP’s approach has evolved accordingly: first providing visibility into what AI exists across the enterprise and the risks it presents, and now extending those capabilities to control and manage AI at runtime.
"Agents keep learning, keep adjusting, and keep drifting," Herzig says. "Without the ability to measure that and enforce controls at runtime, you don't have AI governance. Having governance without runtime enforcement resembles being a governor with no courts, no law enforcement, and no jails."
Reconstructing what an agent did after it reached a restricted system leaves the cleanup to whoever owns the affected process, so enforcement has to intercept the action while it happens. Breaking down the silos separating enterprise architects, CISOs and compliance chiefs matters as much, which explains the rise of AI centers of excellence across large organizations.
AI governance data measures agent ROI and process performance
Connecting agent execution to process conformance reveals not only whether agents are operating as intended, but whether they’re actually improving the business processes they were deployed to support. That turns governance data into evidence of performance and ROI, rather than simply a record of risk avoidance.
Process benchmarks give organizations metrics to attach to a deployment before it goes live, and those metrics aggregate at the process level or across the application portfolio at the business capability level.
"Agents produce plenty of base telemetry, including token input and output, model usage over time, tool call health, and success rates," Herzig says. "The question is whether you can aggregate that detail against a process that six people used to run and now runs with two people and agents in the loop. Proving the efficiency gain requires tooling that rolls those signals up to the level where business value becomes visible."
How SAP governs AI across architecture, identity, business processes and compliance
SAP connects these domains through products that provide different layers of governance context.
SAP LeanIX supplies the architectural context and compliance mapping, SAP Signavio the business process context and the ability to measure business value, Cloud Identity Services the identity layer and SuccessFactors the workforce view, with the AI Agent Hub serving as the entry point across them. Its discovery capabilities identify and inventory agents across the enterprise, including those outside the SAP ecosystem.
Verification gates sit in the deployment path, where MCP servers built and managed in SAP Integration Suite require verification before production use, and Joule Studio applies the same principle to agents leaving a test environment. SAP plans to ground those verification seals explicitly in regulations such as the EU AI Act, and follow with runtime enforcement capabilities and guardrails before the end of 2026.
AmTrust Financial Services extended its SAP LeanIX enterprise architecture practice to AI governance in advance of EU AI Act obligations, building an AI inventory, tagging applications by risk level and standing up a cross-functional AI governance council. CapitaLand built reusable governance frameworks across business units operating in more than 260 cities, letting governance scale alongside adoption instead of getting rebuilt for every deployment.
The harder problem sits between vendors rather than inside any one of them, Herzig says.
"Our discovery already covers ServiceNow, AWS, Microsoft and Google agents, well outside the SAP ecosystem," Herzig says. "Where the industry needs more work is a stronger open agent ecosystem, because the granular telemetry required to access how agents are performing, monitor agent health and behavior, and the aggregation of this information into measurable business outcomes sits behind closed doors in each big tech environment. No organization runs purely on SAP or purely on Microsoft. Opening that up makes AI governance better for everyone."
Sponsored articles are content produced by a company that is either paying for the post or has a business relationship with VentureBeat, and they’re always clearly marked. For more information, contact sales@venturebeat.com.
