By Guillaume Bacuvier, CEO of ARIS.
- AI agents are moving from assisting people to executing work. What changes from a security and governance perspective when AI starts taking action?
Enterprise AI is moving from AI that answers questions and helps people make decisions to agents that can make decisions and execute work themselves, changing the risk equation considerably. An agent that takes the wrong action inside a critical business process can create an entirely different class of problem. Controls over which systems agents can access and which actions they’re authorized to perform are essential, but authorization alone doesn’t provide operational understanding. Governance has to be designed in from the start, and the fundamental question changes from “what can this agent do?” to “what should this agent do in this situation?”
- Your research found that 86% of leaders see process context as essential for reliable AI agents, yet only 22% have comprehensive real-time process visibility. Why is this gap so difficult to close?
Much of the knowledge agents need exists somewhere inside most organizations. The problem is that it is fragmented across process models, policies, applications, documentation and, very often, people’s heads. Humans have traditionally compensated for those gaps, but agents don’t arrive with that institutional knowledge.
In The Hackett Group’s 2026 Process Context Study, developed in collaboration with ARIS, 86% of respondents agreed that AI agents cannot be deployed reliably without process context. Yet only 22% of organizations report comprehensive, real-time visibility into their business operations, while 59% describe their visibility as fragmented. Businesses increasingly understand the context agents need, but most don’t yet have a complete enough view of their own operations to provide it.
Part of the reason the gap is so difficult to close is history. Maintaining an accurate picture of how a company works has been hard. It was largely manual, it needed a mandate from the executive suite, and many companies gave up on it. Some organizations now face process debt in the same way others face technical debt. They could get away without actively managing their processes in the past, and now they have to pay that debt down before they can deploy AI at scale.
- What can go wrong when an AI agent understands the data but doesn’t understand how the underlying business process actually works?
Data tells AI things about your business, but it doesn’t necessarily tell AI how your business works. An agent approving an invoice might have the supplier, purchase order and amount and still not know which approval thresholds apply, what to do if the documents don’t match, or when to escalate. Without end-to-end process visibility, an agent can optimize the task in front of it while creating a problem somewhere else. It can miss an important exception or take an action that is technically permitted but inappropriate in the wider business context.
- How does process context help organizations put guardrails around autonomous AI decisions?
Process context is the business understanding an agent needs around the task it is performing. It connects agent behavior to known workflows, rules, approvals and exception paths. The clearer you are about what an agent should do, what it shouldn’t do and when it needs to escalate, the more confidently you can allow it to operate autonomously within those boundaries.
An agent needs relevant context at runtime: process state, rules, roles and permissions, dependencies, controls, exceptions and escalation requirements. That context needs to stay governed and current as the business changes. Process mining helps here by working as an observability layer. It compares how processes are designed to run with how they actually run, so the agent’s guardrails reflect reality.
- The study points to cost, data quality and organizational silos as major barriers. Which of these tends to create the biggest challenge when organizations try to scale AI?
Together, cost, data quality and organizational silos account for over 70% of the primary obstacles to establishing actionable process context. When it comes to scaling, silos are often the hardest.
A company can usually get early wins in the part of the organization that already has good documentation. Eventually, though, it’s difficult to avoid needing an end-to-end view of the company. If you optimize procurement because you were well equipped to do that, you can create problems in finance or supply chain. Deploying agentic AI successfully can’t be done piecemeal. That’s simply how business transformation works.
Cost and effort are becoming easier to manage. AI can gather the unstructured information that describes processes, such as documents, slides and diagrams, and turn it into a first version of a process model. Work that would have taken months can now take days.
- Why does cross-functional visibility matter when AI agents are working across systems, teams and approval processes?
Every process in an organization is connected to others. Agents working across them need to understand those dependencies, the IT systems involved, who holds decision rights and which regulations apply. Without that view, an agent can fix one bottleneck while creating inefficiencies elsewhere in the end-to-end process. With it, you can model an agent’s impact across the organization before deploying it, and that sometimes shows you need several agents working in parallel for the process to flow properly.
- Only 18% of organizations surveyed have mature, enterprise-wide AI governance frameworks. What should companies put in place before giving AI agents more autonomy?
I would start with three steps.
First, understand the process before automating it, starting with the business outcome you want to improve. Second, identify where autonomy creates genuine value, because the easiest process to automate isn’t necessarily the most valuable one. Third, make process context available when the agent acts, and keep it governed and current as the business changes.
Governance also needs input from the people who own the business processes, especially since 46% of enterprises still place AI accountability solely with IT.
- What should security and technology leaders rethink if they want to move from AI experimentation to autonomous, governed operations?
For decades, organizations have invested in understanding and improving processes mainly so people can work more effectively. In the agentic AI era, that understanding increasingly needs to become machine-consumable. For CIOs and enterprise architects, process can no longer sit only within an operational excellence team. Process models, execution data, governance rules and organizational context need to become part of the infrastructure required to deploy AI reliably and cost-effectively.
Leaders should also rethink governance. Setting up governance may slow you down a little at first, but it lets you scale much faster down the line. Process context connects agent behavior to known workflows, rules, approvals and exception paths, so governance becomes an accelerator.
There is a compelling business case. The Hackett Group study found that organizations with high process-context experience are five times more likely to report very successful AI outcomes than organizations with low experience. Small-scale pilots can survive with narrow context and significant human oversight. Enterprise-wide deployment is more complex, because agents encounter process variation, systems, exceptions and accountability requirements.
As AI models become increasingly powerful and accessible to everyone, the differentiator will be the companies that can give agents the deepest understanding of their business and put them to work most effectively.