Generative AI has become a foundational layer of business software. It drafts emails and contracts, writes and reviews code, summarizes meetings, produces images and video, and answers customer questions. Most organizations now use it somewhere, whether through a sanctioned rollout or through employees who adopted it on their own.
The next step is already under way. Agentic AI systems do not just produce an answer for a person to act on; they plan a sequence of steps, call tools, and act. That is a different kind of technology from a governance standpoint, because the question shifts from “is this output accurate?” to “should this system have been allowed to do that?” Organizations that pair the two waves with a working governance program will move faster, not slower, because they will not have to stop and clean up after preventable mistakes.
Generative AI: the content layer
Generative AI models, including large language models and image and video generators, produce new content from a prompt. Their business value comes from compressing tasks that are mostly about producing a first draft: marketing copy, code, reports, support responses, and analysis of documents too long for a person to read quickly.
The limits are equally well understood. Models can produce confident but wrong answers, reproduce biases in their training data, and leak sensitive information if employees paste it into consumer tools. In a generative workflow, however, a human usually reviews the output before it goes anywhere. That review step is the main safety control, and it is why generative AI adoption has been relatively low-risk for organizations that set basic usage rules.
Agentic AI: the action layer
Agentic AI wraps a model in a loop: it receives a goal, breaks it into steps, uses tools such as search, databases, email, ticketing systems or code execution, observes the results, and continues until the goal is met or it gets stuck. A generative assistant writes a refund email. An agent looks up the order, checks the refund policy, issues the refund in the payment system and sends the email.
That is where the productivity upside lies, and also where the risk concentrates. Every tool an agent can call is a permission it holds. An agent that can read email can be manipulated by a malicious email through prompt injection. An agent that can move money or change records can do real damage if it misreads a situation. The human review step that made generative AI safe is exactly what agentic AI is designed to remove.
Analysts expect adoption to be rapid but uneven. Gartner predicted in 2025 that a third of enterprise software applications will include agentic AI by 2028, up from less than 1 percent in 2024, and in the same year warned that over 40 percent of agentic AI projects will be canceled by the end of 2027 due to cost, unclear business value or inadequate risk controls. Both forecasts point to the same conclusion: governance is what separates the projects that survive from the ones that do not.
The governance frameworks that matter
Organizations do not need to invent AI governance from scratch. Several established frameworks provide structure, and they are designed to work together.
- NIST AI Risk Management Framework. A voluntary US framework organized around four functions: govern, map, measure and manage. In July 2024 NIST added a Generative AI Profile (NIST AI 600-1) describing risks specific to generative systems, such as confabulation, data leakage and information integrity.
- ISO/IEC 42001. Published in December 2023, it is the first certifiable international standard for an AI management system, structured much like ISO 27001 for information security. It suits organizations that need to demonstrate governance to customers or auditors.
- The EU AI Act. Entered into force in August 2024 with obligations phased in. Prohibited practices and AI literacy duties applied from February 2025, and obligations for general-purpose AI model providers from August 2025. Rules for high-risk systems, such as AI used in hiring, credit or critical infrastructure, apply to any business that places such systems on the EU market or uses them there, including US companies.
- Sector rules and existing law. Privacy law, consumer protection, anti-discrimination rules and financial regulation already apply to AI-assisted decisions. Several US states have enacted or proposed AI-specific rules, particularly for automated decisions in employment and insurance.
Governing both waves in practice
Governance works when it is proportionate: light for low-risk content generation, tighter as systems gain the ability to act. A practical program looks like this:
- Inventory AI use. Record every AI tool and model in use, who owns it, what data it touches and what it can do. Include features embedded in existing SaaS products, which are easy to miss. Our article on shadow AI covers how to find unsanctioned tools.
- Classify by impact. Separate content generation reviewed by a person from systems that act or make decisions affecting customers, employees or money. The second group gets more scrutiny.
- Set data rules. Define which data can go into which tools, and prefer enterprise agreements that exclude your data from model training.
- Grant agents least privilege. Give each agent its own identity and only the permissions its task requires. Require human approval for irreversible actions such as payments, deletions and external communications.
- Log and monitor. Keep records of prompts, tool calls and actions so you can investigate incidents and demonstrate compliance.
- Test before and after launch. Evaluate accuracy, bias and resistance to prompt injection before deployment, and monitor for drift afterwards.
- Assign accountability. Every AI system needs a named business owner who answers for its outcomes.
The trade-off is speed at the start. A governance review adds days to a pilot. It also prevents the far longer delays that follow an agent sending the wrong data to the wrong customer. For agent-specific controls, see our guide to AI agent security.
Are enterprises moving fast enough?
On balance, adoption is outpacing governance. Many organizations have a written AI usage policy but no inventory, no risk classification and no logging of what their AI systems actually do. That gap is manageable while AI mostly drafts content. It becomes a real exposure as agents gain access to production systems. The organizations best positioned for the next era are treating governance as part of the deployment pipeline rather than a separate compliance exercise.
Update (September 2026): The EU adopted a “Digital Omnibus” amendment to the AI Act, which entered into force in July 2026 and pushed back the main high-risk obligations: to December 2027 for stand-alone high-risk systems and August 2028 for AI embedded in regulated products. The delay gives more preparation time, not an exemption.
Frequently asked questions
What is the difference between generative AI and agentic AI?
Generative AI produces content, such as text, code or images, for a person to review and use. Agentic AI uses a model to plan and carry out multi-step tasks by calling tools and taking actions in other systems, often with limited human involvement at each step.
Does the EU AI Act apply to US businesses?
It can. The Act applies to organizations that place AI systems on the EU market or whose AI output is used in the EU, regardless of where the company is based. A US company using AI to screen EU job applicants, for example, would be in scope.
Where should a mid-sized company start with AI governance?
Start with an inventory of AI tools and a short acceptable-use policy covering data handling. Then adopt the NIST AI Risk Management Framework as a structure, and apply stricter controls only to systems that act or make consequential decisions.
Build AI that is useful and accountable
Delana Technologies helps organizations adopt generative and agentic AI with governance built in, from inventory and risk classification to agent permissions and monitoring. Learn about our AI consulting and agentic AI solutions, call 239.414.5126 or contact us.
Sources: NIST AI Risk Management Framework 1.0 and NIST AI 600-1 Generative AI Profile (July 2024); ISO/IEC 42001:2023; Regulation (EU) 2024/1689 (EU AI Act); White & Case, “EU AI Omnibus enters into force, amending the AI Act” (2026); Gartner press releases on agentic AI adoption and project cancellations (2025).
