I’ve been fascinated by how AI is changing the work at every level of seniority and in every department. I recently spoke with a friend who runs an APAC partner team for a US$10+ billion tech company. As part of their strategy, they are widening senior people’s span of control by a large margin. Being a senior manager now means leading much larger teams and also managing agentic workloads, with clear expectations on security and compliance.

I’ve also spoken with people in companies that are stuck and can’t deploy anything because they can’t get legal time. Two or three legal counsels in a large organisation that wants to deploy agentic AI is not enough. Do those specialists understand what MCP is, what personal information (PII) flows through it, whether it respects the terms of customer master services agreements (MSAs), and whose confidentiality obligations apply when an agent acts on a person’s behalf? What training and support have they been given to understand this? Has the business made ownership clear? And is there a clear business strategy to invest into the legal team to support all of these people building AI?

All of this has shown me how AI is upending operating models. Agentic AI removes one bottleneck and often creates a new one in legal or security. Waiting six months for a legal review is no fun.

So, I asked my friend Claude to make this diagram for leaders working through operating models and business cases. You can use it for a single business case for an agentic solution or platform you’re building, and also as a framework when you’re deciding how to resource your organisation to respond to the technology breakthrough.

Leaders have to drive this change. When a transformation is justified by efficiency and lower opex, the business case also has to count the full cost of design, build and run: the whole cost of ownership. The pivot point for this is the risk profile of the company (and a culture enabling the risk to be understood – or not understood…more on that later!).

Based on this the balance tips one way or the other…sometimes that favours adoption, sometimes the case doesn’t stack up even if a great technical solution exists (which your tech team will no doubt be very vocal about).

Security. Agents come with two broad levels of access. Read access lets an agent gather data and context. Write access gives it the authority to create, change or delete data in your systems. Even read-only agents need well-managed, monitored and auditable access. Once an agent can write, the risk goes up sharply, and so does the cost of securing it. In practice this usually means a senior security resource, and senior security people are some of the hardest and most expensive hires in the market. That cost should go into the business case. If its not there, you are not making an informed decision.

Compliance and legal. Data protection rules differ in every market you operate in. Someone has to review the legal feasibility of the solution during the design and deployment phase and needs to be available to support the governance of it throughout the solution lifecycle. Many mid-sized organisations don’t have legal advice on hand for this, let alone a budget line for it. If you can’t make it compliant or don’t have resource for it, you can still run a proof of value and keep testing, so the organisation keeps learning while the legal foundations are put in place. But ideally, your leadership team would be getting ahead of the curve and make sure legal cost is budgeted for with each business case…so it never turns into a bottleneck.

Business ownership. Every agent needs a business owner who understands what it does, checks that it’s still doing the right thing and answers for it when something goes wrong. That takes time and headspace from managers who may already have a wider span of control. This is harder to estimate in $$ value but should be included as a consideration.

Register and oversight. The most basic control is knowing which agents you run, what data and systems they touch, and who owns each one. What is the cost of developing and maintaining this register? Even a high level estimate is better than nothing – it should all go into the business case.

None of these is a reason to stop. They are reasons to build the business case differently, looking at the impact of AI across the whole organisation, ensuring that the investment goes where the highest ROI can be achieved safely.

Leave a comment

Trending