Microsoft’s new responsible AI report shows that the governance discussion is moving to a new level: once artificial intelligence can access data, use tools and execute tasks, controlling the model alone is no longer enough.

Microsoft identifies a shift in the governance problem

Microsoft published its Responsible AI Transparency Report 2026 on September 1, outlining how its practices for the responsible development and deployment of artificial intelligence are evolving. One of the areas highlighted is the expansion of agentic AI capabilities, accompanied by a change in how organizations need to approach risks and controls.

From responding to executing

A traditional AI model can receive a request and produce an answer. An AI agent, by contrast, can coordinate multiple steps toward a goal, using tools, retrieving information and interacting with systems.

That difference changes the governance problem. Risk is no longer concentrated solely on the quality of the answer produced by the model. It also involves what the system is able to access and do.

The new perimeter of enterprise AI

Microsoft itself says more capable systems can retain memory, use tools, access data and take actions on behalf of users. As a result, the company says governance needs to account for interactions among models, agents, applications, tools, data and people.

That is the key shift highlighted by the report: governing AI increasingly means governing what the system is capable of doing.

Identity becomes part of AI agent governance

AI agent with its own identity connected to enterprise systems

As agents become more autonomous, knowing which system is performing an action becomes part of enterprise control.

Identity becomes increasingly important because an agent operating inside a company should not simply be treated as an indistinguishable extension of the user. It can execute processes, retrieve information and interact with multiple systems.

Why agent identity matters

Agent identity provides a way to determine which agent or system is performing a particular operation. This can help companies establish accountability and distinguish actions performed by people, applications and agents.

This model also complements a trend already emerging across enterprise AI. Notícia Tech previously examined how AI agent identity can work inside businesses, showing that greater autonomy creates new requirements for access control and traceability: understand the role of AI agent identity in businesses.

Identity does not mean unlimited autonomy

Giving an agent an identity does not mean granting it freedom to perform any task. On the contrary, identification needs to be associated with rules that determine which resources can be used and under what circumstances.

In practice, this brings agent governance closer to established enterprise security concepts such as authentication, authorization, access control and traceability. The difference is that these mechanisms now need to support systems capable of taking actions across multiple steps.

Tool permissions become a critical layer

The second element highlighted by Microsoft is controlling the tools agents are allowed to use. This is particularly important in enterprise environments because a tool can give an agent the ability to produce real-world effects beyond the AI interface itself.

Access needs to match the objective

An agent responsible for organizing information does not necessarily need permission to modify financial records. Likewise, a system tasked with preparing reports may not need to send external messages or modify data in critical systems.

Governance therefore needs to establish a relationship between objective, tool and permission. The greater the agent’s ability to take action, the more important it becomes to apply controls proportional to the associated risk.

The problem is no longer just the model

This shift helps explain why evaluating the AI model alone is not enough. Even a model that behaves appropriately can be part of an application with excessive permissions or poorly configured integrations.

A similar issue is emerging as companies adopt agents for productivity. The expansion of systems capable of executing tasks is already changing the relationship between AI and work, as enterprise tools increasingly move beyond generating content toward executing activities. See how the AI agent era is changing enterprise productivity.

Monitoring begins to follow the actions agents take

Monitoring AI agents as they perform actions across enterprise systems

Agent control does not end at deployment: behavior during operation becomes part of governance.

The third layer is action monitoring. For Microsoft, the evolution of agentic systems requires mechanisms capable of tracking what happens after the technology begins operating in real-world environments.

Governance after deployment

In traditional AI development, much of the attention is concentrated on training, testing and evaluation before release. With agentic systems, production behavior becomes more important because an agent can interact with environments that continuously change.

The company describes a governance approach that includes risk assessment, controlled deployment and ongoing monitoring to identify problems, respond to incidents and continuously improve systems.

Action history becomes more valuable

Monitoring actions also creates a layer of traceability. If an agent changes information, accesses a particular resource or performs an unexpected sequence of actions, the company needs ways to understand what happened.

This turns activity records into an important part of governance. The goal is not to eliminate all autonomy, but to create conditions in which autonomy can be monitored, limited and corrected when necessary.

Governance begins to cover the entire AI architecture

Microsoft’s report also points to a broader change: governance is no longer being treated simply as a policy applied to the model. The company says it has restructured its Responsible AI Standard to account for different layers of the AI architecture.

Model, platform and application

Agents can exist at different points across the technology stack. They may rely on models, operate through platforms and appear inside applications used directly by employees.

Controls therefore need to follow that architecture. A company adopting an enterprise agent is not necessarily managing only a language model, but a connected set of components.

The deployer also becomes part of the equation

Another important point is the distinction between the responsibilities of developers and those of organizations deploying AI systems. This distinction matters because a company may use an AI application created by a third party while still assuming responsibilities related to how that system is deployed.

The question is no longer simply, “Did the vendor build the AI correctly?” It also becomes, “Is the company using that AI appropriately within its own environment?”

What changes for companies adopting AI agents

Executives evaluating AI agent governance, permissions and monitoring

For companies, the expansion of AI agents turns governance into an operational issue involving technology, security and accountability.

The most important message in the report is not that agents should be avoided. The direction identified by Microsoft is the opposite: the technology is moving toward more capable systems, and control mechanisms need to evolve alongside them.

Governance is no longer just policy

A corporate policy stating that AI should be used responsibly is insufficient without technical mechanisms capable of enforcing that rule.

Identity, permissions and monitoring turn abstract principles into operational controls. They help define who can act, what can be accessed and how activities can be tracked.

The next challenge will be managing autonomy

This creates a new agenda for technology leaders. The question will not simply be which model delivers the best performance, but how much autonomy each agent should receive, which systems it can access and which actions require human approval.

The trend is particularly significant because the race to build AI agents already involves major technology companies. The expansion of platforms capable of executing tasks is creating another layer of competition in the enterprise market, while companies begin evaluating how these systems can be incorporated into their own processes.

Microsoft is signaling that this adoption will have an unavoidable consequence: the more AI moves beyond simply responding and begins to act, the more governance will need to follow each step of that action.

For companies, this may become the defining issue of the next phase of AI adoption. The challenge will not simply be putting agents to work, but building an infrastructure in which autonomy, access, accountability and oversight can coexist without turning automation into a new source of operational risk.