TechCrunch reported on August 29 that conversations at TechBBQ in Copenhagen kept returning to the same AI question: not what can these systems do, but who is actually in control. That is the right question for business leaders too. The next phase of AI adoption will not be won by the companies with the biggest tool budget. It will be won by the companies that decide where agents are allowed to act, where people must stay in the loop, and who owns the result when the work crosses from suggestion into execution.
TL;DR
If your company is adding AI agents, build the control model before you expand access. Every agent needs a named owner, a defined scope, clear permission boundaries, a review path, and a shutdown path. Without that, you are not scaling intelligence. You are scaling ambiguity.
The control question is no longer theoretical
TechBBQ’s theme was agency, and according to TechCrunch, the conference conversations moved quickly from capability to control. Signal President Meredith Whittaker warned about AI assistants being integrated into operating systems and called the current AI wave a “data collection apparatus.” Emad Mostaque put it more bluntly: “the person that controls the AI controls the country.”
Most companies do not need to solve national AI sovereignty this quarter. They do need to solve the smaller version inside their own walls.
Who controls the agent that reads customer emails? Who controls the assistant connected to documents, calendars, and sales records? Who decides whether a support agent can answer directly or only prepare drafts for a human?
These questions are no longer abstract. Gartner has projected that by 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024. McKinsey’s 2026 State of AI survey also found that 40% of large organizations report scaling AI agents, up from 27% the prior year.
That means control is becoming a normal operating concern, not a future strategy topic.
Most teams are buying capability before designing authority
The pattern I keep seeing is simple. A team finds an AI tool that saves time. Another team finds a different one. A vendor adds an agent feature to software the company already uses. A manager approves a trial because the cost is small and the demo looks useful.
None of those decisions feels like an operating model decision in the moment. Then the organization wakes up with agents reading information, drafting work, triggering workflows, summarizing meetings, touching customer records, and influencing decisions across departments. Nobody planned an agentic organization. They assembled one by accident.
This is where the tool mindset breaks. A tool waits for a person to use it. An agent can keep state, pursue a goal, call another system, ask for more context, draft the next step, or act inside a workflow. That does not make it dangerous by default. It does make unclear authority dangerous.
The answer is not to ban agents. The answer is to stop pretending they are normal software.
Use a five-part control model
The first version of agent governance should be boring enough that the whole team can understand it. If it requires a 40-page policy before anyone can act, adoption will route around it. If it is too vague, it will not protect anything.
Start with five questions for every agent or AI-enabled workflow.
First, who owns it? Every agent needs a named business owner accountable for the outcome, permissions, review process, and decision to keep or retire the workflow.
Second, what can it touch? Define read access and action access separately. Reading a document library is different from editing it. Drafting a customer message is different from sending it. Preparing a refund recommendation is different from issuing the refund. Each permission changes the risk profile.
Third, what is it allowed to decide? Some agents should gather information. Some should draft. Some should recommend. Some should act after approval. A smaller number should act without approval inside narrow limits. The goal is not maximum autonomy. The goal is reliable throughput with the right judgment in the right place.
Fourth, how is the work reviewed? Review cannot depend on someone remembering to check. If an agent drafts outbound messages, there should be a queue. If it updates records, there should be a log. If it touches code, there should be a normal review process before anything merges.
This is where many pilots fail. The demo works because everyone is watching. Production fails because attention moves on. MIT’s reported finding that 95% of corporate generative AI pilots fail to deliver measurable financial impact is usually discussed as an ROI problem. It is also a control problem. Work that cannot be trusted, owned, reviewed, or repeated does not become financial impact.
Fifth, how do you turn it off? Every agent needs a shutdown path. If it starts producing bad work, leaking context, creating rework, confusing customers, or acting outside scope, who can pause it immediately? What systems does that person need access to? What happens to work already queued? Who gets notified?
If the answer is “IT would figure it out,” the workflow is not ready for serious use.
The companies that move fastest will look more controlled
There is a false tradeoff in a lot of AI conversations: move fast or add governance. That framing is wrong.
The teams that move fastest with agents will usually have cleaner rules, not looser ones. They will know which systems agents can read, which actions require approval, which workflows are safe for autonomy, and which decisions stay human. That clarity lets people experiment without guessing where the edge is.
Control is not the opposite of adoption. Control is what lets adoption survive contact with real operations.
The TechBBQ conversation was framed around Europe, sovereignty, and platform power. Inside a company, the question is practical: before you add another agent, can you say who controls the ones you already have?
If not, start with the control model.