Breaking Through the "Three Barriers" that Hinder Company-Wide Deployment of AI Agents: New Standards for data integration and Governance
The use of generative AI, including ChatGPT, is progressing from improving individual productivity in tasks such as document creation and information retrieval to transforming the very operations of companies.
Among these, "AI agents" that autonomously perform multiple tasks are attracting particular attention.
This article explains the risks and governance considerations that companies should keep in mind when using AI agents in their daily operations.
Furthermore, we will introduce a "connecting architecture" that enables AI agents to access business systems and internal company data.
What is an AI agent? How does it differ from conventional generative AI?
AI agents don't just respond to instructions given by humans; they can perform tasks by combining multiple processes, such as searching for necessary information, referencing internal company data, and operating external services and business systems.
On the other hand, as AI becomes more autonomous in performing tasks, the risks that companies must consider also increase.
"Is it okay to let AI access internal company data?"
"To what extent should we allow AI to control the system?"
"If AI makes a wrong decision, who will be held responsible?"
"When the number of AI agents increases, will it be possible to manage their usage and costs?"
To address these issues and ensure the safe and continuous integration of AI into business operations, governance of AI agents is crucial.
In conventional AI generation,
Humans ask questions
↓
AI will answer.
This was the primary way it was used.
On the other hand, with AI agents,
Humans dictate the objective.
↓
AI collects the necessary information
↓
AI makes the decision
↓
Operate the necessary systems and services
↓
Complete the task.
This is the point where we can entrust the task to AI.
For example, if a sales representative instructs the AI agent to "check the latest status of this customer and propose a next approach," the AI agent could retrieve customer information from the CRM, review past sales history and related information, and then create a proposal.
Taking it a step further, it will become possible to entrust AI with actual business processes such as creating and sending emails and registering data in internal systems.
In other words, with the emergence of AI agents, AI is changing from an entity that "generates information" to an entity that "performs tasks."
This change will have a significant impact on the concept of AI governance.
How will governance change with the proliferation of AI agents?
As the use of generative AI expands, companies are facing challenges in understanding and controlling its usage, such as the proliferation of AI tools and the existence of shadow AI.
We discuss the proliferation of AI and how to deal with shadow AI in more detail in another article.
However, when it comes to integrating AI agents into business operations, the scope of governance considerations expands even further.
In previous generative AIs,
- Which AI service should you use?
- What kind of data should be entered?
- How to handle AI-generated answers
These points were important.
In addition to that, AI agents also have
- What data can AI access?
- Which systems can you operate?
- What kinds of processes can be executed?
- Which processes require human approval?
- Which models can AI use?
- How to record and audit the processes performed by AI
It needs to be managed up to that point.
In other words, in AI agent governance, it's important to control not only "what the AI answers," but also "what the AI is made to do."
Three obstacles preventing the business use of AI agents.
When companies try to deploy AI agents from a limited proof-of-concept (PoC) to company-wide operations, they face three major obstacles.
1. "Uncontrollable"—The barriers to security and governance
First, IT departments and security departments are concerned about information leaks and access control issues associated with the use of AI.
"Is it really okay to hand over company data to AI?"
"Will AI operate the system on its own?"
"Can we identify all the AI agents being used?"
Concerns such as whether a company can properly manage and control AI become obstacles to company-wide deployment.
In particular, AI agents can not only refer to information but also perform actual business processes such as updating databases and sending information to external services.
Therefore, if the authority granted to AI is not properly controlled, AI misjudgments could directly lead to business accidents.
The important thing is neither to completely liberalize AI without limits, nor to ban it entirely.
It is crucial for companies to establish a safe and secure AI environment, enabling them to advance the necessary AI applications within that environment.
2. "Disjointed"—The barrier from individual optimization to organizational optimization
Even if AI is introduced, simply streamlining individual tasks such as email composition, meeting minute taking, and information retrieval will not lead to a transformation of operations across the entire organization.
Furthermore, there will be differences in how AI is used and in AI literacy depending on the department or individual.
Currently, only employees with expertise in AI are using it in an advanced way, while other employees are limited to simple chat applications.
To utilize AI agents company-wide, it's crucial not only for individuals to creatively use AI on their own, but also to develop AI agents for each specific task and create an environment where they can be used as an organization.
for example,
- Customer information search agent for sales departments
- Invoice processing agent for accounting departments
- Inquiry support agent for IT departments
We provide AI agents tailored to specific tasks, ensuring their safe delivery to users who need them.
By doing so, we can evolve AI from a "convenient tool for individuals" to a "business infrastructure for organizations."
3. "No progress"—the barrier to internal data integration
Furthermore, a major bottleneck when integrating AI agents into actual business operations is the integration with internal data and business systems.
For example, to an AI agent,
"Check the latest sales data."
"Please check the current inventory status."
"Please review this customer's past transaction history."
"Extract the cases that meet the criteria."
In order to make such a request, the AI must be able to access mission-critical system, core system, SaaS, databases, legacy systems, etc.
However, if we have to develop separate integrations for each system, the implementation burden will increase every time we add an AI agent.
the result,
Although the proof-of-concept (PoC) worked, data integration became a bottleneck during the company-wide deployment phase, and the project stalled.
This situation could occur.
To fully integrate AI agents into business operations, it's necessary to consider not only the AI itself, but also how to connect the AI with the company's internal data and systems.
Three responsibilities that should be managed in AI agent governance
As AI agents begin to perform tasks, companies will face three main responsibilities.
1. Accountability for the content—"What basis did the AI use to make its decision?"
As AI responses and judgments are increasingly used in business operations, it becomes crucial to be able to explain "whether that information is correct" and "what the basis for the judgment was."
For example, if an AI is to answer inquiries about company regulations, it needs to be able to use the latest regulations and manuals approved by the administrator as its basis.
Therefore,
- Manage the knowledge that AI can access.
- Properly manage the information that forms the basis of your answers.
- Manage the models and AI behavior used.
Such a system is required.
2. Responsibility for Action—"What to Make AI Do"
As AI agents gain the ability to operate business systems, "authority management" for the AI becomes crucial.
For example, the business risks involved in simply referencing data, updating customer information, and sending emails to external parties differ significantly.
Therefore,
- Allow references.
- Updates should only be allowed for specific users.
- External transmission requires approval.
- Important processes are subject to final verification by humans.
In this way, we appropriately control the operations that the AI can perform.
In particular, for high-impact processes such as database updates and external data transmission, a mechanism that incorporates human approval through HITL (Human-in-the-Loop) is effective.
Rather than leaving everything to AI, it's important to clearly distinguish between tasks that should be handled by AI and those that require human judgment.
3. Financial Responsibility—"How Much to Spend" on AI
As AI agents are deployed throughout the company, the number of AI models and agents used will also increase.
Furthermore, AI agents may autonomously perform multiple processes or API calls in response to a single instruction.
Therefore, AI usage may increase without the user's awareness, potentially leading to inflated costs.
Therefore,
- Manage available AI models
- Understand usage patterns by department and agent.
- Monitor the cost of using AI.
- Restrict the available models as needed.
This requires cost governance.
Three levels of authority that balance control and freedom of use
When considering AI governance, the approach of "controlling everything centrally" may hinder the progress of AI adoption in the field.
On the other hand, if everything is left to the field, there is a risk that the number of AI agents, models used, and connected systems will proliferate, making it difficult for the company to maintain control.
Therefore, what becomes important is designing authority structures that separate overall control from the autonomy of those on the ground.
For example, by dividing the work into the following three roles, it is possible to achieve both good governance and convenience for those on the ground.
AI administrator (general administrator)
We manage the company's entire AI environment.
It centrally manages available AI models, connected systems, and user permissions, providing a comprehensive overview of AI usage and costs.
The AI administrator's role is to create a "safe AI agent environment" that can be used with confidence by those working in the field.
AI Developer (Agent Administrator)
Within the environment provided by the AI administrator, you will create and manage the AI agents necessary for your department's tasks.
For example, you can register knowledge such as manuals and regulations, or incorporate business actions such as database searches and SaaS integration.
General users
We use AI agents prepared by administrators and developers in our actual work.
By giving instructions to the AI agent using natural language, you can search for necessary information and perform tasks.
Thus,
"What is permitted" is controlled by the entire organization, while "how it is used in business operations" is left to the individual teams.
By dividing roles in this way, it becomes easier to achieve both speed in AI utilization and effective governance.
How to connect AI agents with corporate data
As we have seen, simply managing the AI itself is insufficient for effectively utilizing AI agents in actual business operations.
For AI to perform its tasks, it needs access to various data and systems within the company.
Therefore, the important thing is not just to "store data," but to "connect data."
Challenges of "storage" architectures
In previous data utilization efforts, the common approach was to "store" data by aggregating it from various internal systems into data lakes or DWHs, and then using that accumulated data for analysis and AI.
There are many advantages to aggregating data.
On the other hand, when AI agents utilize the latest data from business systems, the following challenges may arise:
- Copying data causes synchronization delays.
- As secondary data increases, so does the amount of data that needs to be managed and protected.
- It is necessary to manage the consistency between the original data and the copied data.
- A new data infrastructure needs to be developed to enable the use of AI.
In particular, when AI agents make business decisions and perform processing, it is crucial that they can utilize the latest primary data from business systems, rather than outdated or processed secondary data.
A "connecting architecture" that directly links AI and business systems.
That’s why there’s a concept called “Connecting Architecture,” which integrates AI agents with existing business systems and data.
In “Connecting Architecture,” rather than copying and storing large amounts of data in a separate location for the AI, the AI agent and business systems are connected via the existing data integration platform.
With “Agent Orchestration,” the AI business execution platform provided by Saison Technology, AI agents can be connected to core databases, SaaS applications, legacy systems, and more via the “data integration” platform “HULFT Square.”
This enables AI agents to access primary data in business systems and, when necessary, perform business processes.
The advantages of a "connected architecture"
AI can be utilized without making major changes to existing systems.
Instead of significantly modifying existing business systems to utilize AI, we will connect AI with existing systems by leveraging existing data integration mechanisms.
The latest primary data is available.
By accessing the original data of the business system, synchronization delays caused by data copying are minimized, and the AI agent can utilize the latest information.
Legacy systems can also be leveraged for AI applications.
Companies have not only the latest SaaS applications, but also mission-critical system, core system and legacy systems that they have been using for many years.
In order to deploy AI agents across the entire company, it is crucial that the data accumulated in these existing systems can also be utilized by the AI.
This avoids the need to increase the amount of data copied for AI.
If there is no need to create large amounts of new data copies for AI utilization, the increase in data that needs to be managed and protected can also be kept to a minimum.
When considering AI governance, it's crucial to design not only "what to show the AI," but also "where the data is located and how the AI accesses it."
Key points for successfully utilizing AI agents in business operations
When introducing AI agents to a company, it's important to consider the following four factors together, rather than just evaluating the AI's performance.
1. Clearly define what the AI will do.
First, we need to clearly define which tasks will be handled by AI and which will require human judgment.
2. Manage the data that AI can access.
This manages which data can be accessed and which information is used as the basis for AI decisions.
3. Restrict the operations that the AI can perform.
Based on the principle of least privilege, we grant the AI agent only the necessary permissions.
4. Securely connecting AI and data systems
Integrating AI agents into actual business operations requires integration with various internal systems.
Instead of repeatedly developing individual applications, utilizing a common data integration platform creates an environment where the integration burden does not increase significantly even when the number of AI agents is increased.
The governance of AI agents is not a mechanism to "stop AI."
As the use of AI agents increases, companies will need not only to "use AI safely," but also to have systems in place to "safely entrust tasks to AI."
To that end,
- What basis does the AI use to make its decisions?
- What data can AI access?
- Which systems can AI operate?
- Which processes require human approval?
- Which AI models are available?
- How do we manage AI usage and costs?
The governance needs to be designed to include all of that.
And the foundation for this is a system that securely connects AI, data, and business systems.
To ensure that AI agents are not merely "convenient chat tools" but rather contribute to business transformation, it's crucial to consider the overall architecture, including existing data and systems, rather than just focusing on AI implementation.
Supporting the execution of tasks by AI agents
"Agent Foundation"
"Agent Orchestration," provided by Saison Technology, is an AI business execution platform for integrating AI agents into a company's actual business operations.
Based on data integration platform "HULFT Square," we connect AI agents with core databases, SaaS, and legacy systems within companies, creating an environment where AI can access business data and execute necessary business processes.
Furthermore, by dividing roles into overall administrators, agent administrators, and general users, we achieve both company-wide governance and the practical application of AI in the field.
As the use of AI agents moves from the "trying it out" stage to the "delegating tasks" stage, what's needed is not just the introduction of AI.
The goal is to securely connect AI, data, and business systems, manage them as a company, and create an environment where on-site personnel can utilize AI.
That is a crucial point for sustainably integrating AI agents into business operations.
Saison Technology Online Consultation
If you would like to hear more about our data utilization platform, we also offer online consultations.


