Trust and Safety Outlook 2026

AI agents as workforce counterparts—what governance should look like

  • Report
  • July 17, 2026

Key takeaways:

  • AI agents need enough access to be useful, but not so much autonomy that they create unmanaged risk. 
  • Each agent should have a verified identity, defined role, task-specific permissions, and auditable records. 
  • Access governance should reflect industry risk, organizational role, agent-to-agent interaction, and task scope. 
  • Human oversight should increase as agent autonomy and consequence increase.

AI agents are transitioning from assistive tools to workforce counterparts. That shift creates a practical governance challenge: Agents need enough access to complete cross-functional work, but not so much autonomy that they create unmanaged security, compliance, or trust risks.

In PwC’s Trust and Safety Outlook 2026 research, 85% of US respondents say they have confidence in AI agents conducting at least one task in their daily work. However, these rapidly expanding capabilities also introduce a set of governance challenges that many organizations are not yet equipped to handle.

Organizations should use a governance model that treats agents as workforce counterparts without treating them as employees. Each agent should have a verified identity, a defined role, task-specific permissions, auditable activity records, and clear limits on autonomous action. Access should expand only where the agent’s purpose, the supported employee’s role, and the regulatory environment allow it. As autonomy increases, human oversight should also expand—especially over actions that affect customers, employees, sensitive data, financial outcomes, or legal obligations.  

Understanding AI “worlds” and why they need to evolve

Typically, enterprises respond to AI adoption by creating worlds—discrete environments with a delineated network of applications and APIs that an agent is allowed to interact with. These boundaries help prevent data leakage, support compliance, and make AI behavior more predictable. They can also limit the cross-functional activity that makes agents valuable.

By containing AI access within worlds, companies reduce the risk of sensitive data crossing into the wrong hands and enable auditable traceability of AI agents’ actions. However, these worlds are often designed for containment, not for dynamic problem-solving.

As agents are deployed for increasingly complex tasks that span multiple data sources, they require information that lives in multiple worlds simultaneously. Without flexible access, agents are limited in their decision-making and what they can accomplish. Employees are left manually managing and coordinating disconnected agents, reducing potential efficiency gains.

A more mature framework mirrors how human access already works—tiered by role and seniority—while recognizing that agents require different controls: shorter permission windows, tighter task scoping, continuous monitoring, and clearer accountability for the human who deployed or approved the agent.  

The AI agent access hierarchy

Effective agent access governance should be determined by four factors working together: industry, organizational, industry, agent-to-agent interactions, and tasks.

The industry the AI agent operates within should dictate the ceiling of access for both the organizational level and regulatory environment—whichever is more restrictive.

In highly regulated industries, such as healthcare, financial services, law, and defense, this constraint is significant. A hospital’s HIPAA obligations mean that no agent, regardless of who authorized it, can autonomously access individual patient records unless that access is legally permitted, properly scoped, and governed by appropriate controls.

Meanwhile, in less regulated environments, such as technology and media, the regulatory constraints may be lighter, and agents can operate with considerably more autonomy at the same seniority level. For example, a product manager at a tech company may be able to authorize an agent to analyze capabilities and gain access to data that a hospital executive couldn’t authorize for patient-level data.

The framework accounts for this through an industry risk profile that’s applied before the hierarchy model. Every organization using this framework should begin by identifying the minimum set of constraints imposed by their industry before mapping workforce levels to agent access tiers. This approach is consistent with responsible AI: Governance should enable value, but it should start from the risks, obligations, and trust expectations of the operating environment.  

Two fundamental points must be true: Each agent needs its own verified identity, distinct from the employee it serves; and that identity must match the level of access and seniority of the employee it serves.

The solution is to issue agents their own credentials that carry information about each agent’s authorization tier and any access that has been granted for a specific task. When an agent crosses a world boundary, that credential can be validated.

In organizations where employees use multiple agents simultaneously—a research agent, a communications agent, a scheduling agent—each one requires its own distinct credential. Credential expiration should also be built in from the start, so stale permissions don’t persist after an employee’s role change or departure. This is where access governance should connect directly to workforce processes, including onboarding, role changes, internal mobility, and offboarding.  

As organizations become more sophisticated with AI, agents will increasingly work with other agents. A senior leader’s agent might orchestrate a set of specialized agents to complete a complex workflow, such as one agent gathering data from finance, another from HR, and another synthesizing the output into a recommendation.

Agent-to-agent interactions should be governed by the most restrictive applicable permission set. When a higher-tier orchestrating agent calls a lower-tier agent to complete a subtask, the downstream agent should operate only within its own standing permissions. This safeguard may limit what the workflow can accomplish, but it also helps prevent privilege escalation, permission laundering, and unintended data movement.

The risk of data exfiltration and agent manipulation for widespread organizational harm can be addressed at the technical level by enforcing world-boundary checks at every agent hop, not just at the entry point of the workflow. This should be enforced via a traceable, auditable activity trail. Establishing these foundational elements early is critical as organizations scale agent usage.  

The task that the agent has been deployed to perform is one of the most defining factors in determining access. Two agents serving the same employee can require very different access depending on what they’re being asked to do. A research agent for a given employee needs read access to a defined set of sources, while a workflow agent coordinating a multi-step process for the same level may need temporary, scoped access to multiple worlds. Each should be provisioned to match its specific function.

Task scope also determines whether access should be permanent or temporary. Standing role functions can be supported by static permissions tied to the employee’s tier. Project-based work calls for time-bound tokens that grant entry to specific worlds and expire automatically when the work is done.  

Risks to watch for

Even a well-designed framework can face real challenges in deployment. Understanding them early is what separates organizations that govern AI well from those that are caught off guard.

Technical and security risks

Organizations should use active monitoring systems that can detect unusual agent behavior in real time, clear internal policies that assign accountability before something goes wrong and enter contractual agreements with AI vendors that address model updates, data handling, and behavioral changes. Governance that only defines what agents are allowed to do, without tracking what they’re actually doing, is incomplete.

Key considerations include:

  • Agents taking higher-impact actions than intended
  • Agents chaining tool calls to accumulate access beyond their approved scope
  • Permission laundering in multi-agent workflows
  • Employees creating unapproved agents to bypass oversight
  • Vendor-driven model changes that alter agent behavior in ways the organization does not immediately detect
  • Accountability gaps between how responsibility is shared between departments such as employees, IT, security, compliance, and more

Agent maintenance risks

Mitigating maintenance risk requires treating agents the same way organizations treat software systems—with defined ownership, scheduled reviews, and documented change management processes. At a minimum, organizations should establish review cadences tied to calendar milestones and trigger events, such as role changes, system changes, model updates, regulatory changes or material shifts in agent performance. They should also maintain auditable documentation of agent activities, approvals, tuning decisions, and access changes.

Key considerations include:

  • Agents are non-static deployments which require continuous maintenance to remain up-to-date, secure, and aligned with organizational principles
  • Agent maintenance models that are continuously updates with organizational priorities, role changes, regulatory changes, and cross functional data inputs
  • Agent maintenance resourcing in terms of humans to make updates to agent roles, expand access, suspend activity or deprecate them
  • Agent performance evaluation frameworks to evaluate drift and output quality

Ethical and equity risks

Performance reviews, hiring decisions, disciplinary actions, and terminations all carry significant consequences for real people. Even when a human manager makes the final call, an agent that frames the data, selects what to surface, and structures the recommendation is shaping the decision in ways that may not be visible to the person responsible for making it. The distinction matters: the agent supports the decision; the human owns it. But that accountability is only meaningful if the human can see what the agent did and why.

When asked what would increase their trust in AI systems handling important or personal tasks, 37% of those surveyed named human and expert review of high-risk or complex situations as a top response. Decision-making transparency is also essential—and, in certain industries and contexts, legally required.

Key considerations include:

  • Some decisions—hiring, promotion, discipline, termination—should be explicitly excluded from autonomous agent action by policy
  • Where agents support high-impact processes, affected individuals should have plain-language visibility into what data was used, what the agent did, and where human judgment entered
  • Organizations should conduct regular evaluations for bias, accuracy, reliability, drift, and unintended outcomes  

Getting started—a phased approach

Organizations should think about agent access in phases:

  1. Industry risk profile: Assess and define risk profile of your industry to map agent identities that meet necessary risk and compliance thresholds.
  2. World creation and access governance: Map existing data environments into functional worlds against the tiers, identify industry-specific no-fly zones, and institute enterprise-wide data controls to prevent loopholes in agent-access. Establish a governance policy to define who can create and modify worlds and access.
  3. Agent access, interactions, and life cycle management: Map agent access tiers to workforce levels using the organizational framework that includes defining appropriate data, agent-to-agent communication permissibility, and world access at each level. Integrate agent access provisioning into HR workflows which should be governed with clear communication standards, permission inheritance rules, and full call-graph logging.
  4. Quality assurance stop gates: Implement human-in-the-loop checkpoints that govern consequential actions.

Static world segmentation—the rigid boundaries around what each agent can access—won’t scale. As agents take on more complex, cross-functional work, those boundaries will increasingly hold organizations back.

The framework proposed here treats agents as governed workforce counterparts—powerful and increasingly autonomous, but always bounded by identity, access, accountability, and oversight.  

Trust and Safety Outlook 2026

FAQs

AI agents should have verified identities, defined roles, task-specific permissions, auditable activity records, and clear limits on autonomous action. Oversight should increase as autonomy and consequence increase.

AI agents often need cross-functional access to complete work, but unmanaged access can create data leakage, security, compliance, and accountability risks. Access should be scoped by industry, role, task, and interaction type.

Contact us

Daniel Hays

Principal, Consulting Solutions, PwC US

Kim David Greenwood

Principal, PwC US

Rahul Kapoor

Principal (Partner), PwC US

Follow us

Required fields are marked with an asterisk(*)

Your personal information will be handled in accordance with our Privacy Statement. You can update your communication preferences at any time by clicking the unsubscribe link in a PwC email or by submitting a request as outlined in our Privacy Statement.

Hide