New research from Salesforce, reported this week, has put a number on something a lot of IT and security people already suspected: UK businesses are adopting agentic AI, tools that don’t just answer questions but take actions on their own, faster than they’re putting any governance around them. Task-specific AI agents are being wired into business software at a pace that’s roughly quadrupling year on year, while oversight, monitoring, and clear rules for what these agents are allowed to do are, in most organisations, an afterthought or missing entirely.
For SMEs this gap matters more than it might seem, because agentic AI tools are increasingly bundled straight into the software you already use, not a separate purchase decision someone has to sign off. Microsoft 365 Copilot, Google Workspace, and most major CRM and helpdesk platforms now ship with agent features that can draft and send emails, update records, or execute multi-step tasks on their own once switched on. A tool getting turned on by default, or by one enthusiastic team member, without anyone deciding what it should and shouldn’t be trusted to do, is exactly how this governance gap shows up in practice.
Where the risk actually sits
The problem isn’t that AI agents are inherently dangerous, it’s that most small businesses have no process for the basic questions: what data can this agent see, what actions can it take without a human checking first, and who finds out if it does something wrong. Gartner has separately predicted that over 40% of agentic AI projects will be cancelled by 2027, and the reasons cited are rarely the AI itself, they’re unclear ownership, no monitoring, and costs or actions nobody was tracking. An agent quietly emailing a client with the wrong information, or updating a customer record incorrectly, causes real damage whether or not anyone designed it maliciously.
Closing the gap without slowing down
Write down what each AI agent in your business is actually allowed to do. Even a short list, “this one can draft replies but not send them,” “this one can update a CRM field but not delete records,” turns an invisible risk into a visible, manageable one.
Review what’s already switched on. Many businesses have agent features quietly active in tools they’ve had for years, enabled in a recent update nobody read the release notes for. A 20-minute audit of your core business software’s settings is worth doing this month.
Keep a human in the loop for anything customer-facing or financial. Draft-then-approve is a small amount of friction for a large amount of risk reduction, and it’s the single most common gap Salesforce’s research points to.
If you’re building agents into your own products or workflows rather than just using off-the-shelf ones, bake governance in from day one rather than retrofitting it. BuildApps builds custom app and AI implementations with proper oversight and controls designed in from the start, and helps UK businesses adopt AI tools with a clear-eyed view of what needs supervision, not just what’s technically possible.
The takeaway
Agentic AI isn’t going anywhere, and for most SMEs the productivity case is real. But “we turned it on” isn’t the same as “we know what it’s doing.” The businesses that get the most value from AI agents over the next year will be the ones that spent an afternoon now writing down the rules, not the ones that find out the hard way what happens without them.