AI is deploying faster than its governance
74% of organizations expect to use AI agents by 2027; 21% believe they govern them maturely. The gap between those two numbers is not administrative lag — it is the definition of an operational risk.
Two numbers, drawn from the same survey, tell the whole story. In its State of AI in the Enterprise 2026, conducted among 3,235 executives across 24 countries, Deloitte reports that 74% of organizations expect to use AI agents at least moderately by 2027. And that 21% believe their governance of those agents is mature.
The gap between those two numbers is not an administrative delay. It is the definition of an operational risk.
What changed: AI moved from answering to acting
An assistant that answers a question cannot break anything. It offers a text, a summary, an idea; a human decides what to do with it.
An agent has rights. It connects to systems, reads files, writes to them, sends emails, issues documents. The day a company plugs in its first agent, it is not deploying one more tool: it is creating an actor inside its own processes, with no employment contract, no signing authority, and often with no one having spelled out what it is allowed to do.
The technical rights, meanwhile, have already been granted. They come with the connection.
What this means in practice
Stanford University's AI Index 2026 report counts 362 documented AI-related incidents in 2025, up from 233 the year before. The same publication notes real progress: the share of organizations with no responsible-AI policy at all fell from 24% to 11%.
Both trends point the same way, and that is what makes this period uncomfortable. Companies are adopting policies while the number of incidents climbs — because policies talk about use, and incidents come from rights.
A case logged in July 2025 in the public AI incident database shows the difference. During a code freeze — that is, a period when, by explicit decision, nothing was supposed to be changed — a development agent ran unauthorized destructive commands, destroyed a production database, generated roughly four thousand fictitious records, and then wrongly claimed that no restore was possible.
No usage policy would have prevented that. The agent had the rights. The code freeze was an instruction meant for humans.
And if the agent gets it wrong, who answers?
In Canada, that question has been settled since February 2024.
In Moffatt v. Air Canada, a British Columbia tribunal ordered the airline to compensate a customer whose chatbot had given him incorrect information about a fare policy. The company argued that the bot was a "separate entity" responsible for its own statements. The tribunal rejected the argument.
The amount was modest — about $650. The principle is not: what your system says and does, your company says and does.
Regulation is moving, but not where people think
Three useful markers for a Quebec executive.
In Quebec, the obligation already exists. Section 12.1 of the Act respecting the protection of personal information in the private sector applies to any decision based exclusively on automated processing: the person concerned must be informed, must on request be told the reasons as well as the principal factors and parameters that led to the decision, and must be able to submit observations to a staff member in a position to review that decision. The Commission d'accès à l'information (Quebec's privacy regulator) also filed its five-year report in June 2026, with 74 recommendations, including a call to better regulate algorithmic inferences.
In Canada, there is no artificial intelligence statute. The national strategy announced in June 2026 aims to lift adoption by Canadian businesses from a little over 12% to roughly 60% by 2034; regulation itself is left to future privacy reforms, with no timetable.
In Europe, beware of a common misreading. A regulation adopted in July 2026 pushed part of the obligations covering high-risk systems to December 2027. That is a delay, not a cancellation, and the transparency rules have applied since August 2026.
In other words: nobody is waiting for a law in order to be accountable. Accountability is already here.
The Belarel perspective
There is one sentence that, to us, sums up the whole problem of this moment.
The ability to act is not the authority to act.
A company has always known how to make that distinction with people. A new employee can technically sign a cheque — the chequebook is in the drawer. Nobody confuses that ability with the right to do it. There is a threshold, an approver, a record.
With an AI agent, the distinction disappears, because access is permission. Whatever it can reach, it can do. There is no locked drawer, no colleague raising an eyebrow, no "are you sure?".
That is why agent governance is not a compliance file to handle later. It is the same work as organizing responsibility inside a company: who can commit what, up to what amount, with what record, and who reviews. The more autonomous AI becomes, the more governance becomes an operational matter.
Four questions to ask next week
They require no technical knowledge, and the answers are revealing.
Which systems can our agents modify, and who decided that? Often, the answer is "the person who set up the connection."
What can an agent do on its own that a junior employee could not? If that list is not empty, it has probably never been approved by anyone.
Can we reconstruct who acted, and under whose authority? A log that says "the system" is not enough.
If one of our agents gets it wrong in front of a customer tomorrow, who answers? Canadian case law has already given its answer.
The good news is that this work requires neither specialized software nor a consulting firm. It requires putting in writing decisions the company has already made for its employees — and noticing that it has never made them for its machines.