Forrester argued that most companies govern the systems around AI agents rather than the agents' own decision-making, controlling credentials, logging tool calls and routing risky actions to human approvers. It set out five test scenarios in which every individual action passes policy while the overall outcome breaks it, such as splitting a payment into smaller compliant transfers or five agents each contacting the same customer once. It also grouped the current vendor approaches to closing this gap and said no single supplier covers the problem end to end.
What it unlocks
A structured way to test whether existing controls would catch failures that arise from sequences of individually compliant agent actions.
- forrester.com2026-08-27