GUEST OPINION: The next major shift in enterprise technology is no longer centred on mobile apps or cloud platforms, but on autonomous software systems that can act, decide and transact independently.

AI agents are rapidly emerging as what some industry observers call the “fifth channel” of commerce, alongside web, mobile, voice and physical interactions. Their rise is forcing executives to rethink long-standing assumptions about trust and identity in the digital economy.

For corporate Australia and global enterprises alike, the implications are significant. The challenge is no longer simply deploying AI but governing it at scale.

The new channel reshaping enterprise architecture

Traditionally, digital strategies have been organised around four primary channels with each introducing its own operating model for security, customer experience and growth measurement. The web era introduced perimeter-based security, mobile accelerated identity-based authentication, and cloud computing centralised access control systems.

AI agents disrupt this progression by introducing non-human actors into the core transaction layer of business systems. These agents can retrieve data and interact with external platforms continuously and at a speed far beyond human monitoring capacity.

However, unlike human employees, these agents do not naturally fit into existing identity and access management frameworks. That mismatch is beginning to surface as both a technical and governance issue.

Governance gap widens as adoption accelerates

Despite rapid uptake, governance maturity is lagging behind deployment. A survey of more than 500 data professionals shows that while 41% of organisations are already using agentic AI in daily operations, only 27% believe their governance frameworks are mature enough to manage these systems effectively.

The risks are not theoretical. According to consulting firm McKinsey, 80% of organisations using agentic AI have already encountered concerning behaviours, including unauthorised system access and improper exposure of sensitive data.

Traditional identity systems were designed around the simple assumption that humans are the primary actors initiating system interactions. In an agent-driven environment, that assumption no longer holds. Machines now initiate transactions, often on behalf of users, other systems or entire business units.

This raises a fundamental question for boards and executives. How do they assign accountability when the actor is not human, but software operating autonomously within defined constraints?

Building a new trust foundation for autonomous systems

The emergence of AI agents requires a redefinition of digital trust. Rather than focusing solely on human identity, organisations must now extend governance to include the lifecycle and behaviour of autonomous systems.

Three core dimensions are increasingly seen as foundational. First, organisations must establish clear authorisation chains, identifying who deployed or approved an agent and on whose behalf it is acting.

Second, they must define precise operational boundaries detailing what the agent is permitted to do, which systems it can access and under what conditions. This includes limiting escalation pathways and constraining access to sensitive data.

Third, organisations need continuous behavioural governance, ensuring that agent activity is monitored, auditable and adaptable over time as conditions change.

Together, these principles form the basis of a trust model that extends beyond static identity verification. In an agent-driven environment, trust has to be continuous and context-aware, reflecting the reality of systems that operate independently and at scale.

Preparing for the agent-driven economy

For business leaders, the rise of AI agents is already becoming an operational reality inside enterprises. Preparing for this shift requires more than incremental policy updates. It demands a structural rethink of identity, governance and risk management frameworks. Executives are increasingly being advised to focus on four priorities:

Organisations should formalise trusted delegation models, treating each AI agent as a distinct digital identity with clear ownership, classification and lifecycle management.

They must enable secure digital workforces, recognising that agents will increasingly function as autonomous contributors within operational processes. This includes defining task boundaries and visibility controls.

Firms need to embed transparency across agent interactions, ensuring that every action can be traced back to its origin, intent and policy constraints. This is critical not only for compliance but also for maintaining confidence.

Organisations must also extend zero trust principles to the agent layer itself, ensuring that every interaction is authenticated, authorised and continuously validated across its lifecycle.

Trust becomes the new competitive advantage

The emergence of AI agents as a fifth digital channel marks a decisive shift in how organisations operate, compete and manage risk. What began as a productivity enhancement is rapidly evolving into a foundational layer of enterprise infrastructure.

Yet the core challenge is not technological but rather institutional. As autonomous systems become embedded in critical workflows, the ability to maintain trust, accountability and control will increasingly define organisational resilience. The companies that succeed in this transition will not necessarily be those that deploy AI agents fastest, but those that build the strongest frameworks for governing them. In the agent-driven economy, trust is no longer a background assumption. It is now the operating system.