Category
Your AI Agent Is Already Speaking For You
AI agents are not just productivity tools; they are becoming delegated organisational actors. That makes governance of permissions, records and response a communications issue before it becomes a crisis issue.
4 min read

Is it just me, or are we still talking about AI agents as if they are clever interns?
That is the wrong frame.
An intern can draft a note, book a meeting, forget an attachment, maybe annoy a client.
An agent can read a customer file, trigger a refund, update a CRM record, send an email, brief a salesperson, generate a response, pull data from three systems and act before anyone in communications knows the organisation has just said or done something.
Check it.
The problem is no longer only, 'Did the AI say something wrong?'
The problem is, 'Did the organisation just do something through AI that it cannot explain?'
That is a very different reputation risk.
McKinsey’s 2026 AI trust research puts it plainly: in the agentic era, organisations have to deal not only with systems saying the wrong thing, but with systems doing the wrong thing. Taking unintended actions. Misusing tools. Operating beyond guardrails.
Seriously, that sentence should be printed and taped to the wall of every comms, legal, IT, marketing and sustainability team.
Because the public will not care whether the mistake came from a workflow, a plug-in, a vendor model, a badly configured connector or someone in sales experimenting with an automation tool.
They will say: your company did this.
And they will be right.
Here is the problem.
Most organisations are still managing AI communication at the content layer. Policies about disclosure. Guidance on prompts. Brand tone. Approval workflows for external copy. Maybe a line in the social media policy saying employees should not paste confidential data into public tools.
Fine. Necessary.
Not enough.
Once agents have permissions, they become part of the organisation’s operating voice.
Not brand voice.
Operating voice.
The actions they take communicate priorities. A rejected claim communicates fairness. A pricing change communicates intent. A sustainability data response communicates credibility. A customer service escalation communicates whether the company is listening or hiding behind automation.
That means communications can no longer sit downstream waiting for approved messages.
By then, the message may already have happened.
Gartner has been warning about AI agent sprawl: too many agents, too many permissions, too many unmanaged workflows, too little visibility. Their recommended basics are not glamorous: inventory agents, define identity and permissions, govern information access, monitor behaviour, remediate what exceeds scope.
Very dull.
Very important.
Because reputation usually fails in the boring bits.
Not in the keynote.
Not in the innovation lab.
In the permission nobody reviewed. The connector nobody owned. The automated response nobody tested against a vulnerable customer scenario. The sustainability claim pulled from an obsolete data source. The campaign variant generated for a segment nobody thought would ever complain.
What?
Yeah.
This is where comms people need to stop pretending AI governance is mainly an IT matter.
If an agent can act in ways that affect customers, employees, investors, regulators, communities or campaign audiences, then communications has a legitimate seat at the design table.
Not to slow everything down.
To ask the awkward questions early.
Who is this agent allowed to speak for?
What systems can it touch?
What decisions can it make without human review?
What evidence is retained when it acts?
Who gets alerted when it behaves outside expectation?
What happens if a journalist, regulator, customer or employee asks, 'Why did your system do that?'
If the answer is a shrug followed by three weeks of internal archaeology, congratulations. You do not have AI-enabled efficiency. You have automated reputational debt.
Regulation is moving in the same direction, although not always in language communicators naturally use. The European Commission’s AI Act transparency guidelines make clear that people should know when they are interacting with certain AI systems or exposed to AI-generated content. That matters.
But labels are the floor.
The bigger question is whether the organisation can account for the interaction.
A disclosure may tell someone that AI was involved. It does not prove the system had the right data, the right permission, the right escalation rule, the right human oversight, or the right correction process.
Trust does not come from saying, 'AI was used.'
Trust comes from being able to show how, why, by whom, within what limits, and with what remedy if it goes wrong.
That is why frameworks like the NIST AI Risk Management Framework are useful, not because senior leaders need another PDF, but because they force a more disciplined conversation about mapping, measuring, managing and governing AI risk.
But even that needs translation into organisational life.
For communications teams, the practical shift is simple.
Start treating AI agents as delegated actors.
Give them a mandate. Give them boundaries. Give them records. Give them escalation routes. Give them retirement dates. Give them owners.
And please, stop calling every internal automation a pilot if it is already touching real customers, real claims, real employees or real data.
That is not a pilot.
That is production with plausible deniability.
So what should change?
First, build an agent register that communications can actually understand. Not a technical asset list buried in IT. A plain-language map of where agents operate, what audiences they affect, what decisions they influence and what reputational exposure they create.
Second, create permission tiers linked to communication risk. Drafting copy is one thing. Sending copy is another. Changing customer records is another. Producing public-interest text without human review? Different level entirely.
Third, rehearse agent failures as communications events. Not only cybersecurity events. Not only compliance events. Run scenarios: wrong refund, misleading ESG response, biased customer triage, synthetic executive message, automated investor Q&A error.
Fourth, build evidence into the workflow. Logs, approvals, data sources, model versions, human overrides, correction trails. Boring again. Exactly.
Because when something goes wrong, the winning organisation will not be the one with the most inspirational AI strategy deck.
It will be the one that can explain what happened quickly, accurately and credibly.
AI agents are not waiting politely in the future.
They are already being connected to tools, data and decisions.
The communications question is not whether they speak in the right tone.
The real question is whether they are already speaking for you without anyone owning what they say, what they do, and what it means.