Agentic AI adoption: ease of approval may trump capability, report warns
A report warns that firms adopting agentic AI may favour tools that clear cybersecurity and procurement reviews easily over more capable ones.
Companies bringing agentic AI into their operations face a subtle but significant commercial risk: procurement decisions may end up favouring tools that are simpler to approve over those that actually perform the required work best, according to a report by the Actuaries Institute.
The report identifies this as a deeper concern than vendor lock-in, even though lock-in remains a real issue as integrations deepen and organisational dependence on a chosen vendor grows over time. The core problem, it suggests, is that the agent which clears cybersecurity and procurement review most smoothly may not be the agent best suited to the task.
A pre-packaged agent that fits neatly into an organisation's existing compliance posture is appealing precisely because it creates no friction. By contrast, a more capable agent may require new controls, a more demanding security review and unfamiliar vendor terms. The report cautions, however, that a pre-packaged tool may simply lack the capabilities needed to meet the required standard for a particular task — a fundamental limitation that adding more controls cannot fix.
The objective, the report argues, is not to pick the system that is easiest to govern but the one that best meets the business need, with governance arrangements proportionate to the risks it creates. AI controls should therefore be chosen and calibrated according to the specific use case, the risks involved and the organisation's risk appetite, rather than applied uniformly across every deployment.
The report also stresses the value of monitoring technical failures and customer complaints to surface AI-related risks early and allow corrective action. Claims wrongly rejected by an AI system and later overturned, for example, could point to problems with a model's performance, while customer documents containing another person's claim information could signal cybersecurity or data privacy risks.
At the same time, it notes that reviewing every interaction by hand would defeat the purpose of an agent designed to handle volume across channels. Instead, internal and external dispute resolution mechanisms need to be accessible, timely and effective, since AI agents operating at scale can generate large numbers of disputes when errors occur. Even a relatively stable error rate can translate into a higher absolute number of errors as automation increases the volume of interactions.
Quality assurance built for human-scale volumes may prove inadequate, the report warns. As throughput rises sharply, organisations should strengthen — not merely scale — their quality assurance, monitoring and statistical process controls.