THE POLICY EDGE
Reports/Data Releases

19 September 2026

OECD: Companies Are Putting AI Agents to Work but Keeping High-Stakes Decisions Human

Interviews with 25 organisations show AI agents moving into business and public-sector workflows, particularly where tasks are structured and results can be checked. None reported giving such systems unrestricted autonomy, while evaluation, cybersecurity and accountability remain underdeveloped

Reports/Data Releases image

Key Details

The OECD paper Agentic AI in organisations: Early insights from practitioner interviews provides an early qualitative picture of how organisations are using and governing agentic AI; it does not measure economy-wide adoption or productivity.

  • Evidence base: Interviews with 25 organisations across 11 countries, including technology developers, enterprise users, government agencies and research institutions.

  • Current applications: Internal workflows, customer support, software development, cybersecurity, compliance, supply-chain planning, infrastructure management and scientific research.

  • Best near-term fit: Tasks that are structured, verifiable and reversible, but still require judgement or coordination across systems.

  • Level of autonomy: No participating organisation reported deploying agentic AI with unrestricted autonomy.

  • Common controls: Human approval for high-impact actions, restricted permissions, sandboxing, audit logs, agent registries and grounding in trusted data.

  • Persistent gaps: System-level evaluation, agent identity, cybersecurity, traceability and accountability when several agents or organisations interact.

  • India example: Infosys described enterprise agent-development tools and internal uses in accounting and facilities management.


What Is Agentic AI?

An AI agent can interpret a goal, plan steps, use tools and act on an environment with some autonomy. Agentic AIusually refers to a system in which several specialised agents coordinate to complete more complex tasks over longer periods with limited human intervention. Unlike a chatbot that mainly produces an answer, an agent may also query databases, alter software, initiate transactions or trigger other actions. That ability to act makes permissions, monitoring and accountability central governance questions.


Operational Use Is Advancing Selectively

Organisations reported agentic AI use in customer service, account reconciliation, software testing, cybersecurity and research, while public agencies described more cautious applications such as email triage, coding and case preparation.

Maturity varies from operational systems to pilots and longer-term concepts. The evidence therefore shows growing adoption, not widespread autonomous deployment.

Near-term use is concentrated where tasks have defined steps, outputs can be verified, errors are reversible and agentic capabilities add value beyond conventional automation. Several organisations also deploy agents internally before exposing them to customers, allowing failures to be identified in controlled settings.


Bounded Autonomy Is Emerging as the Practical Model

Rather than choosing between full automation and constant human supervision, organisations are giving agents limited authority within predefined boundaries.

Consequential actions such as payments, data deletion and policy overrides often require human approval. Some organisations increase autonomy as reliability improves; others use fixed rules that allow an agent to recommend but not execute certain actions.

Common safeguards include least-privilege access, separate agent authentication, controlled testing environments, resource limits, approved-agent registries and activity logs.

These practices are not yet standardised, but show responsible-AI principles being translated into operational controls.


Risk Rises When AI Can Act, Not Just Advise

Language-model errors become more consequential when an output can trigger a transaction or alter a system. Agents may select the wrong tool, use incorrect parameters, act on hallucinated information or follow malicious instructions. In multi-agent systems, errors can also cascade across otherwise functioning agents.

Key unresolved issues include:

  • identity and access systems designed for people rather than autonomous agents;

  • evaluation focused on speed or efficiency rather than safe execution;

  • unclear responsibility when agents from different organisations interact;

  • human over-reliance on authoritative-looking outputs; and

  • unpredictable computing costs, with two organisations reporting cost overruns.

The evidence suggests early convergence around safeguards, but no settled framework for evaluating or assuring agentic AI.


India Appears Through an Enterprise Case, Not a National Assessment

Infosys was the sole India-based organisation among the 25 participants. It described Infosys Topaz Fabric, an enterprise platform for developing and governing multi-agent systems, along with internal applications in accounting and facilities management.

For accounting, agents perform routine work such as invoice matching, reconciliation, validation, anomaly detection and preparation of entries. Material exceptions, low-confidence results and high-impact financial decisions are escalated for human review. In facilities management, agents analyse building and mobility data to improve energy efficiency and reduce carbon impact.

These examples illustrate bounded enterprise deployment in India. They do not establish how widely Indian companies or government agencies have adopted agentic AI.

The report’s wider findings on non-English deployment are especially relevant to India. Organisations reported that language performance can affect not only communication but also an agent’s ability to interpret intent, apply domestic rules and choose tools correctly. Reliable use across Indian languages will therefore require language-specific testing in the actual legal and administrative context, not only translation of an English system.


Policy Relevance

For India, agentic AI shifts governance from supervising what a model says to controlling what a digital actor is permitted to do.

Government deployment: Public agencies will need defined autonomy levels, named human responsibility and an auditable record of every consequential action. Systems assisting with benefits, licences, taxation or regulatory decisions require more stringent controls than agents summarising documents or scheduling work.

Cybersecurity and enterprise governance: Agent identity, restricted permissions and approved-agent inventories become important alongside conventional data protection. CERT-In guidance and organisational security policies may need to address agents that call tools, access credentials and act across connected systems.

Procurement and IndiaAI programmes: Buyers need to know which models, tools and data sources an agent uses; where information is processed; how vendors record actions; what limits apply to cost and permissions; and how responsibility is divided when several providers are involved. Model-level accuracy alone is an inadequate procurement test.

India’s multilingual environment adds another requirement: agentic systems should be evaluated for task completion, tool selection, traceability and safety in each language and domain in which they will operate.


Follow the Full OECD Paper Here: Agentic AI in Organisations: Early Insights from Practitioner Interviews

Rethinking Public Policy Through Insight | Inquiry | Impact

Opinion • Grassroots Voices • Policymakers Perspectives • Expert Analysis • Policy Briefs