placeholder
Stuart Gentle Publisher at Onrec

Guardrails can’t fix agents that lack context, says M-Files

As AI takes on greater autonomy, organisations must treat content readiness as a core component of governance to ensure agents can make responsible decisions

AI has proven itself as an immensely valuable tool for static cases such as data entry and communication summarisation. However, a recent report warned that the proliferation of AI agents is creating new challenges around visibility, permissions and accountability, with just 13% of organisations believing they have the right governance in place to manage them.

According to Tony Grout, Chief Product and Technology Officer at M-Files, governance must focus on the permissions as well as the context of the information granted. If organisations cannot establish whether it is accurate, relevant and appropriately governed, they cannot have full confidence in the decisions AI systems make. 

“When businesses deploy AI to streamline their workflows, they often forget the data behind it plays a vital part in its success. The admin efficiency gains are proven to be successful but the tasks that typically lie with humans are rarely simple for these systems. They require judgment, prior understanding, and, most importantly, context. With only 14% of organisations reporting high confidence that their content is AI ready, governance and data-quality should be a top priority in the boardroom if it isn’t already.”

Governance alone cannot make an AI system trustworthy. While some errors may be simple enough to catch, Grout argues that employees in complex business environments have limited time to verify every output.

“Organisations may have policies in place for how AI should operate, but if the system has no understanding of the content itself, those guardrails don't perform and deliver how they should. This creates a dangerous dynamic where AI is unchecked and overused, despite general governance practices. That risk becomes even more significant as AI evolves from providing recommendations on behalf of a business.”

Grout also notes that there is a risk of agents making tacit decisions without a clear AI strategy or the necessary information to be accurate enough.

“There has been a shift from businesses using AI assistants to autonomous agents, which has been deployed at pace. However, the architectures it’s built upon lack the trust needed to support responsible decision-making. The question for leaders to consider is: you wouldn't trust a thousand untrained employees to do a job, so why would you trust a thousand untrusted AI agents?”

Ultimately, accountability remains with the human who approved the technology, to provide it with the information necessary to function. Business leaders must ensure they understand why each agent is making each decision because the final result is theirs to own.

“Context-aware systems help AI distinguish relevant information from noise and understand the purpose behind content, instead of simply retrieving files based on keywords. It also gives humans greater visibility into the information that influenced its actions, so no action is unexplained. Without this, leaders are sleepwalking into risky and complex AI-driven decisions.”

Grout continued, “Traditional compliance models must also evolve to suit AI agents that can act independently and execute tasks at scale. Typically, compliance and context are added on rather than built into the foundation of the system, but organisations should instead view content governance as a core component of AI governance.

“This can prevent security and liability risks that ultimately fall on the human supervisor. For example, a key security risk is the differing information access AI agents and human employees have at their disposal. These systems need to be made explicitly aware of what to do if there is a human or other agent that does not have security access to all the data. Without this, agents can act on behalf of employees who do not have the clearance necessary.”

Grout concluded, “As organisations move from AI-assisted tools to agentic workflows, the role of trustworthy, context-aware content becomes the prerequisite for effective AI adoption and governance. With the right information and data foundation will allow for sharper decisions, efficiency, sharper decisions, and more importantly, trust in AI value.”