Bruno Billy, President & CEO of APGAR North America, advises organizations on the operational reality of data and enterprise transformation.
Recent tests with frontier AI agents from OpenAI, Anthropic and Meta have highlighted a recurring pattern. When you give an agent an objective, it may find ways to accomplish that objective in ways you did not anticipate.
One comment from AI researchers Michael Dalton and Eric Wallace during a recent presentation particularly caught my attention. They described how models under pressure to work quickly, efficiently or with fewer tool calls can discover shortcuts rather than completing a task through the route their designers intended. They called it “cheating.”
An AI agent may find the easiest available path to achieve an objective it has been given. Unless we make the constraints explicit, we can’t assume it will prefer our authoritative data sources, follow our established processes or handle exceptions the way an experienced employee would.
Humorously, in that respect, agents may not be so different from people. They just operate at machine speed.
Governance creates friction.
Governance has traditionally focused heavily on rules: defining policies, translating them into controls and monitoring if those controls are working. That work is necessary. Some data and some actions require hard boundaries. But it is worth keeping in mind that every control does something else. Controls create friction, and friction changes behavior.
If you look around your office or neighborhood, you’ll often see a dirt path cutting through the grass, sometimes very close to a paved walkway. In user journey terms, the paved path is the intended journey or designed path. It is the route users were expected to take.
On the other hand, the dirt path is the actual journey (a.k.a., “desire path”). These paths appear when users find an easier or more natural route than the one we designed. Over time, as other users see the path emerge, people “vote with their feet” and a new default path appears.
Identify the actual journey versus the intended journey.
Data teams need to think about that dynamic. Imagine someone in the business needs data and they have two options:
1. Search the data catalog, identify the right data sets, request permission, wait for approval and then use the data for analysis.
2. Use the spreadsheet they found on SharePoint that “looks right.”
We shouldn’t be surprised when people opt for the spreadsheet. In many situations, speed matters more than perfect data.
I’ve seen this behavior firsthand. When I was in-house on a data and analytics team, one of the sales executives relied on an external consultant known for turning around analysis incredibly quickly. The biggest issue was that the underlying data often had holes, sometimes big ones. When we asked why the executive kept using the consultant, he had a pragmatic answer. He pointed out that the data was being used internally and that the analysis was almost always directionally right. For him, having something useful quickly was better than getting a more complete answer two weeks later. He understood the trade-off and made it deliberately.
That example stayed with me because it illustrates something data governance teams sometimes underestimate. People don’t necessarily bypass the governed path because they don’t value governance. The alternative simply serves their business need better.
Data governance teams should then answer the hard questions:
• Why is trusted data harder to find than an uncontrolled copy?
• Why does approval take longer than the business can tolerate?
• Are we relying on policy to compensate for poor usability?
And now, we’re introducing AI agents into those same environments.
Unlike an experienced executive who understands that a spreadsheet has limitations, an agent may simply identify the route that allows it to complete its objective most efficiently.
That changes the governance question. Instead of only asking, “How do we prevent the agent from doing the wrong thing?” we should also ask, “How do we make the right thing the easiest thing for the agent to do?”
Make the governed path easy.
Indeed, governing the agent alone isn’t enough. We also need to think about the paths available to it. Make authoritative master and reference data easy to discover and consume. Make trusted data products easier to access than uncontrolled copies. Make business definitions and approved rules machine-readable. Give agents clear routes for common actions and clear escalation paths when they encounter ambiguity or exceptions.
The best processes don’t work because employees consult governance and read user manuals. They work because the systems make the expected behavior easy and natural. Let’s design governance for AI agents the same way.
It’s also worth pointing out an additional benefit. Done well, this approach promotes greater consistency across the organization. If teams and their agents use the same governed data products, analyses start from the same business entities (e.g., customer, product) and the same definitions. You are less likely to have two teams reach different answers simply because they started with different versions of what “customer” means or different definitions of “revenue.”
Not all friction is bad, though.
None of this means getting rid of controls. The objective should be to make friction intentional. Some data and some actions absolutely need hard boundaries. The amount of friction should reflect the consequences of the action:
• An agent retrieving an approved product hierarchy may need almost no friction.
• An agent changing a supplier’s banking information should encounter considerably more.
• Accessing sensitive employee information, approving a large transaction or publishing information externally may require additional controls or human approval.
Data governance teams should spend as much time making it easy for business users to get what they need versus creating policies, setting up controls and telling people what they should do or not do. The best control may sometimes be simply making the right path the easiest one to take.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?

