The three guardrails Aussie businesses need to build trust in AI agents

Progress Software’s Philip Miller explores how Australian organisations can build trust as AI agents expand across business and society.

Philip Miller
Philip Miller
Uncategorized · 2 Oct 2026 · 2 min read
Above The three guardrails Aussie businesses need to build trust in AI agents. Dynamic Business

Agentic AI is at the heart of most AI conversations today, but when you think about it it’s only become mainstream pretty recently. Yet, it’s already redefining what industries - and society at large - can achieve with AI. Machine-to-machine interactions are scaling, changing the fundamental rules of how AI is used.

A great example is the launch of Moltbook, earlier this year. To this day, Moltbook continues to generate headlines, and that’s because it feels like science fiction made real. 

But the reality is far from science fiction. In ANZ, businesses are adopting agentic AI for a wide range of use cases, from automating and improving customer service to managing personal tax returns. And according to Gartner, 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from less than 5% in 2025.

While businesses and individuals increasingly rely on agentic workflows, the question of trust becomes an essential consideration. 

As the Australian Cyber Security Centre recently pointed out, while agentic AI can automate repetitive, well-defined and low-risk tasks, these additional opportunities come with additional risks. Like other AI services, agentic AI can be misused or misappropriated, leading to productivity losses, service disruption, privacy breaches or cyber security incidents.

How can we build trust in AI agents? To answer this, we first need to understand governance in the context of agentic AI.

The self-governance question

Human social networks do not self-govern. Instead, they require identity systems, moderation and clear accountability. Similarly, agent networks do not just simply communicate; they optimise, coordinate and act. In this sense, they represent somewhat of a digital ecosystem, whereby feedback loops accelerate, iteration compounds and emergent behaviour become inevitable.

Worryingly, Deloitte found that only one in five companies has a mature governance model in place for autonomous AI.

This presents a fundamental challenge: as adoption accelerates, how can we govern these agents at scale? 

If an agent can publish persuasive content, recruit other agents or influence decisions, we need to know how it operates, who deployed it and what it has been authorised to do.

A robust agent ecosystem requires verifiable identity for both agents and operators alike. Technologies like cryptographic signing can preserve authenticity, while provenance tracking can reveal the data sources, models and tools that informed a particular outcome. When agentic systems store structured context about their reasoning, organisations can fact-check and verify claims rather than assume they are correct.

But verifiable identity is only one part of the trust equation. Other guardrails need to be put in place to build a truly trustworthy agentic workflow ecosystem.

The three agentic AI guardrails for trust 

  1. Designing for constraint

Agents should not have authority without clear guardrails; they need clearly defined permissions and strict isolation boundaries. This is critical amidst the rise of prompt injection to indirect instruction attacks, where agents encounter malicious instructions incorporated into content and follow them unknowingly. If that agent has assigned authority, the affected business risks a data leak at best—or long-lasting operational disruption at worst. 

Designing for constraint does not limit an agent’s capability; rather, it allows it to operate within safe and predictable limits. When an agent begins to question whether it has permission to act, the answer should come from a governed policy layer—not from the agent itself.

  1. Defining responsibility

If an agent spreads false information or makes an operational mistake, who is responsible? The platform, the organisation that deployed it or the operator?

These are essential questions to answer.

Right now, there are open conversations between industry and regulators, aimed at defining a framework that would solve this challenge. For example, the impending EU AI Act would require organisations to develop, document and monitor AI systems throughout their lifecycle.

But organisations shouldn’t wait for regulators to set their agentic AI trust foundations. Proactive efforts need to be made right now, as agentic workflows are being designed, rather than after the fact when it’s often too late. 

  1. Auditing at scale

Trust in AI agents is earned through managed and repeatable controls; data lineage, policy enforcement and the replication of outputs when prompted. Organisations need to understand what an agent observed, how it interpreted that information and the necessary action it took.

Moltbook is a prime example. Alongside its rapid growth, questions are emerging about whether the platform’s security can keep pace with its scale and whether the content being created is truly agent-generated. Incidents involving exposed data and misconfigurations reflect a ‘move-fast’ approach that carries a greater risk when software is mediating trust at large. 

Businesses that enforce verifiable identity, clear usage guardrails and auditing from the onset will be best positioned to govern Agentic AI as adoption accelerates. If these foundations are established early, agentic systems can evolve into reliable collaborators that assist human decisions, rather than infrastructures that function independently and beyond human oversight.

Furthermore, building trusted agents means that organisations can have more trust in AI-powered decisions as a whole, moving AI from a potential liability into a strategic business asset.

PM
Philip Miller
From the floor
Closer to this story than we are?
If you're building in this space — or watching it reshape your market — pitch us. We edit it; you get the byline.
More from the desk

Keep reading.

Founder Friday ◆

From a swallowed bottle of cleaner to a homecoming: the Soapnut Republic story

Launching somewhere you’re a stranger is in some ways easier, because you arrive without any preconceptions about how things should work. We recently caught up with Kim Gilliland, co-founder of Soa…

Yajush Gupta · 2 min
News ◆

auDA just made a move that could shake up .com.au domains

auDA approved a rule change that could affect how businesses qualify for their .com.au domain.

Yajush Gupta · 2 min
News ◆

What's the cheapest way to get paid once surcharges go?

Surcharges are gone from 1 October, and one payment option is worth a look

Yajush Gupta · 2 min
0 people like this

Comments

Loading comments…