cd /news/ai-agents/rethinking-and-realigning-it-for-the… · home topics ai-agents article
[ARTICLE · art-128923] src=cio.com ↗ pub= topic=ai-agents verified=true sentiment=· neutral

Rethinking and realigning IT for the agentic AI era

Three-quarters of enterprise leaders are adopting agentic AI, but only a small minority have implemented meaningful production applications, according to Forrester's State of Agentic AI 2026 report. CCS CTO Richard Mackey said an agent produced a presentation in 15 minutes that would have taken him four hours, while Capital One vice president of enterprise AI Rashmi Shetty said organizations must govern data, agent identities and permissions, tool access, and human intervention points. Palo Alto Networks CIO Meerah Rajavel said distinguishing AI automation from agents is critical because agents must reason and continuously learn.

read12 min views2 publishedSep 14, 2026

Even as a seasoned IT leader, Richard Mackey’s jaw drops in amazement over what AI and AI agents can help him do — especially when it comes to the tasks he dislikes the most. “It’s like my long-lost friend,” says Mackey, CTO of healthcare company CCS.

For example, while Mackey has become adept at creating PowerPoint presentations, he appreciates how fast an agent can make one for him. Recently, Mackey delivered a presentation to CCS’s CEO and others that an agent put together, which he admits was pretty good. “This would have taken me four hours … and the basic part of it was done in 15 minutes, which is crazy.” Having an agent do this shifts the work for humans, he says. “I like this approach because it creates the starting point.” Mackey adds that he used a watermark to attribute the presentation to AI and modified about 20% of it, but “those are the kinds of things that I find all the time are helping me go faster.”

It’s that kind of ringing endorsement that is helping fuel the rise of AI agents, prompting IT leaders to fundamentally rethink how IT operates as they move beyond chatbots and copilots to autonomous systems that make decisions, execute workflows, and interact with multiple enterprise systems. That reset includes how they should organize IT teams, leverage data, re-engineer their technical stacks, and interact with business partners to make the most of agentic AI.

Three-quarters of leaders at enterprise organizations are adopting agentic AI, but only a small minority have implemented meaningful production applications, according to Forrester’s State of Agentic AI 2026 report. Even companies at the leading edge have not yet realized the expected value promised by agentic, the report states.

“In 2026, we see agentic technology rapidly changing software markets, even as enterprises slog through the morass of challenges between promise and payoff,” the report notes. “The core question is, will the engine of agentic pull the enterprise payload?”

While that remains to be seen, agentic AI requires organizations to move beyond individual models toward governing the whole system in which models operate, observes Rashmi Shetty, vice president of enterprise AI at Capital One. “That means governing the data and context moving across agents, their identities and permissions, the tools they can access, the actions they are permitted to take, and the points where a human needs to step in.” Capitol One

Amid the exuberance surrounding agentic in the enterprise, continuous evaluation and observability remain important, Shetty stresses. “Teams need to understand how agents are behaving in production, which tools they are invoking, whether agentic systems are achieving their intended goals, how the system performs end to end, and where latency or failure occurs.”

The organizations best positioned to scale agentic AI “will build these capabilities into enterprise platforms from the outset, creating a governed path from rapid experimentation to safe, reliable production deployment,” Shetty says.

Understanding the difference between AI and agents is critical, says Meerah Rajavel, CIO of Palo Alto Networks, noting that AIs involved in automation are sometimes misconstrued as agents.

As opposed to generic AI automation, agents perform specific work and must be capable of reasoning, continuously learning, and updating its memory, Rajavel says. Agentic workflows take that concept a step further, clustering agents to work together to achieve a task.

“An agent is an atomic task level, and an agentic workflow is achieving a business outcome in a complex world,” she explains.

“Getting to a true agent does take a complete reimagination of how you do the work,” she adds.

At Palo Alto, all employees have access to Panda AI, an internal agent built with AI workflows more than a year ago to handle IT, travel, expenses, and HR issues. Panda AI has automated 82% of tickets and reduced IT operational costs by almost 70%, Rajavel says.

Palo Alto Networks

Palo Alto responds to more than 900 RFPs annually, and IT has built another AI agent that automates the first draft of complex RFPs, which is then validated and refined by a team of consultants.

“It used to take six to eight weeks to get a good RFP done,” Rajavel says. “Today, it’s a matter of hours.” The company is in the early stages of building more agents, but it’s a process, she says.

“Before you build an agent or agentic workflow, you really have to go and spend a lot of time looking at the data” and determine what data is and is not available, Rajavel says. “You need to really do a deep rip out of your current state, and then you have to completely forget [how work is done] today and go to a clean sheet and say, ‘What is our first principle thinking in an agentic world? Should we then bridge it?’ That’s where the trick comes.”

Mike Tria, CTO of online payroll provider Gusto, says his company is moving toward agentic capabilities that will be autonomous and proactive. To get there requires investing in an automated testing infrastructure, he says.

When building agentic capabilities, the goal is to ensure that the systems are doing what they’re designed to do, Tria says. It’s no longer just about continuous integration — the second layer is adding the ability for the agent to conduct evaluations.

Gusto

“Having a really good test infrastructure will tell you when you have outdated data,” Tria explains. “It’s expensive for companies to do vast exploration. Agents can be pretty smart about knowing when something is outdated. Lean on that first.”

Companies are investing in knowledge layers and ontology systems, and IT should build something that sits above the data that helps describe the business and how its systems work, he says. “Give your agent access to that. You should fix the data, but you want to make sure you fix the right stuff.”

CCS has just over 1,000 employees and serves hundreds of thousands of clients. Mackey says that when IT began looking at how agentic could help its business, there were many potential areas, including corporate, sales and marketing, and the contact center. Like many organizations, CCS opted to begin with the latter because officials saw a good opportunity to increase call resolution over time.

So the IT team introduced an agent called CC at the start of 2026, and now over 30% of calls are being resolved autonomously. What officials didn’t anticipate was that as agents handled more calls, the ones that reached humans became more complex. It wasn’t that the agents were failing, but that the human conversations required more judgment and problem-solving, changing the nature of the work.

“What we like to say is we’re not in the business of trying to replace humans with machines,” Mackey notes. “We’re in the business of augmenting our human capabilities with these tools.”

CCS

The goal is to help patients and teams automate where it makes sense, he says. At the same time, Mackey adds, they are not trying to replace clinical judgment.

“We’re not trying to have machines make decisions around or judgments or evaluations of any kind of a clinical nature, but we are trying to automate tasks that may be more mundane and more mechanical,” he says. Employees are now addressing “more of the exceptions” that come into the contact center, and those exceptions take longer sometimes to resolve, he says.

When CC was first rolled out, IT didn’t anticipate that there was, and will likely always be, a significant number of people who want to talk to a human no matter what, Mackey notes.

However, “the next wave of investment” will be to build features that enable the agents to offer up what they can help with when a caller asks to speak to a human. The agent will then ask whether they want to continue interacting with it — with the understanding that someone can still talk to a human if they want, Mackey says.

Another key concern when moving forward with agentic AI is the need to apply guardrails so that IT has accountability for how agents operate in production. That’s critical for CCS as a healthcare entity. Even though agents are only performing tasks that speed up administrative work or share information, Mackey knows that will change.

“We see that as a technology team, a year or two from now we’ll be using more agentic AI in how we develop software and how we help answer service desk calls — even how we run projects with our business partners,” he says. “But we’ve made certain decisions that we should have a human in the loop [and] that we should not be automating clinical decisions.”

Palo Alto Networks is implementing security and privacy guardrails, but Rajavel says there are “business boundaries type of guardrails” as well.

“We definitely hold the business to say what are the guardrails that they need,” she says, which involves enlisting stakeholders to decide what to allow an agent to do and not do.

“For example, there are certain approval agents that we have, and the entire approval framework of what is allowed and what’s not allowed is a pure business decision,” she explains. “And then, when it really comes down to making sure the agent cannot operate out of its boundary, … how do you stop the agent? That’s actually what I focus on.”

Gusto’s Tria says compliance regulations are useful guidelines in the agentic world. To avoid having an agent go rogue, IT puts it in a sandbox “where quite literally, they can’t break out,” he says, adding, “that doesn’t mean you don’t have to audit them. We still have our security team doing regular audits.”

“In a lot of ways, you want to treat these agents like you treat an employee — trust and verify,” he says. That means giving employees the tools to do their jobs and periodically conduct performance reviews on the agents in the same way humans are reviewed.

There are also trust issues enterprises need to consider. A new report from SAS and IDC finds that nearly 89% of respondents say AI agents already play a role in decision-making, yet trust in agentic AI is 10 points lower than trust in generative AI.

Mackey believes the structure of IT will likely change in the next year two. Gone are the days when IT would run a job at night, and if part of that job failed, an email would be sent informing employees to hold off on accessing certain information until IT gave the green light.

“If you’ve got an agentic system that’s accessing data, it doesn’t know to read the email unless you tell it,” he says. “So, a lot of our systems now need to be reengineered to elevate the importance of the data integrity, and we’ll have to have new systems.”

Moreover, in the future IT will also need to devise “new ways of managing these agents, because the speed at which they work requires that the other systems be integrated so that they are aware of that,” Mackey says. “That is a realization we’ve had in the last six months.”

Developer skills will also change of time as their workflows become more agentic. “It’s less important that our developers are writing actual lines of code and more important that they understand the context and the inputs and the outputs that are being required in the change,” he says.

Gusto CIO and CISO Mike Wittig says the company has already created AI agent manager roles where people are responsible for the performance, roadmap, and metrics of AI agents.

“This is a hybrid of product and engineering roles where the agent manager needs to understand their stakeholders and meet regularly with them to review health metrics and roadmap items for the agent, as well as contribute to the backlog by building new agent functionality,” he says. “This also ensures human accountability for agentic activity, which is a core tenet of our strategy as we continue to scale with AI.”

Palo Alto’s Rajavel also sees roles, such as in software development, evolving over time. While engineers still need to make modifications to AI-generated code, she says, “[AI] does a significant lift. So I have to reimagine the role of some of our software engineers.” Now they spend more time on design thinking and building security into the code, as well as scalability and performance.

Also, pursuing agentic AI is changing how IT and the business collaborate, she adds.

“Our [product managers] are not anymore just sitting with the business talking about the requirements. They are actually sitting with the business building out a prototype version before even getting out of the conversation,” Rajavel says. “That means you need the product manager to be more tech savvy and more comfortable with using AI tools to go from a business problem to a conceptual solution.”

Similarly, she adds, software engineers should be more comfortable “cutting across rather than [making] a narrow slither to more depth and breadth.”

When deciding where agentic makes sense, Rajavel looks at whether a workload requires reasoning, some level of understanding, and continuous learning, she says.

Her roadmap for the next year is to determine which AI technologies have the highest ROI for disruption. Often, it takes 12 to 18 months to gain the full benefits, she notes. That was the case with Panda AI — it took about 12 months to go from 12% automation to 16% automation, and today, it stands at 83%.

Further, IT is constantly revising what its business priorities are, which makes targeting the right workflows for an agentic overhaul all the more important.

“Make sure your use cases are the right fit for it,” she advises, adding that here data volume and integrity is important. Often, people hold onto a lot of “tribal knowledge,” she says, and you have to figure out how to give the agents that knowledge, “otherwise your agents are not going to be effective.”

She also advises not underestimating the importance of “keeping the agents continuously on track.” That requires “having clarity of ownership and making sure … you have a person who’s accountable to make sure this is actually behaving as intended and having the right guardrails and right evaluations,” she adds.

While all the IT leaders say that AI and agentic are helping their organizations move faster and be more efficient, Gusto’s Tria says that creates a perspective that security is being sacrificed. “Moving faster does not mean you are dropping rigor. Moving faster does not mean that you are less reliable or less secure,” he says. “We have a lot of confidence internally that the very same agentic capabilities that make us go faster also increase the reliability of our systems. … It’s actually a win-win.”

── more in #ai-agents 4 stories · sorted by recency
── more on @richard mackey 3 stories trending now
sponsored brought to you by zahid.host 4,200+ EU-deployed projects
reading about agents? ship yours in a single git push.

Run your AI side-project on zahid.host

EU-based hosting, git-push deploys, automatic HTTPS, no cold starts. Free tier with a custom domain — perfect for shipping the agent you just read about.

$git push zahid main
Live at https://your-agent.zahid.host
Get free account → Pricing
from €0/mo · no card required
LIVE [news/rethinking-and-reali…] indexed:0 read:12min 2026-09-14 ·