
As enterprises move from AI-assisted workflows towards systems that can plan, make decisions and execute tasks, governance becomes a core operational requirement. Agentic AI can interact with applications, access enterprise data and initiate actions with limited human intervention. Indonesia is also developing national AI governance measures, with the government preparing a Presidential Regulation covering AI and its ethical framework.
For CIOs, regulators and technology leaders, the priority is establishing controls that allow innovation while maintaining accountability, security and auditability.
Traditional AI generally produces an output after receiving a defined input. Autonomous systems can take this further by interpreting objectives, creating action plans, using connected tools and adjusting their actions based on results. This creates opportunities across customer service, IT operations, finance, cybersecurity and supply-chain management.
However, greater autonomy introduces additional control requirements. An AI system with permission to modify records, initiate transactions or access sensitive systems can create operational consequences without conventional approval workflows. NIST’s AI Risk Management Framework (AI RMF 1.0) recommends managing AI risks throughout design, deployment, use and evaluation, with governance operating across the entire lifecycle.
AI governance must be established before autonomous systems receive meaningful access to enterprise processes. As AI adoption expands rapidly, Indonesia’s Ministry of Communication and Digital Affairs (KOMDIGI) has highlighted concerns involving data security, misinformation and the need for stronger governance.
For enterprises, governance should therefore define acceptable use, risk thresholds, accountability and intervention mechanisms before deployment. The objective is not simply to approve an AI system but to determine what it can access, which decisions it can make, when human intervention is mandatory and how its actions can be investigated.
Enterprise-scale deployment requires governance that clearly defines where autonomous systems can operate and where human authority must remain. Clear ownership and accountability structures should assign responsibility across business, technology, security, legal and risk teams, ensuring every system has identifiable oversight.
Defined decision boundaries and escalation paths should determine which activities an AI system can execute independently and which require escalation. For high-impact decisions, human review checkpoints should remain mandatory, particularly where financial, regulatory, customer or operational consequences are involved.
Effective continuous monitoring and audit trails should capture system activity, decisions, tool interactions and exceptions, allowing organisations to investigate incidents and demonstrate accountability. At the same time, data access controls and permission limits should restrict autonomous systems to the information, applications and privileges necessary for their approved functions.
Governance must also account for failure. Incident response and rollback procedures should allow organisations to suspend systems, revoke access, and contain and/or reverse harmful actions when required. For externally developed models and platforms, vendor and third-party risk assessment should examine data handling, security responsibilities, model changes, incident reporting and audit provisions.
Finally, regular testing against real-world operating scenarios should be embedded into the AI lifecycle. Simulations, adversarial testing and controlled deployment can identify unexpected behaviour before systems receive broader authority. Together, these controls create an accountable framework for scaling autonomous capabilities without allowing operational autonomy to outpace organisational oversight.
Responsible AI adoption requires more than just policies stored in compliance documents. Business leaders, developers, security teams, legal specialists and employees who interact with autonomous systems need clearly defined responsibilities.
Organisations should maintain an inventory of AI systems, classify them according to potential impact and periodically reassess their risk. Training should cover appropriate use, escalation procedures, data handling and recognising abnormal AI behaviour.
Executive oversight is equally important. Boards and C-suite leaders should receive meaningful reporting on AI incidents, exceptions, performance, access rights and unresolved risks. This creates a governance structure where accountability remains with people even when systems perform tasks autonomously.
The Indonesian government’s current AI policy work signals increasing attention to ethical, transparent and accountable AI deployment. In August 2026, Indonesia’s Ministry of Communication and Digital Affairs (KOMDIGI) specifically highlighted the governance challenge created when AI systems begin actively planning, deciding and executing actions.
For organisations adopting autonomous systems, the practical priority is to align enterprise controls with evolving national requirements. This reflects the growing need to balance innovation with robust governance, transparency and measurable accountability.
As autonomous and agentic AI systems increasingly move into enterprise operations, organisations in Indonesia will need governance frameworks that enable innovation while maintaining clear accountability, security and human oversight. Establishing defined decision boundaries, access controls and effective intervention mechanisms will be essential to scaling autonomous capabilities responsibly.
These priorities will be explored at digitalCIO 2026, taking place on 11 November 2026 at The Ritz-Carlton Jakarta, Pacific Place. The summit is expected to bring together over 350 pre-qualified delegates from more than 150 organisations, alongside 40+ thought leaders and 30+ solution providers, creating a platform for technology leaders, government representatives and industry experts to examine the opportunities, risks and governance requirements shaping enterprise AI adoption in Indonesia.
Registrations are open. Visit https://www.digitalciosummit.com/ for more information.
1. What governance controls should enterprises establish first?
Start with ownership, decision boundaries, access permissions, human approval requirements, monitoring, incident response and documented accountability.
2. Why does autonomous AI require stronger oversight?
Autonomous systems can execute actions across connected environments, increasing the potential impact of errors, unauthorised access or unexpected behaviour.
3. How can companies support Responsible AI adoption?
Companies should combine employee training, risk classification, testing, monitoring, transparent documentation and executive oversight throughout the AI lifecycle.
4. What role does AI governance play in cybersecurity?
AI governance defines access rights, monitoring requirements, escalation procedures and controls that reduce risks created by autonomous system activity.
5. Why is testing important before enterprise deployment?
Testing can identify unexpected behaviours, security weaknesses and operational failures before an autonomous system receives broader permissions.