Leadership1 publisher3 min readPublished
EY's chief data officer calls for AI-ready data governance as agents take on more autonomous tasks
Richard Clough says enterprise data rules were written on the assumption that a human makes the final call, and the survey number he brings to size the problem counts people who let AI shop and bank for them.
The Board Room · Leadership desk

What happened
- Richard Clough, EY's global chief data officer, wrote in a Forbes Tech Council post that enterprise data rules have rested throughout their life on the assumption that a human would make the final call.
- In what the post calls Pioneer Markets, nearly a quarter of people report having used autonomous AI.
- His first prescription is that data access policies specify not just who can reach a dataset but which decisions that data can legitimately be used to support.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint A framework that certifies human decisions cannot answer for an agent's, so an incident review may find no record of what the agent drew on unless the tooling was put in first.
- decision The permissions review belongs before deployment in a given area, which puts a policy exercise ahead of the next agent pilot in the queue.
- cost A real-time record of every source an agent touches is engineering work on each agent, and the team shipping the agent pays for it.
- exposure A board citing the 16% figure as a read on its own agent exposure is quoting a household measure, because no enterprise count appears in this record.
EY's number and EY's argument are about different populations. The research found that 16% of people globally report delegating to AI systems that act on their behalf without human intervention [5]. The behaviours underneath it are household ones: 11% have let AI carry out banking and financial tasks without their direct input, 11% allow AI to automatically manage purchases and refill shopping carts, 10% have used an AI agent to buy products for them, and 9% have travelled in a self-driving vehicle [6][7][8][9]. None of those quantities counts a company letting an agent approve a transaction [24]. The largest single behaviour is about two thirds of the headline, 11 divided by 16 [20].
In Pioneer Markets, nearly a quarter of people report having used autonomous AI [10]. Set against the global 16%, that is roughly half again as high [21].
Clough lists what agents are already doing inside enterprises: drafting communications, updating customer records, approving routine transactions and generating reports that reach external audiences, often without a human reviewing [3]. He does not say how many organizations have those agents in production [24].
The mechanism he describes does not depend on the survey. Most access rules answer one question, whether a person, role or system can access a dataset [11]. A dataset a customer service team may legitimately open is not, for that reason, one an agent should use to make automated decisions about account status or credit terms [12]. Clough wrote that governance frameworks are "exposed as insufficient, not because the old rules are wrong, but because they were written at a time when the primary user of enterprise data was a person" [16]. He allows that agents can be designed to flag uncertainty, pause before acting on ambiguous data or escalate to a human when confidence is low, and says that requires deliberate governance choices most organizations have not yet made [22].
Clough is EY's Global Chief Data Officer and his stated remit is mobilizing the AI Ready Data Strategy and AI Ready Data Governance [1], and the argument ran as a Forbes Tech Council contributor post [23]. His two instructions can be tested in-house cheaply: ask whether current access policies specify what decisions data can legitimately support, and add that clarity "before agents are deployed in that area" [13]; and require any agent to maintain a real-time record of the data sources it uses before deployment, a record he says "does not need to be complex, but it does need to exist" [14][15].
The second instruction is the harder one, because it is a build requirement and not a policy edit. Most organizations can establish after the fact where a piece of data came from, and what they typically cannot do is say whether the data it drew on was current and reliable [18].
This argument has a long-term implication and an immediate one. The long-term implication is that the primary user of enterprise data stops being a person and the certification apparatus built around that user has to be rewritten [2]. The immediate implication is narrower: for each area where an agent is proposed, establish whether the access rules name permitted decisions, and hold the deployment until they do [13]. Clough wrote that "For organizations that want to move fast with AI without accumulating risk, the governance question is not one that can wait" [17]. On the evidence in his own post, the policy review is what cannot wait. The 16% figure is a household figure. It does not tell a board how many agents inside its own company are already acting outside the framework [5][24].
What to watch
- Whether EY or anyone else publishes a count of enterprise agents holding approval authority inside companies, which is the measure the governance case currently lacks.
- Whether EY defines Pioneer Markets and publishes the sample behind the 16% delegation figure.
- Whether auditors start asking for an agent's real-time record of data sources as evidence when a decision is challenged.