AI agents introduce a regulatory gap
SOX, FDA, GxP, and internal audit processes were built around people following approved workflows. They were not designed for agents that can move through ERP screens, change records, route approvals, or trigger downstream financial and operational effects.
The gap is not just permissioning. Teams need to know which workflows are safe to automate, what evidence proves those workflows still behave correctly, and how they will explain agent-driven actions when regulation and auditors catch up.