There’s no question that using agents is worthwhile. The crucial factor, however, is whether a company determines for itself how it works with its agents. Peter de Lorenzi, Executive Director Horizontals, Platforms & Services at adesso SE and an expert in digital sovereignty, outlines what’s important when building sovereign agent systems.
1. Digital Sovereignty Is Taking on a New Dimension
For a long time, discussions of digital sovereignty focused primarily on data locations and access rights. Recent developments in leading AI models in the US and China have added a second layer: access to the model itself is becoming a political variable. A data centre in Frankfurt or Berlin can appear more secure than it actually is. Ultimately, what matters is who determines access to the model. This reveals how much control a company retains over its own value creation – often without the company realising it at the moment the decision is made.
2. Deciding Who Is Accountable for the Agent
An agent that accesses systems or initiates processes is acting on behalf of the company. Guidelines alone cannot regulate this. Companies need role- and authorisation-based frameworks that show which agent acted with what authority and who remains accountable for it, even months later. Only with this attribution can a company intervene and rectify the situation if any doubt arises. Without it, responsibility remains dependent on the agent’s logic, regardless of how well this works in individual cases.
3. Shorter Cycles Require More Frequent Evaluation
This pattern is most evident in software development. When agents prepare designs, tests and documentation, entire development cycles often shrink from weeks to just a few days. However, the task of evaluating every proposal does not disappear as a result; it simply becomes more frequent. This ability to evaluate is the real bottleneck. Anyone who, over a prolonged period, merely approves proposals instead of examining the solutions thoroughly for themselves will gradually lose the ability to assess whether a result is genuinely sound or merely appears convincing. It is precisely at such critical moments that they end up relying on the agent’s judgement.
4. Freedom of Choice Must Be Factored Into Planning From the Outset
Multi-model capability is almost impossible to retrofit if a provider suddenly restricts access. It must therefore be integrated into the architecture from the outset, for example, via abstraction layers that orchestrate agents independently of the specific model. Dependency rarely arises from a single, clearly identifiable step. It grows through prompts tailored to a specific model or through workflows that run on a single platform. This development remains invisible in the architectural diagrams, but as soon as conditions change, it becomes very real.
5. Governance Makes Scaling Possible in the First Place
At first glance, clear authorisation models, defined approval processes for critical actions and traceable logging may seem like an additional burden. In fact, they determine whether companies can deploy agents in truly critical processes. A robust classification is essential here: not every use case requires the same level of control, but each must be deliberately categorised before an agent goes live. Only in this way can a company properly intervene, correct or halt operations in an emergency.