The German economy is at a fundamental crossroads regarding the integration of Artificial Intelligence (AI). Mathias Herrmann, Managing Director of ALLEHERZEN GmbH, explains that AI is no longer merely an innovation topic for large technology corporations. According to current Bitkom studies, 41 per cent of German companies already use AI, while another 48 per cent plan or are discussing its implementation. This means almost every company is engaging with this technology.
However, the next stage of development – agentic AI – differs significantly. AI agents can independently translate goals into action steps, access systems and data, prepare decisions and execute actions. This increasingly transforms a mere tool into an independent actor within business processes. So far, the German economy has shown considerable restraint in this development. The PwC Cloud Business Survey 2025 shows that only seven per cent of surveyed German organisations are developing or scaling agentic AI solutions, while the EMEA average is already 29 per cent.
The PwC AI Performance Study 2026 indicates that German companies have a solid AI starting position but struggle to convert experiments into scalable value creation. Globally, 74 per cent of AI-driven value creation is attributed to just 20 per cent of companies. The central challenge lies not in the question of AI deployment but in the conditions under which systems are increasingly allowed to operate autonomously. This creates a governance gap that can hardly be closed with classical AI guidelines. While a company can stipulate which generative AI services employees may use, this is insufficient if an agent independently accesses customer data, aggregates information, alters processes, and triggers actions.
With increasing system autonomy, control at the beginning and end of a process is no longer sufficient. Companies must be able to ascertain an agent's identity, its access rights to data and systems, possible actions, the necessity of human intervention, and the reconstructability of past processes. These requirements are not just a matter of technical security but also touch upon accountability, data protection, information security, internal controls, and regulatory traceability. The EU AI Act, whose transparency obligations under Article 50 apply from 2 August 2026, illustrates the direction of this development. Depending on the role, system, and risk class, different requirements arise for responsibilities, risk management, human oversight, and technical control mechanisms.
A Deloitte survey among German companies shows the extent of the gap: almost half of the respondents in 2024 had not yet intensively addressed the implementation of the EU AI Act, and only about a third felt well-prepared. More recent data confirm that many companies still lack fundamental elements for scaling AI agents. The challenge becomes particularly clear in complex scenarios involving multiple systems and responsibilities. Classical IT access control, which regulates who may access a system, is insufficient to manage an agent's specific actions within a business context under defined conditions and approvals.
Preventing the general use of AI agents, thereby leaving significant economic potential untapped, is not a solution. A purposeful strategy involves making autonomy controllable. This requires a technical mediation layer between the AI agent and the enterprise systems. Here, access must be checked, actions approved based on defined rules, critical processes escalated to humans if necessary, and all relevant activities traceably documented. The focus is on not having to completely replace existing systems. Instead, governance applies where an agent accesses enterprise systems and intervenes in business processes. Such a 'Governed Access Layer' controls not only which systems and data an agent may use but also which actions it can perform in what context and under which compliance, risk, and approval rules. Critical operations can be forwarded to humans for decision-making.














