Workday’s Vision for Governing AI in The Enterprise
AI agents are entering the enterprise faster than policy can keep up. We’re sharing Workday's proposed safeguards policymakers can act on today.
AI agents are entering the enterprise faster than policy can keep up. We’re sharing Workday's proposed safeguards policymakers can act on today.
In this article we discuss:
Today, we're sharing Workday's Vision for AI Governance, a policy framework for AI safeguards in the enterprise that builds trust without slowing innovation.
In recent years, policymakers have devoted significant attention to AI safety issues emerging from the rapidly advancing capabilities of frontier AI models. Meanwhile, enterprise AI adoption is accelerating, increasing productivity, improving decisions, and freeing time for more strategic work—something we see with our customers every day. These opportunities raise policy questions that demand a response: AI governance focused only at the frontier will not suffice.
Since 2019, Workday has helped lay the groundwork for smart and workable AI safeguards that build the trust necessary for beneficial AI adoption—guided by more than a decade of experience delivering AI innovation in HR and finance, and our enterprise responsible AI framework. The vision we're releasing today builds on that work. It offers a public policy framework for AI systems that make important decisions about people and AI agents taking high-stakes actions in the enterprise.
Realizing AI’s benefits at scale requires trust: organizations, employees, and the public must have confidence that it’s developed and deployed responsibly. That's why our framework takes a risk-based approach and centers on ‘high-impact AI’—systems that make important decisions about people, such as hiring, lending, or healthcare decisions. Focusing here ensures safeguards apply where potential risks are higher, without slowing innovation elsewhere.
Managing these risks is a shared responsibility: developers who design and train AI systems must partner with the deployers who configure and use them in real-world settings. We support five core safeguards that apply to both:
Impact assessments that identify, document, and mitigate risks throughout an AI system’s lifecycle—from design and development through deployment and ongoing monitoring
Internal governance programs with defined responsibilities, escalation paths, and accountable leaders
Meaningful transparency across the value chain and for individuals interacting with AI systems
Human oversight that enables people to understand, review, or override AI outputs
Strong privacy and security protections to safeguard personal data and AI systems
These measures should align with widely recognized definitions, frameworks, and standards like the NIST AI Risk Management Framework, ISO/IEC 4200, and key concepts in the EU AI Act. That alignment strengthens protections while reducing conflicting requirements that slow responsible innovation across borders.
Realizing AI’s benefits at scale requires trust: organizations, employees, and the public must have confidence that it’s developed and deployed responsibly.
AI agents operate on probabilistic, rather than deterministic logic, working across tools and systems to take actions in core enterprise processes. When deployed on top of—or outside—governed enterprise environments, agents become “lawless” because they don’t inherit the permissions, controls, and accountability at the core of deterministic enterprise systems.
At Workday, we believe this is fundamentally a governance issue. We propose five core safeguards to guide policymakers when considering a path forward for agents with authority over key enterprise decisions, like employment, payroll, benefits, and financial approvals:
Persistent identity and authority to ensure every agent has its own non-human identity—credentials distinct from any person’s—plus a designated owner, and documented purpose, scope, and permissions
Rigorous human oversight with clearly defined decision rights and escalation paths—and mechanisms for people to review, approve, override, or stop an agent’s actions
Sensitive data protections that enforce data minimization and least-privilege access to ensure agents use no more information than an authorized task requires
Auditable logs that allow organizations to reconstruct what an agent did, on whose behalf, under what authority, with which systems or tools, and with what level of human involvement
Assurance before deployment against widely recognized standards and frameworks, including independent third-party evaluations for certain agents granted significant discretion over high-stakes decisions
A near-term first step? Policymakers should consider leveraging the National Institute of Science and Technology, including directing NIST to:
Develop a NIST AI RMF Agentic AI Profile that tailors the framework’s core functions—map, measure, manage, and govern—to AI agents.
Develop a standardized assurance schema to support consistent documentation of key agent characteristics like identity, authority, purpose, and access to data and tools.
We strongly urge policymakers to act now, and advance safeguards to drive the development and deployment of trustworthy agents in the enterprise.
We strongly urge policymakers to act now, and advance safeguards to drive the development and deployment of trustworthy agents in the enterprise.
AI technology is advancing more rapidly than ever before, and public policy—at every level of risk—must evolve alongside it. These recommendations reflect Workday’s vision for AI policy that builds trust while accelerating enterprise AI innovation.
Read Workday’s Vision for AI Governance to explore the full recommendations.
More Reading
We're excited to announce that the waitlist for Workday's Open Developer Platform is now open. Here’s what happened when we let any developer build on our platform for the first time.
Workday discovered a better method for telling AI what memories to hold onto—and what to forget—driving 12% higher precision and 8% improved memory quality.
Our new agent automates Workday release prep, making it easier than ever to deploy product updates. Early adopters have already cut time spent on feature rollouts by 50%. Watch a quick demo to see how.