Assurance is an accelerator, not a brake.
With the evolution of agentic artificial intelligence, businesses have the opportunity to reimagine everything they do. As they move from pilots to large-scale adoption, autonomous agents are helping to generate revenue, save time and money and transform the customer and client experience.
The potential benefit is enormous, but, as with any new technology, it also brings new risks, from bias and data privacy to sophisticated cyber threats. Evolving regulations are also adding to a complex landscape.
To help our clients navigate this new territory, our Audit & Assurance (A&A) experts are measuring and evaluating the trustworthiness of AI use cases, as well as focusing on AI governance, controls, infrastructure and regulatory compliance. Good governance and focused controls do not slow progress. They enable businesses to deploy, scale and commercialise AI faster while also understanding how to manage the risks to their businesses.
As AI introduces new opportunities and risks into enterprises, control and risk management frameworks must mature and develop accordingly. Deloitte’s State of AI in the Enterprise Survey 2026 shows that 23% of organisations are already using agentic AI, while 74% expect to adopt it in the next two years.
But investment in controls is lagging spend on innovation. Only 21% have mature governance models for agent oversight. Meanwhile, 69% don’t consider themselves highly prepared to deal with the risk management and governance challenges the technology brings.
Businesses further ahead on the AI maturity curve are thinking about the evolution of their trustworthy AI frameworks. As their ambition increases, AI becomes a part of more important businesses’ processes, and their number of use cases grows.
“AI assurance isn’t just a risk exercise; it’s a growth enabler,” says managing partner for Audit & Assurance, Allee Bonnard. “By building trust in AI from the outset, organisations can drive innovation and strengthen confidence.”
The UK government has positioned third-party assurance as vital to the country’s AI transformation.
Unlike in the EU and other countries, there are currently no specific AI laws or regulations in the UK, but principles-based rules are being layered on to sector-specific requirements. Provision 29 of the 2024 UK Corporate Governance Code also requires boards to declare the effectiveness of their material internal controls, which encompasses AI.
All this is now making it a business imperative to understand the governance and assurance that needs to be established, commensurate to the firm’s AI strategy, including the impact of existing laws and regulations, and ensure there is appropriate AI literacy across the organisation.
Mark Cankett, AI Assurance partner at Deloitte UK, says: “If you get the governance and control around AI right, and everybody knows what they need to do to push fantastic AI tools out into the business, companies can transform faster.”
"Good governance and focused controls enable businesses to deploy, scale and commercialise AI faster while also understanding how to manage the risks to their businesses."
Deloitte A&A is breaking new ground in this area.
The AI Assurance team combines specialist governance and control, regulatory, data science, security, cyber and digital skills. It also draws on Deloitte’s expertise in other areas, including auditing and consulting.
Our Trustworthy AI framework guides our approach and focuses on critical dimensions that support trustworthy AI processes. We’re helping clients with all aspects of their AI transformation, from decision-making to platform infrastructure. And that’s essential for boards, employees, investors and consumers.
Deloitte assurance is focused on where it matters most: high-impact AI. As the landscape evolves, we are monitoring emerging rules and trends, so our clients can be confident they’re in step with evolving good practice.
“If your organisation has ambitious plans, the first thing you need to understand is where you’re using AI and what the risk is,” says AI Assurance partner, Richard Tedder. “Then, you have to decide on the appropriate response, which will vary depending on your organisation and your risk appetite. There is no right answer, but having a timely conversation is important.”
As the UK’s AI transformation gathers pace, and AI plays a more prominent role in critical business processes, confidence in its trustworthiness will be increasingly important for success.