How much should an AI agent be allowed to decide on its own?

AI agents do more than generate text: they take action. They bring together information from different systems and trigger actions. As the potential benefits grow, so does the responsibility. How can companies integrate an AI agent into a business process? And how can they stay in control when many AI agents built on different models and technologies come together? Tino Mager from Telekom MMS and Sven Giesselbach from T-Systems explain what matters.

Graphic showing people manually coordinating workflows
The T-AI Agent Platform automates clearly defined business processes. The T-AI Agentic Hub coordinates entire agent landscapes—from fixed workflows to agents that independently plan and distribute tasks. © Deutsche Telekom AG

What changes when AI no longer just responds, but takes action?

Tino Mager, AI Expert and Cloud Solution Architect, Deutsche Telekom MMS : AI is becoming the new colleague. Take logistics, for example. A driver photographs a delivery document. The AI agent reads the information, checks the address and completeness, transfers the data into the ERP system, and triggers the next step in the process. The case no longer moves from desk to desk for manual data entry. Employees can focus on unclear or incorrect cases.

AI has arrived in companies: According to Eurostat, one in five EU companies with at least ten employees was already using artificial intelligence in 2025. Bitkom reports current figures for Germany: 41 percent of companies with at least 20 employees now use AI, while another 48 percent are planning or discussing its use. The experimentation phase is coming to an end. AI now has to demonstrate the concrete value it can deliver for processes, employees, and customers. In the study “The ROI Compass for AI in the Mittelstand” Telekom MMS and mind digital collected data and insights from 100 frontrunners on AI maturity, investment rationale, and measurable results.

Sven Giesselbach, CTO AI & Data T-Systems International: The next stage of development in companies is the move toward AI agents that independently handle clearly defined tasks. The study found that 91 percent of the frontrunners surveyed use knowledge assistants, and 83 percent use automated document generation and text processing.

AI agents also bring a new level of responsibility. An inaccurate chatbot response is annoying. But if an AI agent is used in manufacturing, logistics, energy, or transportation, an error can stop a production line, delay a shipment, or create a safety risk. It becomes critical if an AI agent triggers an order without proper controls, changes master data, or accesses sensitive information. The benchmark for AI agents should therefore not be what is technically possible, but the concrete value they create at a manageable level of risk.

Deutsche Telekom is launching two offerings: the T-AI Agent Platform and the T-AI Agentic Hub. What’s the rationale behind having two different platforms?

Tino Mager: Because companies start from different points. Many mid-sized businesses have one immediate problem they want to fix: too many manual emails, recurring service requests, or employees moving data from one system to another by hand. They want to start with a clearly defined process, see results quickly, and build from there. They can use a preconfigured agent, adapt existing workflows themselves, or work with us to develop a custom agent — all with predictable package pricing.

Sven Giesselbach: In organizations where more and more processes are being handled by AI agents, those agents are often developed independently across different business units. One may be built on n8n, another on LangGraph, CrewAI, or AutoGen. They do not necessarily “understand” one another, they may use different language models, and they operate with different levels of autonomy. The T-AI Agentic Hub brings together AI agents from different vendors and technology frameworks on a shared operating platform. It serves as the central control point for compliance and cost management. It is the operating system for AI agents.

Tino Mager: In simple terms, the T-AI Agent Platform automates clearly defined business processes. The T-AI Agentic Hub coordinates entire agent environments — from fixed workflows to agents that plan and delegate tasks on their own. The T-AI Agent Platform executes the processes; the T-AI Agentic Hub keeps the interaction under control. The difference therefore lies less in the technology itself than in the level of complexity, risk, and organizational starting point.

What specific problem does the T-AI Agent Platform solve for a company?

Tino Mager: In practice, companies often struggle to turn an idea into a working business process. Which task is taking up time today? Which process can be automated reliably?

The T-AI Agent Platform combines n8n-based workflow automation with AI models and capabilities such as voice and IT security. It offers standard agents, an agent builder, and custom agents. Using n8n’s graphical interface, for example, prebuilt workflow templates can be adapted to a company’s existing email, CRM, or ERP systems. Operations, security, user and access management, lifecycle management, monitoring, billing, and support are all part of the platform. Telekom MMS supports customers in selecting the right process and integrating the solution into their existing IT environment.

A good first AI agent has a clearly defined task. Its results can be verified. And the company can see whether it reduces effort, processing time, or errors.

When do companies need to move beyond a single workflow solution?

Sven Giesselbach: An AI agent in customer service can usually still be assigned clearly to one process and one team. The situation changes when AI agents are also operating in IT, financial analysis and risk management, or supply chain processes, while accessing different data sources and enterprise systems.

As agents gain more autonomy, identity, access rights, traceability, cybersecurity, and human approval need to be built in from the start. Control cannot be added as an afterthought. Only then can the use of AI agents be expanded reliably.

In addition, when AI agents plan tasks on their own, delegate subtasks, and collaborate with other agents or systems, companies need to rethink their processes: Which reusable building blocks can be used across processes? How much autonomy makes sense, and where is a fixed workflow the better fit? The T-AI Agentic Hub provides a common framework for both approaches. It connects agents across system boundaries, shows which model each AI agent uses, which systems it can access, and what actions it has taken. Data remains in the source systems, with access provided through controlled interfaces. Activities remain traceable and testable, while role- and rights-based controls govern what agents are allowed to do. Cost limits can also be set for specific users or models.

Different models? Does that mean companies need a separate contract for each AI model?

Sven Giesselbach: No. Among others, the T-AI Agentic Hub uses the AI Foundation Services, T-Systems’ marketplace for AI. This gives companies access to a wide range of AI models through a single provider, one technical interface, and consolidated billing — instead of separate contracts and integrations with each model vendor. Usage is billed based on consumption.

Tino Mager: The T-AI Agent Platform also connects to AI Foundation Services. The practical benefit is choice. Companies can select the model that best fits each task in terms of speed, cost, quality, or security requirements.

Sven Giesselbach: You’re touching on sovereignty here, Tino. That freedom of choice is an important part of it. In June, for example, the U.S. government temporarily required AI company Anthropic to restrict access to its latest models for users outside the United States. A survey by the ifo Institute shows that almost nine in ten German companies use digital products from U.S. providers, and 31 percent consider themselves highly dependent on them. Sovereignty means knowing where those dependencies lie, having alternatives, and being able to switch or intervene when necessary.

Not every model has to come from Germany. Models differ in performance, pricing, and levels of sovereignty. Companies can specify where models are run — for example, in their own IT environment, on sovereign infrastructure such as the T Cloud, or with a hyperscaler. Based on the level of protection the data requires, the T-AI Agentic Hub determines which environments are permitted under the company’s policies. This allows different models, including a company’s own models, to be combined within a single agent system based on data protection requirements, cost, and performance. The T-AI Agent Hub can be adapted to the operational and sovereignty requirements of large enterprises and public-sector organizations.

On sovereignty: IT and compliance want control, while business units want fast results. How should companies balance the two?

Tino Mager: If you focus only on speed, you risk ending up with a pilot that works but cannot be scaled later. If you treat every first use case like an enterprise-wide high-risk application, you prevent teams from gaining practical experience.

I like to explain it through a focused use case, ideally one built around recurring patterns. That makes it possible to define success criteria, interfaces, and rules up front. Companies can then gain experience quickly without postponing the necessary governance framework. Many AI projects get stuck because these prerequisites are addressed too late.

Sven Giesselbach: Governance should not be seen as an obstacle. Done properly, it is what makes scaling possible. As long as a pilot is handled by a small team, many questions can still be resolved manually. Once dozens of AI agents are operating across different parts of the organization, that no longer works. Each AI agent then needs a clear identity, defined access rights, logged actions, and boundaries it cannot cross.

The goal is not to impose as much control as possible at every point. It is to apply the right level of control to each action.

Who is responsible when an AI agent makes a mistake?

Sven Giesselbach: Responsibility cannot be delegated to the AI agent. The company using it must decide which tasks may be automated and what controls are required.

That means putting several layers of protection in place. In the T-AI Agentic Hub, AI agents can be tested by people before they are released, with security and compliance requirements built into the process. The T-AI Agentic Hub assesses agent actions based on their level of risk and determines when human intervention is required. Particularly critical actions can be configured to always require human approval. Cost and usage limits can also be set.

Tino Mager: What matters is how the specific process is designed. An AI agent can, for example, prepare a decision that is then confirmed by a person. For a low-risk routine task, the AI agent may be able to complete the process on its own. The question should not be whether AI agents are allowed to act autonomously in general, but how much autonomy is appropriate in each individual process.

What should companies decide now?

Tino Mager: Companies should start with the use case, not the technology: Where does unnecessary manual work still tie up time and resources, and can the benefits of automation be measured? There is no single path every company has to follow. Some start with one business process, while others need centralized control from the outset because of their complexity or regulatory requirements. The two offerings are not mutually exclusive. Workflows from the platform can be integrated into a larger hub environment.

Sven Giesselbach: And companies should decide early on what level of control each use case requires: What decisions is the AI agent allowed to make? Which data and systems may it access? What infrastructure should be used to run the agent? And when does a person need to step in?

Tino Mager: The success of a company will not be determined by having the most powerful AI. What matters is whether it can turn AI into real business value, scale it securely, and govern it responsibly.