Skip to main content
AI GovernanceMicrosoft 365CybersecurityComplianceLos Angeles

Rolling Out AI Agents in 2026: A Governance Checklist for LA Businesses

· By Ashkaan Hassan

The Decision You’re Actually Making

Every week, another vendor tells you their AI agent will read your email, search your files, draft your documents, and update your systems. Your team is already pasting client material into consumer chatbots whether you approved it or not. And somewhere in the middle sits the real question you have to answer as an owner or IT decision-maker: do we point AI at our actual business data, and if so, what has to be true first?

The honest answer is that the AI decision is not an AI decision. It is a permissions decision, an identity decision, and a records decision — three things most small and midsize firms have been quietly deferring for a decade. AI agents do not create those problems. They expose them at machine speed, to every employee, all at once.

This post is the checklist we walk clients through before enabling agent access to a tenant. It assumes a Microsoft 365 environment (the most common case for Los Angeles professional-services firms), but the governance logic applies to Google Workspace, Slack, and standalone AI platforms equally.

What Changed Going Into 2026

Three things shifted, and together they turn “we’ll figure out AI governance later” into a compliance exposure.

California now regulates automated decision-making directly. The California Privacy Protection Agency’s finalized regulations on automated decision-making technology (ADMT), risk assessments, and cybersecurity audits took effect at the start of 2026, with businesses required to comply with the ADMT obligations by January 1, 2027, and to submit their first risk-assessment attestation by April 1, 2028. If you use AI to help make significant decisions about hiring, promotion, compensation, or access to services, you now owe consumers notice and — in defined cases — the ability to opt out and to request an explanation. “The vendor’s model did it” is not a defense.

You can now diligence AI vendors on their training data. California’s AB 2013 requires developers of generative AI systems made available to Californians to publicly post documentation about the datasets used to train them, covering systems released on or after January 1, 2022. That gives buyers a concrete diligence artifact to ask for instead of accepting marketing claims.

Agents got identities. The industry moved from “AI as a feature inside an app” to “AI as a non-human identity that holds credentials, calls APIs, and takes action.” That is a fundamentally different security object, and most firms have no process for creating, reviewing, or retiring one.

The Oversharing Problem, Explained Plainly

Here is the mechanic that catches firms off guard. An AI assistant grounded in your tenant does not grant new access — it honors the permissions each user already has. That sounds reassuring until you remember how those permissions accumulated: a SharePoint site shared with “Everyone except external users” in 2019, an “anyone with the link” file sent to a contractor, a Teams channel that became a de facto company drive, an ex-partner’s OneDrive nobody ever cleaned up.

Before AI, that latent overexposure was protected by obscurity. Nobody browsed to a forgotten site to find the partner compensation spreadsheet. Now an employee types a plain-English question and a retrieval engine surfaces it in seconds, with a citation. Microsoft publishes an entire deployment blueprint dedicated to remediating oversharing before Copilot rollout — which tells you how routinely this bites.

The stakes are not theoretical. IBM’s 2025 breach research found that 13% of organizations reported breaches involving AI models or applications, and 97% of those lacked proper AI access controls, against a United States average breach cost of $10.22 million — the highest of any region in the study. Access control is the entire ballgame.

Four Paths, Compared

Most firms think the choice is “AI or no AI.” In practice there are four postures, and you are already in one of them whether you chose it or not.

ConsiderationBlock AI outrightUnmanaged consumer AI (shadow AI)Vendor AI inside your tenantCustom agents with system access
Who controls the data pathYou, nominallyNobodyYour tenant adminYour admins plus each connector’s owner
Visibility into what staff askNoneNoneFull audit trail availableFull, if logging is configured at build time
DLP and sensitivity labels enforcedN/ANoYes, if labels actually existOnly where you scope them
Exposure from bad permissionsLowModerate (copy/paste leakage)High until remediatedHigh and persistent
Discoverability for litigationN/APoor — data sits outside your controlInteractions retained and searchableDepends on architecture
Governance burden on youLowLow, until the incidentModerate and front-loadedOngoing, per agent
Realistic business upsideNoneUneven, unverifiableBroad and measurableHighest, on narrow workflows

The worst square on this table is column two — and it is where most firms currently live. Blocking AI does not produce column one; it produces shadow AI on personal devices with zero logging. Choosing deliberately is the entire point.

The Pre-Flight Checklist

Do these before you enable a single license. In our experience this is four to eight weeks of unglamorous work for a typical professional-services firm, and it is the difference between a rollout and an incident.

Inventory and fix permissions first. Run a data access governance report across SharePoint and OneDrive. Hunt specifically for sites shared with “Everyone except external users,” org-wide sharing links, orphaned sites with no active owner, and Teams created for matters that closed years ago. Set an expiration on anonymous links and change the default sharing scope from “anyone” to “specific people.”

Use search restriction as a tourniquet, not a cure. Microsoft’s Restricted SharePoint Search lets you limit AI grounding to a curated allow-list, but it is capped at 100 SharePoint sites and explicitly intended as a temporary measure while you remediate. Treat it as scaffolding with a removal date, not architecture.

Deploy sensitivity labels that actually encrypt. Labels are what let an AI assistant respect confidentiality boundaries and what carry protection forward onto AI-generated output. A label taxonomy nobody applies is worse than none — it creates the paperwork of governance without the effect. Start with three or four labels tied to how your firm really works: client-confidential, internal, restricted (deal or matter specific), and public.

Turn on AI-specific monitoring before day one. You want to see which staff are sending data to which AI services, including third-party sites, and you want prompts and responses retained under your existing retention and eDiscovery policy. Retrofitting this after a dispute arises is not possible.

Harden the identities that can invoke agents. Phishing-resistant MFA and conditional access on every account with agent access. An AI assistant meaningfully increases the blast radius of a single compromised login, because the attacker no longer has to know where anything is — they can just ask.

Write an acceptable-use policy with teeth. Name the approved tools. Name the data classes that may never be entered into any AI system (client PII, unreleased production material, privileged communications, source code under NDA). Require human review before AI output goes to a client, a court, or a counterparty. Put it in the handbook and train against it.

Govern Agents Like You Govern Employees

The framing that works: an agent is a new hire with perfect recall, no judgment, and no exit interview.

Every agent needs an owner of record — a named human accountable for what it touches. Every agent needs the narrowest possible scope; if it only needs to read one document library, it does not get tenant-wide access. Every agent needs a review cadence, because permissions drift and connectors accumulate.

And critically, every agent needs an offboarding path. When an employee leaves, you disable their account — but the agent they built in a low-code tool may still hold an authenticated connection to a CRM, a billing system, or a shared mailbox. Add “enumerate and reassign or delete agents owned by this user” to your termination checklist today, before you have to reconstruct it under pressure.

For the governance layer itself, do not invent a framework. Map your program to the NIST AI Risk Management Framework, which organizes the work into four functions — Govern, Map, Measure, and Manage. If clients or insurers are asking for evidence of formal oversight, ISO/IEC 42001 provides a certifiable AI management system standard that slots alongside the SOC 2 work many firms have already done.

What LA Professional-Services and Entertainment Firms Get Wrong

Southern California adds specific wrinkles that generic AI-governance advice ignores.

Client confidentiality is not the same as data privacy. Law firms owe duties of competence and confidentiality that survive any vendor’s security certification. Before an AI tool touches matter files, confirm the engagement letters and outside counsel guidelines permit it — a growing number of corporate clients now require advance written notice or outright consent for AI use on their matters.

Entertainment work carries contractual security obligations. Studio and platform vendor agreements frequently impose content-security requirements that predate AI and were never drafted with it in mind. Uploading unreleased material, scripts, or cuts into any AI system — including one inside your own tenant — can breach a security addendum even when no leak occurs. Read the addendum before you read the AI vendor’s marketing page.

Multi-office and hybrid teams break tenant assumptions. LA firms with staff spread from Century City to the Valley to a remote colorist in Atlanta often have inconsistent device management. Agent access granted to an unmanaged personal laptop is agent access granted to whatever else is on that laptop.

California-specific privacy duties compound. If you are already handling CCPA obligations, the ADMT rules described above layer on top rather than replacing them. Your risk assessment obligation attaches to the processing activity, not to the tool.

A Phased Rollout That Doesn’t Stall

The failure mode we see most is not a breach — it is a pilot that never ends. Structure it to conclude.

Phase one: remediate and instrument. Permissions cleanup, labels, monitoring, conditional access, acceptable-use policy. No end users yet. Success criterion: you can answer “who can see this file” for any file, in minutes.

Phase two: a narrow, measured pilot. Pick one department and one or two workflows with a measurable before-state — intake summarization, document review triage, meeting-notes-to-action-items, invoice coding. Baseline the time those tasks take now. Give the pilot group real training, not a login email.

Phase three: decide with evidence. Compare against the baseline. Expand where the numbers hold, cut where they don’t, and document both. This is also where you decide whether general-purpose assistants are enough or whether a purpose-built agent on one high-volume workflow is worth the ongoing governance overhead.

Phase four: operationalize. Quarterly access reviews, agent inventory, policy refresh, and a named owner for the program. AI governance is a standing process, not a project with a completion date.

How to Tell Whether Your IT Provider’s “AI” Is Real

Every managed services provider in the country now claims to be AI-native. Some are. Here is how to separate them in a single meeting.

Ask them to show you a permissions remediation report from a real client engagement, with the client details redacted. Ask what their process is for retiring an agent when its owner leaves the company. Ask how they log and retain AI interactions for eDiscovery. Ask which specific manual workflow in your business they would automate first, and how they would measure whether it worked. Ask what they would refuse to connect an agent to, and why.

A provider that answers those five questions concretely is doing the work. A provider that answers with product names and partner badges is reselling. The distinction matters more here than in any other part of your IT stack, because the failure mode of bad AI governance is not downtime you can see — it is quiet, cumulative exposure you discover from someone else.

We Solve Problems runs both sides of this problem for our clients: the managed IT and security foundation that makes AI safe to turn on, and the AI operations work of finding the manual workflows actually worth automating. We’re based in Los Angeles, we work with clients across the US, and we have particular depth with entertainment-law and professional-services firms where confidentiality obligations leave no room for a sloppy rollout. If you want a clear-eyed read on whether your tenant is ready for AI agents — and a sequenced plan to get there — start a conversation with us.