
Meet the Authors
Start capturing signed, replayable records of agent actions now; the 18-to-24-month evidence build time is a hard constraint for any 2028 autonomy decision or December 2027 EU AI Act audit.
Pair the SAP AI Agent Hub's inventory and lifecycle controls with a tamper-evident track record so promotion and demotion decisions rest on data, not committee sentiment.
Prove value in one high-volume process first: baseline review load and cycle time over 90 days, then release autonomy task class by task class.
At SAP Sapphire 2026, SAP put numbers behind the Autonomous Enterprise: 224 agents and 51 assistants spanning finance, spend, supply chain, HCM, and customer experience, with bi-directional Agent-to-Agent capabilities due in Q4. It also delivered the SAP AI Agent Hub inside SAP LeanIX at no additional charge, a vendor-agnostic inventory that discovers agents, records risk ratings, and governs their lifecycle until decommissioning.
Capability, therefore, is no longer the constraint. A recent AiFA Labs analysis of the post-Sapphire landscape names permission as the real challenge. Industry data puts human-in-the-loop adoption at near 78% of consequential AI output, which means most of the speed and savings agents promise sit in a review queue. Organizations supervise everything because they have no measured basis for deciding which agents have earned the right to act alone. The uncomfortable corollary is that this basis takes 18 to 24 months to build and cannot be reconstructed after the fact. Thus, the timing question is not whether to build trust infrastructure, but how much of the runway has already been spent.
The Caution Is Rational. The Delay Is Not.
SAPinsider’s June 2026 research shows nearly three-quarters (74%) of organizations report AI-enabled SAP use cases still in identification, experimentation, or no-plans phases, and 43% are not using AI in SAP-related processes at all. Accuracy and reliability of AI outputs in critical processes is the top concern at 63%, with data leakage through AI services and regulatory compliance both at 59%. When asked about the single most important security control for AI on SAP data, 49% chose role-based access aligned with SAP authorizations.
These statistics describe a community that treats agents the way it treats any new hire with system access: on probation until proven. The problem is that probation ends only when there is a record to review, and most organizations are not keeping one.
SAPinsider’s AI Adoption and Maturity report found that while many have foundational governance such as data privacy controls and model documentation, only a small segment describes governance as fully operationalized or automated across the AI lifecycle. The organizations it classifies as AI Leaders differ here: they treat governance as an enabler and report stronger gains in automation, risk and compliance management, and profitability.
What Earned Autonomy Requires
The AiFA Labs analysis frames unsupervised operation as a promotion grounded in evidence. It indicates that three elements complete what the Agent Hub begins:
- A measured track record: Every action captured as a signed, replayable record of intent, data used, model version, human edit, sign-off, and result. In this case, trust stops being a feeling and becomes a number an enterprise architect can defend.
- A clear mandate: Who authorized the agent, for what scope, with what limit, until when, readable in one line and revocable in one click. This is the delegation discipline organizations are already asking for when they insist agents inherit SAP authorizations.
- A place to rehearse: This is where a consequential change runs against a realistic copy of the environment before it touches production.
With those three factors in place, autonomy can be granted per task class on a graduated ladder, from supervised to spot-checked to autonomous, and withdrawn the moment performance slips automatically. A durable share of consequential work will stay under human review indefinitely, the AiFA Labs analysis states. The objective is not to remove people but to spend their attention where it changes the outcome.
Why the Foundation Compounds
The AiFA Labs analysis builds an argument for starting now. It notes that a license to operate backed by 10,000 logged runs is worth more than one backed by 100, and that history accrues one day at a time. An organization that begins capturing evidence in 2026 will have agents graduating to autonomy on a schedule it controls by 2028. However, one that starts in 2027 will still be running supervised pilots while competitors run whole categories of work hands-free.
The same record serves a second purpose. The EU AI Act’s Article 12 record-keeping and Article 14 human oversight obligations for high-risk systems take effect on December 2, 2027, the same month SAP ECC maintenance ends. Agents operating in finance, HR, and procurement fall squarely within that scope, and an evidence trail built to release trapped productivity satisfies those requirements almost as a byproduct. However, one built in a hurry for the auditor will be neither complete nor trusted.
What This Means for SAPinsiders
Start the counters now, not at the governance review. CIOs should treat the 18-to-24-month build time as a hard constraint. That is because evidence not captured today cannot support an autonomy decision in 2028 or an audit in December 2027.
Use the Agent Hub as the directory, and add the track record. Enterprise architects should pair the Hub’s inventory and lifecycle controls with signed, tamper-evident records of agent actions, so promotion and demotion decisions rest on data rather than committee sentiment.
Prove value from one process before scaling. ERP program managers should pick a single high-volume process, baseline review load and cycle time over 90 days, then release autonomy task class by task class, so the ROI comes from the organization’s own records rather than a vendor slide.




