In May 2026, six national cyber agencies, including CISA, the NSA and counterparts from the UK, Australia, Canada and New Zealand, published a joint guide on agentic AI. The guidance warned that organizations that aren’t putting proper controls in place before giving autonomous AI systems broad access to sensitive data and critical systems are taking on risk they may not yet understand.  

Around the same time, automation was becoming more visible online. In June, Cloudflare CEO Matthew Prince posted on X that bots had passed human traffic online “for the first time in the Internet’s history.”  

Separately, HUMAN Security’s 2026 State of AI Traffic & Cyberthreat Benchmark Report, which analyzed more than 1 quadrillion interactions through its defense platform, found that traffic from AI agents and agentic browsers grew 7,851% year over year in 2025. Automated traffic, the report said, is now growing eight times faster than human traffic. 

The agentic era is already shaping who, or what, is active on the internet, transacting in digital commerce and, increasingly, operating inside business software. Today’s SMB leaders are now asking whether they are ready for what engaging with it actually requires. 

However, the valley between adoption and successful implementation remains quite vast. Dynatrace’s Pulse of Agentic AI 2026 report found that roughly half of agentic AI projects remain stuck in proof-of-concept or pilot stages, with security, compliance and scaling challenges slowing wider deployment. 

What agentic AI looks like for smaller firms 

Anthropic’s Claude for Small Business, launched in May, illustrates how this shift is arriving at smaller firms. The product connects Claude to finance, sales, HR, customer service and productivity tools including QuickBooks, HubSpot, Google Workspace and Microsoft 365.  

Enterprise buyers, in other words, are still working through the same implementation questions that are now landing on the desks of SMB owners. The gap is that enterprise buyers have teams assigned to them. 

Guy Bourgault, head of agentic systems at Concentrix, describes the SMB readiness problem in operational rather than technical terms. “The minimum operating model for agents used in live workflows needs to include risk management, workforce readiness and observability,” he tells TechInformed.  

Mid-market firms, he says, need to “be secure,” understand how AI can “enable and integrate with their human workforce” and measure agentic AI performance against wider business goals. 

For most SMBs, the first gap shows up before the agent is even selected. 

The data problem comes first 

Before an agent can do useful work in a live business environment, it needs data it can rely on. That turns out to be a harder problem than it looks. “For smaller businesses looking to implement agentic AI, scale is less critical early on than quality, specifically data quality,” Bourgault says.  

A demo needs clean data to run effectively. Live systems can carry duplicate customer names, outdated product records, incomplete notes and exceptions that exist only in an employee’s institutional memory.  

An agent navigating that environment behaves differently than it did in a controlled test and the errors it makes are not always visible until a customer complains or a payment goes wrong. 

“Ensuring that data input processes are consistent will go a long way to maintaining data quality across human and AI workflows,” Bourgault says, adding that “data labeling is a key piece of that quality equation.”  

The implication is that before expanding what an agent can do, an SMB needs to know which records are reliable enough for automation and which still need a person to verify. 

Salesforce CEO Marc Benioff made a similar point to enterprise buyers at Dreamforce 2025. “You have got to get your data right. You have got to get to more integrated solutions. You have got to get the priorities right. You have to get the governance right,” he says. 

Anthropic’s launch aims to offer SMBs a solution. The company says Claude for Small Business keeps existing permissions in place while requiring approval before sensitive actions are taken.  

Before any agent touches finance, sales, HR or customer-service systems, the business needs to define which data the agent can reach, which systems it can write to and which actions need a human to confirm first. 

This is what Benioff was describing at Dreamforce months ago. “You don’t have your data, then you don’t have your context,” he told the audience. The difference is that Salesforce’s enterprise customers have data teams. Most SMBs have whoever manages the CRM between other responsibilities. 

Choosing the right entry point 

There is no obvious first workflow that fits all SMBs. Bourgault says businesses need to assess their own processes before selecting use cases, and recommended evaluating potential deployments by “complexity, risk, and potential impact to key business metrics” — noting that “a single AI use case can affect multiple business processes or workflows.”  

An agent that drafts a reply, flags an overdue invoice or summarizes an account history carries less risk than one that sends the reply, changes payment terms or updates a contract record. The technology may be similar, but the level of autonomy is not. 

“The risks and impacts of rushed AI deployment are amplified when AI is implemented in customer-facing workflows,” Bourgault says.  

For businesses still building an agentic operating model, he recommends starting with workflows that “support and enable human function — such as agent-assist.” Internal knowledge search, customer triage, sales follow-up and invoice review are better early candidates than finance approvals, compliance decisions or customer disputes. 

Employee participation should be part of the entry-point decision. Sonali Fenner, managing director at Slalom, says agentic AI raises the stakes because the systems are no longer only producing answers. They are taking actions across workflows with less prompting. 

“For SMBs and mid-market firms, successful participation doesn’t start at the training stage. It begins with design,” Fenner tells TechInformed. Employees, she says, can help identify high-frequency, high-drain tasks that leadership may miss from the top down, while also shaping the guardrails, escalation points and success criteria that make agentic deployment safe and usable. 

Oversight as a design requirement, not a fallback 

Human-in-the-loop is often described as a safety feature, but Bourgault says he treats it as a design requirement rather than a fallback. “Human oversight needs to be woven into every stage of the process of implementing and operating agentic AI,” he tells TechInformed

Fenner makes the same point from the employee side. “The companies we see succeeding with agentic AI aren’t treating their people as the final step in a rollout. They are treating them as the first source of intelligence,” she says. 

For Bourgault, that involvement has to continue after the workflow is designed. During integration design, he says, oversight helps teams “understand processes and establish initial guardrails.” During pilots, “human review is critical to speed learning and improve quality of AI performance.” 

In mature deployments, it keeps performance stable “when language models are versioned, when exceptions occur, and when escalations are required.” Planning for those moments, he says, allows “human intelligence to be applied in the right place and at the right time to avoid bottlenecks as well as risk.” 

Those humans in the loop, as they’ve come to be known, must also be able to change the outcome before any damage is done. 

Observability as a management discipline 

Anthropic’s launch describes Claude for Small Business around time-saving tasks: payroll planning, invoice chasing, month-end close, marketing projects. Time saved will be the first metric most SMBs reach for.  

Bourgault, though, thinks the approach could be much broader: “SMB leaders need to think broadly when evaluating the overall impact of agentic AI,” he says. “Value can be driven through cost efficiency, revenue impact, cultural and operating shifts, and customer experience improvements.”  

Tracking whether agents reduce rework, shorten response times, improve collections or lower escalation rates gives a more complete picture than hours saved alone, he says. 

However, there are early warning signs that deserve attention: more corrections, more customer complaints, more unexplained escalations or employees bypassing approved tools signal that the deployment is not ready to expand. Without a record of what the agent did, those signals are hard to trace. 

Bourgault describes observability as “clear visibility into the current performance of your agentic AI” combined with “traceability across historical performance — something critical to managing risk and ensuring compliance.”  

In practical terms, businesses need to see what the agent is accessing, both systems and data sources, and verify that the guardrails defined before deployment are actually working. “Ultimately agentic AI must prove its value to the business by contributing to the metrics that matter — customer and business outcomes,” he says. 

When asked which controls matter most once agents are live, Bourgault’s answer: “permissions and access, human oversight and approvals, traceability, and data quality.” The questions behind those four items are not complex. Who granted the agent access? What data can it use? Which actions need approval? Where is the audit trail? Can it be stopped if it acts outside its defined scope? An SMB may not need the tooling of a bank or insurer, but the questions are the same. 

The groundwork that makes it accountable 

The gap between enterprise ambition and SMB reality is operational. The same underlying agentic AI capabilities are reaching smaller businesses through platforms such as Claude for Small Business, but with fewer data teams, governance structures and implementation resources around them.  

SMBs activating agents without data readiness, defined oversight or observability are not behind on technology. They are behind on the groundwork that makes the technology accountable. 

Bourgault’s assessment of what separates successful deployments from failed ones returns to intent. “SMBs that have a clear vision for the role of agentic AI in their business will separate from the pack,” he says.  

“The question executives and leaders should be asking is not if they should implement agentic AI, but where, how, and to what effect — what kind of agentic business do they want to be?” 

For SMBs putting agents into live workflows, answering that question before the agent acts is the difference between a controlled deployment and an expensive correction. 

Personalized Feed
Personalized Feed