Kyndryl has announced a new capability to create policy-governed agentic AI workflows, designed to help organizations scale the use of AI agents in complex and highly regulated environments. Automated policy enforcement establishes control frameworks, integrates compliance into processes, and reinforces transparency throughout the organization.

This innovation, called “policy as code”, allows organizations to translate internal rules, regulatory requirements and operational controls into machine-readable policies. These policies govern how agentic AI agent workflows are executed, ensuring consistent, auditable, and reliable results, and reinforcing trust in the use of AI agents in critical processes.

Regulatory and compliance concerns

Enterprises want to reap the benefits of integrating agentic AI into their operations, but security, compliance, and governance challenges remain a deterrent to wide-scale adoption. In fact, according to the latest Kyndryl Readiness Report, 31% of customers point to regulatory or compliance concerns as a top barrier to expanding their recent technology investments.

Kyndryl’s policy as code capability addresses these challenges by defining clear operational boundaries and designing agent actions so that they are understandable, reviewable, and aligned with customer-defined business and regulatory requirements. This approach also allows you to reduce costs, accelerate decision-making, minimize errors and enable native AI workflows, always under a previously established control framework.

“Policy as code” is a key element of the Kyndryl Agentic AI Framework, providing a control logic layer that dynamically governs how AI agents run, interact, and operate across systems. This approach is supported by Kyndryl’s decades of experience managing complex business environments and the nearly 190 million automations the company manages each month in mission-critical systems.

This operational basis allows greater control over agents, makes it easier to understand how and why they make decisions, and reduces the risk of unforeseen behavior when they are in real operation.

Integrating Agentic AI Workflows

Kyndryl’s policy as code solution incorporates differentiated capabilities that facilitate the governance of agentic AI workflows, including:

  • Deterministic execution: Agents only perform actions permitted by predefined policies, reducing operational risk.
  • Hallucination mitigation: Controls block unpredictable or unauthorized actions throughout the workflow, preventing operational impacts from erroneous behavior.
  • Transparency by design: Every action and decision of the agent is recorded and explainable, facilitating auditing and regulatory compliance.
  • Human supervision: Agents execute tasks according to verifiable policies, monitored through dashboards that guarantee consistent and controlled decisions.

This structured approach allows Kyndryl to deploy policy-bound autonomous agents in a secure and controlled manner in sectors such as financial services, government, supply chains and other mission-critical areas, where reliability and predictability are essential.