The response to RPA's limits can't just be replacing bots with autonomous agents and removing the constraints. That trades one problem for another. RPA is brittle but predictable. Ungoverned agentic AI is flexible but unpredictable, and in a regulated enterprise, unpredictability is its own liability.
The EU AI Act classifies automated decision-making in financial services, healthcare, employment, and government services under its high-risk categories. High-risk AI systems need transparency in decision-making, human oversight at appropriate steps, and audit trails a regulator can inspect. An AI agent making decisions across enterprise systems with no governance layer doesn't meet that bar, and deploying one that way is a regulatory exposure, not just an operational risk.
DORA adds a further layer for financial institutions operating in the EU: operational AI needs to be tested for resilience, documented against failure scenarios, and designed so automated systems don't create single points of failure in critical processes. RPA programs often fall short of that standard already. Ungoverned agentic AI doesn't fix it.
The answer to RPA's limits isn't ungoverned agentic AI. It's governed agentic AI, where agents operate within pre-approved workflow parameters, actions are logged, and human escalation is built into the process design rather than added after something goes wrong.