The real risk isn't moving too slowly on agentic AI, it's moving without a governance framework — and a number that matters most for small businesses
Published September 8, 2026 by Aaron McMillan in Procurement Magazine ("Zip: How Agentic AI is Reshaping Procurement Decisions"), the interview with Tasha Campbell, Customer Success Manager at Zip, given ahead of a workshop at the Procurement LIVE London summit, makes a simple case: once an agent acts alone at every step, governance can no longer rest on one person's permissions — it has to be built into the software itself. The number behind it: according to Zip's own State of AI report, 57% of employees surveyed already regularly use AI tools their employer never sanctioned.
Campbell describes three layers inside a company: systems of intake (the everyday tools people use, where AI already shows up on every screen), systems of record (ERP, CLM, AP — where the truth about spend lives), and in between, a governance and orchestration layer she calls new. Her point is direct: "Autonomous agents remove that human from each step, so governance now has to live in the software itself." She's just as direct about the most common mistake she sees: it isn't moving too slowly, "it's moving too quickly, often outside any sanctioned process altogether" — which is where the number comes in: 57% of employees use AI tools their employer never sanctioned, meaning, in her words, "someone at most companies is likely pasting supplier contracts into an LLM security teams have never vetted."
That framing, built for large procurement departments, actually feels more urgent for the segment AppH serves. Zip talks to companies with a security team and a procurement function able to catch unsanctioned use, at least after the fact. A six-location domiciliation agency, a fleet garage, a dental practice — AppH's typical customer — have neither: if someone on staff pastes a client's details into an unvetted public chatbot, no one will ever see it, not in real time and not later. Campbell's advice on where to start — "where volume is high and judgment is low": intake triage, first-pass review, data validation — describes almost exactly the ground AppManager already covers: triage, pre-qualify, draft a response, never close out a consequential action alone without a human's click.
For AppH
- The piece validates, from a completely different sector (enterprise procurement) with zero connection to AppH, the founding principle behind AppManager: once an agent acts at every step without continuous supervision, governance has to be designed into the product from day one, not bolted on after an incident.
- The 57% figure makes a risk we often describe in the abstract concrete: for a small business without a security team, starting from an already-governed product (built-in human approval) cuts a risk nobody in-house has any other way to watch for.
Against / the honest limit
- Zip speaks to procurement departments with dedicated teams running this framework day to day — AppH's customers don't have that layer either: AppManager's approval click governs what AppH's own agent does, not what an employee separately pastes into an unrelated external AI tool.
- The cited figures ($8M saved by OpenAI, risk reviews 9x faster at Snowflake) come from Zip's own material about its own customers — credible given the interview's rigor, but not independently verified by AppH.
What stopped us in this interview wasn't the general warning about agent governance — we've read plenty of those — it was the 57% figure, because it shifts where the problem sits: the risk isn't only what a well-designed agent could get wrong, it's what an employee, left on their own, is already doing with a tool nobody approved. For the large procurement departments Zip serves, the answer runs through a dedicated security team. For a six-location small business, that team doesn't exist — which is exactly why we think starting from a product where human approval is built in by design, rather than bolted on after an incident, matters more for this segment than for a large enterprise. We say this without overstating our own reach: AppManager governs what it does itself, not what an employee does elsewhere with an outside chatbot — that part stays, as always, outside our control.
Reviewed by a human at AppH