AI agents — how SMEs should prepare for software that acts, not just answers.
Microsoft counted fifteen times more active agents in the Microsoft 365 ecosystem in a year. The OECD counted 3.6% of AI-using SMEs that deploy them. The distance between those two numbers is where most European firms currently sit.
Insights yazıları İngilizce yayımlanır.
Two measurements published three weeks apart describe the same change from opposite ends. On 13 April 2026 the OECD reported that, among small and medium-sized firms already using artificial intelligence, 3.6% deploy agentic applications. On 5 May 2026 Microsoft reported that the number of unique active agents in its Microsoft 365 ecosystem had grown fifteenfold in a single year.
Both are accurate. One counts firms that chose to run agents, the other counts agents running. Between them is where most European and Swiss SMEs sit: inside software quietly acquiring the ability to act, before anyone has decided what it may do.
Agents multiplied fifteenfold in the supplier’s telemetry, not in company strategy
Microsoft’s figure is product data, not a survey: unique active agents on the Microsoft 365 Copilot Agents platform and in SharePoint, in a rolling 28-day window from March 2025 to March 2026, across all countries including the EU. Growth was fifteenfold year over year, eighteenfold in large enterprises. An agent counts as active if it recorded one day of user-initiated use or one autonomous run. That measures supply.
The OECD’s 2026 D4SME Survey measures demand. Of responding SMEs, 61% use at least one AI-enabled application; among them, 75% use off-the-shelf tools, 5% customised applications and 3.6% agentic ones. Where adopted, they mainly automate multi-step workflows: bookings, invoices, marketing campaigns. The caveats matter: 1,240 responses, three quarters from Japan, from firms already trading on digital platforms, and a sample not representative of the wider SME population.
Read together, they say what a news summary misses: agents are less often chosen than inherited, arriving as features inside the accounting, support and customer tools firms already licence.
An agent is a model that has been given tools, permissions and a loop
Anthropic’s engineering team set out the architectural definition in December 2024: in a workflow, models and tools are orchestrated along predefined code paths; in an agent, the model directs its own process and tool use. Autonomy, the same note warns, raises cost and the risk of compounding errors.
On 1 May 2026, six national cyber security agencies from Australia, Canada, New Zealand, the United Kingdom and the United States issued joint guidance on the careful adoption of agentic AI services. In the accompanying note of 15 May, the UK National Cyber Security Centre describes agentic systems as able to reach data sources, remember context, decide, use tools and act in pursuit of a goal, and lists four properties that change the risk profile: broader access to external systems, data and tools; unpredictable behaviour when goals can be read in ways a person would not expect; problems harder to spot when actions run faster than humans can review them; and courses of action harder to explain.
The consequence is narrow and important. An assistant produces a draft someone still has to accept. An agent produces an action already taken — an invoice raised, a booking confirmed, a message sent. Error stops being a bad paragraph and becomes a wrong transaction.
What organisations report holding them back is control, not capability
McKinsey’s 2026 AI trust survey questioned around 500 organisations between December 2025 and January 2026, among those responsible for AI governance, risk or investment. Nearly two-thirds named security and risk as the main obstacle to scaling agentic AI, ahead of regulatory uncertainty and technical limits; only about a third reported mature strategy, governance and agentic controls. Gartner forecast in June 2025 that more than 40% of agentic AI projects would be cancelled by the end of 2027, on escalating costs, unclear value and inadequate risk controls.
Microsoft’s survey of 20,000 knowledge workers who use AI at work — ten markets including France, Germany and Italy, fieldwork 18 February to 7 April 2026 — locates the constraint. Organisational factors — culture, manager support, talent practices — account for more than twice the reported AI impact of individual ones such as mindset (67% against 32%), though Microsoft notes these are statistical associations, not causal effects. Only one AI user in four, 26%, said leadership was clearly and consistently aligned on AI. And among the 16% Microsoft classes as Frontier Professionals, its most advanced users, only 25% reported agent workflows, human handoffs and quality standards documented and repeatable at organisation level, against 14% of the rest; 24% in Germany, 22% in France. Documentation, not model quality, is the scarce input.
European and Swiss law already govern software that acts on people
Two legal frames already apply. The EU Artificial Intelligence Act, Regulation (EU) 2024/1689, applies generally from 2 August 2026. Article 50 requires providers of systems intended to interact directly with natural persons to design them so those persons are informed they are dealing with an AI system, unless that is obvious: a customer-facing agent has to say what it is. For high-risk systems, Article 26 requires human oversight to be assigned to natural persons with the necessary competence, training, authority and support, and logs to be kept for at least six months. Article 2(1)(c) extends the Regulation to deployers outside the Union where the output is used inside it: a Swiss firm whose agent answers, quotes or books for EU customers is in scope.
Swiss law reaches the same point from the data-protection side. Article 21 of the Federal Act on Data Protection (SR 235.1, in force since 1 September 2023) requires the controller to inform the person concerned of any decision based exclusively on automated processing that has a legal consequence for them or a considerable adverse effect; on request, that person may express their point of view and ask for review by a natural person. Both duties fall away where the decision is directly connected with concluding or performing a contract and the person’s request is granted, or where they explicitly consented — which makes the exception the practical test: the agent that says yes raises no question; the one that declines an application or cancels an order does. Article 22 adds a data protection impact assessment where processing is likely to result in a high risk to the person’s personality or fundamental rights, a question turning on the nature, extent, circumstances and purpose of the processing, and arising in particular with new technologies. Switzerland’s own framework remains sector-specific: the Federal Council decided on 12 February 2025 to ratify the Council of Europe AI Convention, with a consultation draft due by the end of 2026.
The decisions a management team can take before the first agent is switched on
None of this requires a technology budget.
- Choose one bounded, repetitive, low-risk process and name it — order acknowledgements, appointment scheduling, supplier document intake. The NCSC, summarising the joint guidance, advises tightly bounded pilots on clearly defined tasks.
- Draw the action boundary in writing: which actions the agent completes alone, and above which value or degree of irreversibility approval is mandatory. Payments, contracts, customer commitments and personnel decisions belong on the approval side.
- Apply least privilege. The NCSC’s formulation is worth adopting as written: give agents “only the minimum access they need, for the shortest time required”.
- Name the owner. Accountability for the deployment decision, the access granted and the consequences stays with people, and should be assigned before an agent touches a live system.
- Keep and read the logs. Six months is the European benchmark for high-risk deployments, and monitoring surfaces unusual activity across connected tools.
- Interrogate the supplier: what the system can do without a human, what it records, how it is stopped, what happens when it errs.
Three dates and one measurement worth keeping on the agenda
Three dates bracket the period ahead: 2 August 2026, the AI Act’s date of general application, including the transparency duty; the end of 2026, when the Swiss consultation draft is due; and 2 December 2027, to which Regulation (EU) 2026/1744 deferred the obligations for the standalone high-risk uses in Annex III.
The measurement is simpler than the calendar: not how many agents a company runs, nor what it spends, but the share of its agent-assisted workflows for which someone can produce, on request, a written description of what the agent may do alone, who approves the rest and where the record is kept. On that evidence the share sits at a quarter even among the most advanced users surveyed — the one number a management team can change without buying anything.
