
Integrating agentic AI with legacy ERP systems
When an agentic AI programme meets a twenty-year-old ERP, the instinct is to conclude the ERP has to go. It rarely does. Only 27% of enterprise applications are connected to anything at all, which means the blocker is almost never the system of record. It is that nothing has a governed way in or out of it.
Four integration patterns are in play, and they differ on exactly one thing that matters: what the agent is allowed to write.
- Only 27% of enterprise applications are connected on average and 73% of business data sits in silos. Among organisations that have already achieved agentic transformation it is only 32%.
- The four patterns form a ladder, not a menu. Each rung grants more write capability and requires the governance that goes with it.
- Read access is an architecture problem and it is solvable this quarter. Write access is a governance problem and it is what actually stops programmes.
- Gartner expects over 40% of agentic AI projects to be cancelled by the end of 2027, on escalating costs, unclear business value or inadequate risk controls.
- Gartner also expects 40% of enterprises to demote or decommission autonomous agents by 2027 over governance gaps found only after a production incident, and names uniform governance as the cause.
The rebuild is the most expensive way to avoid the question
Here is the sequence that plays out in most enterprises. An agent programme reaches the point where it needs data that lives in the ERP. The integration turns out to be harder than the pilot suggested. Somebody proposes that the real problem is the ERP, and within a quarter an eighteen-month replatform has absorbed a six-week integration question.
That trade is worse than it looks, and not because replatforming is wrong. It is that the replatform does not answer the question that stopped you. When the new ERP lands, you still have to decide what the agent may write, under what conditions, cleared by whom. You will have spent several million dollars and three years deferring a governance decision that was always the actual blocker.
This is not an argument from inability. We have run the hard version: Blackwoods moved a 400,000-SKU catalogue and decades of operational history onto Dynamics 365, phased across business units, without interrupting service to thousands of customers. Replacing a backbone is a legitimate programme when the backbone is genuinely the problem. It is a very expensive way to avoid a conversation about write access when it is not.
The test is unsentimental. If your ERP cannot support the process at all, replace it. If it can support the process and simply has no governed way for anything to reach it, that is an access problem, and access problems are cheap by comparison.
Four patterns, and what each one decides
These are usually presented as architectural alternatives. They are better read as rungs, ordered by how much the agent is permitted to change and therefore by how much governance each one obliges you to build.
| Pattern | What the agent gets | Blast radius | Where it fits |
| Read-only retrieval | Query access through a context bridge to the system of record | None. It cannot change anything. | Nearly every first deployment |
| Sidecar intelligence | Reads the ERP, writes only to its own store | Contained outside the ERP | Scoring, classification, drafting, summarising |
| Orchestrated write-back | Proposes a change, a human clears it, middleware commits it | Bounded by what the approval covers | Where the outcome has to be a transaction |
| Native agents in the ERP | Whatever the vendor grants | Defined by the vendor, not by you | Where the vendor's own agents fit the process |
Most enterprises can get real value from the first two rungs and most never need the fourth. The mistake is not choosing the wrong pattern. It is starting at rung three because a slide deck described rung one as a pilot, and pilots feel like something you have already done.
Read access is architecture. Write access is governance.
Getting an agent to read an ERP correctly is difficult engineering with a known shape: a bridge to the systems of record, retrieval over the document and ticket content where the answer lives in prose rather than in a table, and enough context that the model is not guessing. It is work, and it finishes.
Letting an agent write is a different category of problem, and the reason is that the decision is not binary but is almost always treated as one. Gartner's Shiva Varma puts it directly: enterprises treat agent governance as binary, either locked down or fully trusted, and that is the root cause of failure. An agent that reads a stock level is not the same risk as an agent that raises a purchase order. Identical controls either strangle the first or expose the second, and Gartner's recommendation is proportional governance, classifying agents across autonomy levels where each level is a different trust boundary.
That is precisely the shape of Greenlight Enterprise, and it is why the architecture is read-first with governed, human-approved write-back rather than a migration. A context bridge reaches the systems you already run, retrieval is used selectively where content actually needs it, and the line between what an agent may do unattended and what requires a person is set per use case rather than once for the whole estate. Nothing gets a new home. The system of record stays the system of record.
The part worth stealing even if you build it yourself is the sequencing. Read-only is not a lesser deployment you tolerate on the way to the real thing. It is the rung where you find out whether the agent is right often enough to be trusted with more, which is a question you want answered before it can change a purchase order rather than after.
What actually blocks this, and it is not the model
The 2026 Connectivity Benchmark puts connected enterprise applications at 27% on average, with 73% of business data in silos. Among organisations that have already achieved what the report calls agentic transformation, the figure only reaches 32%. Meanwhile 95% of respondents report struggling to integrate data across systems and 82% of IT leaders name data integration among their biggest AI challenges.
None of those numbers are about model capability, and none of them are new. This is the same integration debt that has sat on enterprise books for a decade, tolerated because the cost of leaving it was diffuse. What changed is that agents need constant real-time interaction with systems that were deliberately designed for stability and isolation, so the debt now has a deadline attached and a visible failure mode.
Which reframes what an agentic programme actually is. Most of the work is not model work. It is integration, access control and the governance to sit on top, and budgeting it as an AI project rather than an integration project is one of the more reliable ways to arrive at Gartner's 40% cancellation rate.
The test, before an agent goes near your ERP
One threshold, and it is worth holding to. For any agent you are about to deploy, you should be able to name three things: exactly which records it may read, exactly which it may write, and who cleared that scope. If any of the three has no answer, it is a read-only deployment. Not as a compromise, and not as a pilot phase to get through. As the correct first rung, because an agent whose write scope nobody can state is one you have no way to hold anyone accountable for.
The reason this matters more than the pattern you pick is that all four patterns can be run well or badly, and the difference is whether that question was answered before the architecture or discovered after the incident. Gartner's finding that governance gaps surface only after production incidents is not a prediction about technology. It is a prediction about the order in which organisations do things.
Australian enterprises meet this earlier than most. Long-lived, heavily customised on-premise ERP is common in industrial, distribution and public-sector organisations here, integration layers are thin because the systems were never expected to talk to anything, and data residency and privacy obligations make an agent with unclear write scope a compliance question rather than only an engineering one. Read-first is not the timid option in that context. It is the one that survives a review.
If the honest answer is that the ERP genuinely cannot carry the process, that is a different programme, and modernisation is where it starts. If the ERP is fine and nothing can reach it, you have an access problem, and governed agents running across the systems you already own is a quarter of work rather than three years of it.
Sources
Figures in this article are compiled from the following published sources. Each should be read in full before a number is used in a business case.
- MuleSoft and Salesforce. 2026 Connectivity Benchmark Report. 27% of applications connected, 73% of data in silos, 32% among agentic-transformed organisations, 95% struggling to integrate, 82% of IT leaders naming data integration. mulesoft.com
- Gartner. Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027, 25 June 2025. gartner.com
- Gartner. Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure, 26 May 2026. The Shiva Varma quotation and the proportional governance recommendation. gartner.com
- Deloitte AI Institute. The State of AI in the Enterprise, 2026. One in five companies with a mature governance model for autonomous agents, and legacy data and infrastructure architectures as a constraint on real-time autonomy. deloitte.com
- Coderio. AI Integration for Legacy Systems: 2026 Enterprise Guide. The pattern taxonomy this article adapts, including sidecar intelligence and middleware orchestration. coderio.com


