AI & Tech

Agentic AI Needs Something Most Indian MSMEs Don't Have: A System of Record

Ask a vendor what agentic AI will do for your business and you will hear about autonomy: software that plans, decides and executes instead of waiting to be prompted. Ask the same vendor what it needs from you, and the pitch gets noticeably quieter. Software that books your dispatches, chases your receivables or reorders your stock has to read your dispatch, receivable and stock records, and then write back to them. That requirement never makes the brochure, and it is the single thing that decides whether any of this reaches a twenty-person firm in Ludhiana or Coimbatore.

India's own published numbers suggest that for most small firms, the honest answer today is: not yet. Not because the technology is weak, and not because owners are unwilling, but because an agent is only as useful as the records it is allowed to act on — and in most Indian MSMEs those records are not in software at all.

Data card comparing agentic AI deployment rates in India against MSME software adoption

An agent is not a chatbot with better manners

The distinction matters more than the marketing allows. A chatbot reads text and produces text; a human being then decides whether to act on it. An agent is given a goal, a set of tools and permission to use them. It does not suggest that you send the reminder — it sends the reminder. It does not draft the purchase order — it raises it in your system.

EY's The AIdea of India: Outlook 2026 describes this as the arrival of an “infinite workforce capacity”, breaking the old equation in which more output required more people. Its survey of Indian C-suite respondents found 76% expecting significant business impact from generative AI, 47% already running multiple use cases in production, and 24% reporting active deployment of agentic AI specifically.

That shift also changes the failure mode, and this is the part small firms should sit with. A chatbot that invents something wastes ten minutes of your time. An agent that invents something issues a credit note, emails a customer, or edits a ledger line — and then carries on to the next task, confidently, on top of the error it just created.

The 24% and the 29%: two numbers that do not fit together

EY's 24% describes Indian enterprises — organisations with IT functions, data teams and integration budgets. Set it beside what we know about the small-business base it is supposed to eventually serve.

The PayNearby MSME Digital Index 2024 found that 29% of tech-savvy MSMEs in India use accounting software. Not 29% of all MSMEs — 29% of the segment already identified as the digitally confident one. The India SME Forum's 2025 study, Breaking Barriers, Building Futures: The State of Digitalisation in Indian MSMEs, put 53.8% of respondents as having integrated the internet, digitisation or e-commerce into core operations, broadly consistent with the Economic Survey 2024-25's estimate that 55–60% of registered MSMEs have moved online in some form and the NASSCOM-Deloitte MSME Digital Index 2025 figure of 57% digitally engaged.

Read those “digitalised” percentages carefully, because they are doing a lot of quiet work. For a large share of that cohort, being digital means a UPI QR code at the counter, a WhatsApp Business catalogue, and a listing on a marketplace. Those are channels. They are not records. An agent cannot reconcile a payment it can only see as a screenshot, and it cannot chase an invoice that exists as a photograph in a group chat.

The same India SME Forum report adds two findings that explain why the gap persists: 52.6% of MSMEs said they struggle to identify the right digital tools for their needs, and 97.3% were unaware of government schemes or incentives designed to support digitalisation. The problem is not that small firms rejected the software. Most were never in a position to choose it.

Gartner's 40% is a warning about prerequisites, not about AI

In June 2025, Gartner forecast that over 40% of agentic AI projects would be cancelled by the end of 2027, citing escalating costs, unclear business value and inadequate risk controls. The number is usually quoted as a verdict on the technology. It is better read as a verdict on readiness.

Consider who is failing. These are not corner shops experimenting with a chatbot; they are funded enterprise programmes. EY's own respondents point at the same wall from the inside: 64.5% rated data governance and security as a “very severe” challenge, and 78% reported struggling with system integration. If the organisations that have integration engineers are being defeated by integration, the constraint is structural rather than a matter of effort.

The binding constraint on agentic AI in a small Indian firm is not the model, the licence fee or the skills gap. It is whether a machine-readable record exists for the agent to act on, and whether anyone would notice if it acted wrongly.

None of this makes the optimistic projections dishonest. The Google–India SME Forum report released in July 2026, built on a primary survey of 3,249 MSMEs, projects that AI adoption could unlock over $490 billion in economic value, with advanced workflows and agentic systems capable of delivering profitability improvements of 30–35%. Both things can be true at once: the ceiling is genuinely that high, and the floor is where most firms are currently standing. The distance between them is measured in bookkeeping, not in ambition.

The liability arrives before the productivity does

DPDP Rules 2025 compliance timeline: 13 November 2026 consent rules, 13 May 2027 full compliance

There is a timing problem that small firms are not being warned about loudly enough. The Digital Personal Data Protection Rules were finalised in November 2025, and the obligations phase in on fixed dates regardless of whether a business feels ready.

DateWhat takes effect
13 November 2026Rule 4 — consent management obligations apply to organisations with digital products and services
13 May 2027Full compliance deadline for the DPDP Act and Rules, including core Data Fiduciary obligations

The penalty ceilings are not scaled to turnover: up to Rs 250 crore for failing to maintain reasonable security safeguards, and up to Rs 200 crore each for breach-notification and children's-data failures. More important for anyone considering an agent, accountability sits with the Data Fiduciary even where the processing is carried out by a Data Processor. Pointing at your AI vendor after a leak is not a defence; the framework expects a contract with security provisions in it.

Now apply that to a plausible small-business deployment. An agent that reads your customer WhatsApp threads to draft replies is processing personal data. It may be transmitting that data to a model you do not host, under terms you have not read, for a purpose your customer never consented to. That is a compliance exposure created on the day you switch it on, and a productivity gain that arrives some months later, if at all.

CERT-In has already listed the agent as an attack surface

Four CERT-In Blueprint controls: inventory, restrict, control and log, adversarial testing

On 25 May 2026, CERT-In issued its Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure. It explicitly names autonomous agents and AI-enabled automation platforms among the capabilities being used to automate exploitation, accelerate vulnerability discovery and orchestrate attacks at scale.

Its governance recommendations translate into small-firm language fairly cleanly. Keep an inventory of every AI system and integration you actually have. Restrict what staff are allowed to upload to public AI services. Apply access controls and logging specific to AI tools rather than assuming your existing user permissions cover them. And conduct adversarial testing for prompt injection and input manipulation.

That last item deserves plain explanation, because it is the risk unique to agents. Prompt injection means an instruction hidden in content your agent reads — the body of a supplier email, the text layer of an invoice PDF, a product review — which the agent then obeys as though it came from you. A chatbot exposed to this produces a strange sentence. An agent exposed to this takes an action. CERT-In's Blueprint also sets an expectation of 12-hour containment for known exploited vulnerabilities on internet-facing systems, a tempo most small firms have no process for at all.

Four questions to answer before you buy anything

These are specific to what the evidence above actually shows, and they are worth working through in order.

1. Where does this record live, and can software write to it? If your stock position exists in Tally, Zoho, Vyapar or a cloud POS with an accessible interface, an agent has something to hold on to. If it exists in a diary and a WhatsApp group, no amount of model capability closes that gap. This is the question the 29% figure is really about.

2. What is the blast radius of a wrong action, and is it reversible? Rank candidate processes by what a confident mistake would cost. A badly drafted reply is recoverable. A wrongly issued credit note, a mis-filed return or an erroneous payment is not. Begin where errors are cheap and undoable, and you buy yourself the evidence to expand later.

3. Who reads the log, and when? An agent without an audit trail that a named person reviews on a fixed day is not an employee, it is an unsupervised one. This is also what CERT-In's logging recommendation and the DPDP Act's accountability structure both quietly assume you have.

4. What personal data does it touch, and where does that data travel? You need this answer before 13 November 2026, not after. If you cannot describe the data flow in two sentences, you cannot obtain valid consent for it.

If you cannot answer the first question for a given process, that process is not an AI problem yet. It is a bookkeeping problem wearing an AI costume — and fixing it returns value whether or not you ever buy an agent, because clean records improve your credit file, your GST reconciliation and your ability to sell the business. My field guide AI for the One-Person Business works through this sequencing for firms with no technical staff at all.

Where this genuinely works today, and where it will not

It works now where the task is high-volume, low-stakes, text-shaped and already digital. First-line replies on a channel you already operate. Drafting and standardising product descriptions for a catalogue. Triaging inbound enquiries into hot, cold and irrelevant. Summarising three supplier quotations into a comparison you still read yourself. Every one of these is reversible, cheap to check, and improves a process you can measure within a month.

It does not work yet where the action moves money without a human confirming it, where it touches a statutory filing, where the source of truth is paper or a photograph, or where the right answer depends on a relationship rather than a record. A great deal of Indian small-business decision-making sits in that last category, and it is not a deficiency to be automated away.

One honest qualification to my own argument. Firm age is not the same as firm readiness, and the gap can cut the other way. A three-year-old D2C business born on a cloud POS with a payment gateway and a proper inventory system has cleaner records than a fifty-year-old engineering unit running three parallel ledgers and a very experienced accountant. The newer firm may leapfrog straight to useful agents while the older, larger one stalls. Readiness is about where the records sit, not about how long you have been trading — which is also the most encouraging thing in this entire picture, because records are something a small firm can actually fix on its own budget and its own timetable.

Further reading

Sources

  • EY India, The AIdea of India: Outlook 2026 — Is India ready for Agentic AI? (2026): 24% active agentic AI deployment, 76% expecting significant GenAI impact, 47% with multiple use cases live, 64.5% rating data governance and security “very severe”, 78% reporting integration difficulty.
  • Gartner press release, 25 June 2025: Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027.
  • India SME Forum, Breaking Barriers, Building Futures: The State of Digitalisation in Indian MSMEs (2025): 53.8% digitalised in core operations, 52.6% unable to identify the right tools, 97.3% unaware of government digitalisation schemes.
  • PayNearby, MSME Digital Index 2024: 29% of tech-savvy MSMEs using accounting software. PayNearby MSME Digital Index 2026: 82% reporting confidence with digital tools.
  • Government of India, Economic Survey 2024-25, and NASSCOM-Deloitte, MSME Digital Index 2025: 55–60% and 57% digitally engaged respectively.
  • Google and India SME Forum, MSME AI adoption report, July 2026: primary survey of 3,249 MSMEs; over $490 billion in projected economic value; 30–35% profitability improvement potential from advanced and agentic workflows.
  • CERT-In, Blueprint for Reducing Exposure and Defending against AI-Assisted Vulnerabilities Exploitation in Digital Infrastructure, 25 May 2026: autonomous agents named as a threat vector; AI inventories, access controls and logging, adversarial testing for prompt injection; 12-hour containment expectation for known exploited vulnerabilities.
  • Digital Personal Data Protection Rules, notified November 2025: Rule 4 consent management effective 13 November 2026; full compliance 13 May 2027; penalty ceilings of Rs 250 crore (security safeguards) and Rs 200 crore (breach notification, children's data); Data Fiduciary accountability retained where a Data Processor performs the processing.
Dr. Dibyendu Choudhury

Dr. Dibyendu Choudhury

Author of 9 published books. Retd. Govt. Employee (MoMSME) · MSME Policy Expert · Visiting Faculty at NI-MSME · Vedic Philosophy Scholar. Writing at the intersection of ancient Indian wisdom, modern entrepreneurship, and national policy.

Never Miss an Insight

Join 47,000+ readers — free fortnightly newsletter on MSME policy, Vedic wisdom & leadership.