workflow automation

Enterprises built AI agents first, now racing to govern them

Enterprises deployed AI agents before building the controls to manage them, and they did it knowingly.

5 min readVentureBeat
Enterprises built AI agents first, now racing to govern them

The data is in, and it tells a story that should give every enterprise leader a moment of pause. VentureBeat Research found that companies deployed AI agents ahead of the controls needed to manage them, and they did it knowingly. That is not a failure of foresight; it is a deliberate bet that speed to deployment outweighs the risk of operating without a net. The result is a sprawling retrofit effort already underway. Across the five control layers measured, identity, evaluation, cost telemetry, context, and orchestration, 57% to 68% of enterprises plan to switch vendors or add new ones within a year. A third of them will move within the quarter. The bill for this correction is coming due, and it will be paid in engineering hours, new tooling, and the uncomfortable work of admitting that the "agents" in production are not what they were sold as. The most revealing number is this: 71% of enterprises said a quarter or fewer of their deployed agents can complete multi-step work on their own. Only 10% said true agents are the majority of what they run. So most of what is being called an agent is a chatbot wearing a label. That distinction matters because a single-prompt chatbot with a human reading every answer needs almost none of the governance that a genuine multi-step agent requires. The retrofitting, then, is not just about tightening security or improving evaluation. It is about building the scaffolding for a capability most organizations do not actually have yet. The urgency is real, but the market is still sorting out who will supply the pieces. No layer has an entrenched incumbent, and the switching intent is highest in orchestration, where 68% plan to adopt, add, or replace platforms within a year. The open question, whether that money flows toward the big platforms' built-in tools or toward specialists, will define the next four quarters. We would tell a reader this: do not assume your current AI vendor will be your governance vendor. Start mapping your control plane now, because the cost of switching later is only going up. The security findings sharpen the point. Companies that let agents share credentials experienced security incidents at a 63.5% rate, against 40.9% for those that enforce scoped identity. That is not a marginal difference; it is the difference between a systemic vulnerability and a manageable one. Meanwhile, two-thirds of enterprises either already allow an agent to push code to production on automated evaluation results alone, or are engineering toward that within 12 months. Only 5% fully trust the evaluations that would make that call. Half shipped an agent that passed internal evaluations and then caused a customer-facing failure. The gap between what is being automated and what is being trusted is not closing; it is widening. The fix is not to slow down. It is to test evaluations against production outcomes, not internal benchmarks, and to start with scoped identity for every agent that touches a production system. As teams like DoorDash have shown with Automating Feature Flag Cleanup: DoorDash Leverages AI for Efficiency, the path to practical multi-agent systems is built on tightly scoped, observable actions, not broad autonomy. The infrastructure numbers reinforce the same theme. More than 80% of enterprises running their own GPUs report utilization of 50% or less, and only 44% track what their AI compute actually costs and returns. The instinct to buy more capacity is understandable, but it is the wrong target. The number worth chasing is utilization and per-workload cost on the hardware already running. The same logic applies to the context layer: 57% of enterprises traced a confident, wrong agent answer to their own missing or inconsistent business context. Wrong metrics, stale definitions, absent documents. This is not an AI problem; it is a data governance problem wearing an AI hat. The practical takeaway we would offer is direct: before you scale agents, govern the definitions they answer from. Metrics and entities first. The technology that enables this shift is moving fast, and the work of modernizing APIs and Scale AI Workflows: Modernizing APIs with Architecture as Code is already showing how structured, automated approaches can bring order to complexity.

From VentureBeat

Enterprises deployed AI agents ahead of the controls needed to manage them — and they did it knowingly. That is the central finding across the five parallel surveys VentureBeat Research fielded in June, spanning every layer of the agentic stack. Now those enterprises are retrofitting to catch up with their own standards, and they are budgeting for it: In each of the five control layers we measured, 57 to 68% of enterprises plan to switch vendors or add new ones within 12 months, and roughly a third, depending on the layer, plan to move within the quarter.

Read the original at VentureBeat