6 min readfrom VentureBeat

One in five enterprises can't stop a runaway AI agent's spending in real time

Our take

Enterprise adoption of AI agents is revealing a critical shift: organizations are increasingly deploying multiple orchestration platforms—averaging three—to mitigate vendor risk and retain control. This trend, driven by concerns around security, permissions, and visibility, sees Microsoft AI Foundry/Copilot Studio leading usage, with Anthropic's Claude Platform gaining significant consideration. Notably, one in five enterprises still lacks real-time control over agent spending, highlighting the need for robust oversight as AI deployments evolve. Learn more about this emerging landscape with VentureBeat's coverage of Serval’s AI agent, Catalyst.
One in five enterprises can't stop a runaway AI agent's spending in real time

The recent VentureBeat Pulse data paints a fascinating, and perhaps unsurprising, picture of enterprise AI adoption: a deliberate diversification of orchestration platforms. The median enterprise now operates three platforms concurrently, a strategic move born not just from a desire to avoid vendor lock-in, but from a deeper skepticism regarding vendor security and permissioning capabilities. This isn't simply a technical choice; it's a reflection of a broader shift in enterprise risk management as they navigate the nascent landscape of AI agents. The move signals a pragmatic approach, acknowledging that relying solely on a single vendor in this rapidly evolving space carries significant inherent risks. This echoes sentiments expressed in articles like Serval’s super agent Catalyst creates roving background agents to identify and fix IT issues before they’re ticketed, where the focus on automation and problem-solving highlights the need for robust and adaptable infrastructure. We’re seeing a move away from the early cloud days' rush to embrace a single provider, towards a more nuanced, multi-vendor strategy.

The data reveals a fascinating ecosystem emerging—Microsoft AI Foundry/Copilot Studio, OpenAI’s Agents SDK, and Anthropic’s Claude Platform are the current frontrunners, with enterprises also exploring Google's offerings and custom in-house solutions. The anticipated shift towards a hybrid control plane by 2026, with over half of respondents expecting this model, further underscores the trend of vendor diversification. While satisfaction with current platforms is relatively high (4.17 out of 5), concerns around ease of implementation and value for money suggest that the market is still maturing. The willingness of enterprises to change platforms within the year—with Claude Agent SDK a top contender—highlights the dynamic nature of the space. The exploration of open-source options, as demonstrated by TrueFoundry’s TrueForge TrueFoundry's open-source AI agent harness TrueForge boasts 30%-75% cheaper task completion than Claude Managed Agents, is also a significant factor, offering potential cost savings and greater control.

Beyond platform selection, the survey illuminates a critical focus on control and visibility. Enterprises aren’t prioritizing flashy features; instead, they’re investing heavily in agent monitoring, debugging, and security enforcement. The fact that nearly one in five enterprises still can’t stop a runaway agent’s spending in real-time is a stark reminder of the challenges in managing these systems, and a clear signal of where investment needs to be directed. This emphasis on reliability and operational stability, rather than end-user experience (currently a lower priority), suggests a phase of foundational building. The move toward multi-step workflow management, with a focus on task completion reliability, reflects a desire for agents that can handle complex, real-world processes. It's a pragmatic approach, prioritizing robustness over immediate user-facing enhancements.

Ultimately, the data suggests that while the hype around "agents" persists, the reality is more nuanced. Most enterprises are still in the early stages of deploying true, autonomous agents, with many systems still functioning as advanced chatbots. The infrastructure is being built, the control planes are being designed, but the full realization of the agentic wave is likely still some time away. The question now becomes: as these systems mature and demonstrate their value, will the focus shift towards improving the end-user experience, or will enterprises continue to prioritize the underlying infrastructure and operational control?

Enterprise AI teams have stopped betting on a single orchestration platform. The median enterprise now runs three at once — not by accident, but because none of them fully trusts a single vendor to run the show, according to VB Pulse data.

This is not just to avoid vendor lock-in and retain flexibility (although that’s a big part of it). There’s still a lot of uncertainty, even distrust, in vendors’ security and permissioning capabilities. Enterprises want the ability to impose their own.

Microsoft leads on primary usage today, while Anthropic leads by a wide margin in what enterprises are considering next. But enterprises still struggle with many challenges, notably around token usage and visibility into agent spending.

These findings are from an ongoing analysis of how enterprises are actually deploying and using AI: Their platforms of choice, what guides their decision-making, what they prioritize, their AI expectations, how they control costs, and whether their AI is actually agentic or still a chatbot in an "agent" label.

VB Intelligence is getting feedback from builders actually in the trenches: software and machine learning (ML) engineers, product and program managers, and data/AI/analytics VPs and directors.

Concerns around retaining visibility and control

Across 107 enterprises, agentic orchestration has become decidedly plural. The survey found that the majority of enterprises are not committing themselves to any one model: 85% are using two or more orchestration tools; 64% are using three. Just 15% run a single orchestration platform.

Microsoft AI Foundry/Copilot Studio shows up in 70% of stacks, OpenAI’s Agents SDK in 68%, and Anthropic’s Claude Platform in 47%. Builders surveyed are also to some extent using Google’s Enterprise Agent Platform, LangChain/LangGraph, Salesforce Agentforce, Amazon Bedrock, and LlamaIndex. Augmenting vendor tools, 22% of builders run custom in-house orchestration.

This trend of hybridability is only expected to continue. More than half of respondents (53%) said the primary control plane will be hybrid by the end of 2026. Fourteen percent expect to use a provider-managed service, 13% plan on a custom in-house control plane, and 11% are betting on external platforms that are abstracted away from model providers.

Dovetailing with this, more than two-thirds of respondents plan to change platforms within the year: 15% in the next three months (or sooner), 24% in three to six months, and 28% in six to 12 months. Claude Agent SDK is a top tool under consideration; 43% of builders are exploring the Anthropic-built model. Roughly one-third are looking at Google’s Enterprise Agent Platform, another 31% are focused on custom in-house orchestration, and 25% are investigating OpenAI’s options.

Perhaps learning from the lock-in of the early cloud days, enterprises aren’t choosing one “winner.” They are deliberately building for a future where multiple orchestration platforms, models, and agents work with each other across a hybrid control plane.

Generally speaking, respondents are pleased with the platforms they’ve been running, rating them 4.17 out of 5 for overall satisfaction. But they are less satisfied with ease of implementation (rating it 3.91 out of 5) and value for the money (3.63 out of 5). Keep an eye on these ratings as orchestration platforms and AI roadmaps mature.

Where enterprises are putting their money

Enterprise buying logic is now based on a mix of several factors. Beyond flexibility (cited by 29% of respondents), top considerations include security and permissions (17%), production reliability (15%), and control over agent execution (15%). Just one out of 10 identify model gravity — native alignment with a state-of-the-art base model — as important in purchasing decisions; 8% name ease of development, 4% cite total cost of ownership, and just 2% cite latency and memory performance.

Spending also reflects enterprise priority on visibility, security, and control. Builders are investing the most in agent monitoring and debugging (31%) and security and permissions enforcement (30%). Workflow tooling accounts for another 19%. That's a shift from VentureBeat's prior wave a month earlier, when workflow tooling led orchestration spending outright.

Enterprises are largely optimizing for task completion reliability (30%), multi-step workflow management (27%), developer productivity (23%), and operational stability (13%). Just 7% of respondents name end-user experience as a top priority at this point, indicating that many are still focused on orchestration at this point rather than UX.

Essentially, enterprises are signaling that workflow succeeds when it carries multiple steps to completion. Simplifying development and end-user experiences could become a larger concern when platforms are actually in place.

The visibility problem

Builders’ biggest concerns when choosing platforms center around control and oversight. They don’t want vendors to constrain their ability to see what their agents are doing on a given platform. Factors top of mind include security and permissioning limitations (37%), vendor lock-in (23%), limited visibility and observability (22%) and inflexibility around models and tools (16%).

Meanwhile, in these early days of AI agents, enterprises still struggle to control agent token use; one in five still can’t stop a runaway agent’s spending in real time.

Builders are using various strategies to try to keep agent spending in line: 30% rely on native platform controls (built-in budget caps or throttling) and 25% have built custom gateway plumbing (proxy middleware to intercept runaway agents).

A quarter of respondents use dynamic routing to offload heavy work to low-cost models, and 21% still rely solely on reactive monitoring, such as post-hoc logs; these enterprises have no real-time kill switches.

One interesting finding: unlike the prior wave, organization size makes little difference in fiscal control maturity — 18% of enterprises with 10,000-plus employees exercise only reactive control, compared to 23% of smaller ones.

Clearly, while enterprises recognize the problem with spend, many have not yet instrumented their stacks to rein it in.

Most enterprises still aren't running true multi-step agents

Builders polled were asked to honestly assess their tech stacks; the consensus seems to be that ‘agents’ are slowly but surely progressing beyond chatbots wrapped in that fancier label.

Here’s how the numbers break down: A small number of respondents (2%) report that 76 to 100% of their systems are advanced and largely autonomous; 14% say 51 to 75% of their systems are complex, multi-agent pipelines; and 47% report that 26 to 50% of their systems are true orchestration.

On the other end of the spectrum, 35% say just 1 to 25% of their systems are true orchestration; most deployments remain basic assistants, and 3% are still only deploying chatbots.

This is in line with VB’s June Pulse survey: 71% of respondents said a quarter or fewer of their deployed “agents” can autonomously complete multi-step work, and just one-tenth say they have deployed agents at scale.

There’s no doubt that enterprises are building control planes and infrastructures for agents; but for many of them, the true agentic wave is still off on the horizon.

Read on the original site

Open the publisher's page for the full experience

View original article