VentureBeat Research: Where enterprise AI agent governance hasn't caught up
Our take

The recent VentureBeat Research findings paint a compelling, if somewhat cautionary, picture of the current enterprise AI agent landscape. It’s clear that organizations, eager to capitalize on the promise of AI-powered automation, raced ahead with deployment, often overlooking the critical infrastructure needed for governance and control. The core takeaway—that enterprises knowingly deployed agents before establishing the necessary safeguards—is significant. As we've seen explored in articles like The agent evaluation gap: Enterprise AI organizations have a reality-alignment problem, not a coverage problem — and most are shipping to production anyway, the pursuit of speed and immediate gains has, in many cases, outstripped the development of robust evaluation processes, leading to potentially costly failures. This retrospective scramble to implement controls—with 57-68% of enterprises planning vendor changes—underscores the inherent risks of prioritizing velocity over stability in emerging technologies. And considering the recent release of models like Anthropic launches Claude Opus 5, a cheaper AI model for coding, agents and enterprise workflows, the pressure to integrate and leverage these capabilities adds further complexity to an already challenging situation.
The research highlights several critical areas demanding immediate attention. The widespread practice of credential sharing among agents, leading to a significantly higher incidence of security incidents, is particularly alarming. The fact that only 5% fully trust agent evaluations—while two-thirds are actively enabling automated code deployments based on those evaluations—reveals a dangerous disconnect between perceived reliability and actual performance. This echoes the concerns raised in Multi-turn attacks broke AI models 88% of the time — single-turn testing missed it, Cisco AI security lead warns at VB Transform 2026, where even sophisticated models are vulnerable to adaptive adversarial attacks that single-prompt testing routinely misses. These findings emphasize the need for a paradigm shift, moving away from reactive patching and towards proactive, layered security architectures specifically designed for the agentic era. Furthermore, the underutilization of expensive GPU infrastructure and the prevalence of inaccurate agent responses due to poorly governed context layers expose fundamental inefficiencies and quality control issues. It’s not simply about acquiring more hardware; it's about optimizing existing resources and ensuring that agents operate on a foundation of reliable, consistent data.
The rapid churn in vendor selection, with a significant proportion of enterprises planning to switch or add new platforms within the next quarter, suggests a market still in its formative stages. The open question of whether this movement will favor the built-in tools of major AI platforms or specialist vendors remains to be seen, but it underscores the importance of flexibility and interoperability. Enterprises should prioritize solutions that seamlessly integrate with existing systems and provide granular control over agent behavior, rather than locking themselves into proprietary ecosystems. This requires a clear understanding of the specific use cases and requirements, coupled with a willingness to experiment and adapt as the technology evolves. The focus should be on building a robust and scalable control plane that can accommodate the diverse range of agents and applications within an organization.
Ultimately, the VentureBeat Research serves as a vital wake-up call. The initial excitement surrounding AI agents must be tempered with a pragmatic recognition of the inherent risks and the essential need for responsible governance. As AI agents become increasingly integrated into critical business processes, the ability to trust their actions—and to understand the cost and context behind those actions—will be paramount. The question now is not whether enterprises will invest in agent governance, but how quickly and effectively they can build the necessary controls to unlock the full potential of this transformative technology while mitigating the associated risks.
Enterprises deployed AI agents ahead of the controls needed to manage them — and they did it knowingly. That is the central finding across the five parallel surveys VentureBeat Research fielded in June, spanning every layer of the agentic stack. Now those enterprises are retrofitting to catch up with their own standards, and they are budgeting for it: In each of the five control layers we measured, 57 to 68% of enterprises plan to switch vendors or add new ones within 12 months, and roughly a third, depending on the layer, plan to move within the quarter.
VentureBeat Research measured the five controls an enterprise has to build before it can trust an agent: identity, evaluation, cost telemetry, the context layer, and orchestration. Identity governs which agent is allowed to do what, under whose credentials. Evaluation determines whether the agent's work is any good. Cost telemetry tracks what each agent costs to run. The context layer supplies the business data and definitions agents draw on when they answer. And the orchestration control plane coordinates multi-step agent work. Each of our five reports measures one of those controls.
Most deployed "agents" are chatbots wearing the label. Seventy-one percent of enterprises said a quarter or fewer of their deployed "agents" can complete multi-step work on their own; only 10% said true agents are the majority of what they run. These respondents are positioned to know: 81% recommend or decide AI purchases at their companies. A single-prompt chatbot with a human reading every answer needs none of the controls the other four reports measure. A true multi-step agent needs all of them — and most enterprises can't say which one they've deployed. (Full findings: Agentic Orchestration report.)
Autonomy is outrunning trust in the evaluations that gate it. Two-thirds of enterprises either already allow an agent to push a code or system change to production on automated evaluation results alone, with no human review, or are actively engineering toward that within 12 months. Only 5% fully trust the evaluations that would make that call — and half of enterprises shipped an agent that passed internal evaluations and then caused a customer-facing failure in the past year. Before removing human review from any workflow, test evaluations against production outcomes rather than internal benchmarks. (Full findings: Agent Reliability & Evals report.)
Companies that let agents share credentials get hit more often. Sixty-nine percent of companies let at least some of their agents share credentials — multiple agents operating under one API key or service account. Organizations that allow credential sharing anywhere experienced a security incident or near-miss at a 63.5% rate (47 of 74), against 40.9% (nine of 22) at companies where every agent has its own scoped identity. The fix is scoped identity for every agent, starting with the ones that touch production systems. (Full findings: Agentic Security & Identity report.)
The most expensive hardware in the building runs at half capacity or less. More than eight in 10 enterprises that run their own GPUs reported utilization of 50% or less, and only 44% rigorously track what their AI compute actually costs and returns. The number worth chasing first isn't more GPUs — it's the utilization and per-workload cost of the ones already running. (Full findings: AI Infrastructure & Compute report.)
Agents answer confidently from data nobody governs. Fifty-seven percent of enterprises traced a confident, wrong agent answer in the past six months to their own missing or inconsistent business context — wrong metrics, stale definitions, absent documents — and most saw it happen more than once. Governing the definitions agents answer from — metrics and entities first — has to come before scaling the agents that depend on them. (Full findings: Context Layers / RAG report.)
No layer has an entrenched incumbent: The defaults today are the built-in tools that ship with the big AI platforms enterprises already use. Switching intent runs highest in orchestration itself, where 68% plan to adopt, add, or replace platforms within 12 months and 34% within the quarter. Our surveys did not ask which direction that money moves — toward the platforms' built-in tools or toward the specialists challenging them — and that open question is the next four quarters of this market.
About this research
VentureBeat Research fielded five parallel surveys in June 2026 under its VB Pulse program: Agentic Orchestration (101 respondents), Agent Reliability & Evals (157), Agentic Security & Identity (107), AI Infrastructure & Compute (107), and Context Layers / RAG (101) — 573 qualified respondents in total, all at organizations with 100 or more employees. Samples are self-selected, and some findings should be read directionally; each report carries its full methodology note. What the pattern supports more strongly than any single percentage is the direction: every survey, independently, points the same way. VentureBeat produces both this research and VB Transform, the conference where these reports debuted.
Read on the original site
Open the publisher's page for the full experience