25 Jul 2026, Sat

Enterprises Deployed AI Agents Ahead of Necessary Controls, Knowingly Admitting a Need to Retrofit and Re-Budget.

In a significant revelation underscoring the rapid, often unbridled, adoption of artificial intelligence within the corporate landscape, a comprehensive suite of five parallel surveys conducted by VentureBeat Research in June has unearthed a critical and widespread organizational blind spot: enterprises have enthusiastically deployed AI agents without first establishing the foundational controls required to effectively manage them. This was not an accidental oversight, but a deliberate, albeit risky, strategic decision, as a substantial majority of respondents acknowledged. The immediate consequence is a pressing need for these same organizations to retroactively implement these essential governance structures, a process that is already prompting significant budgetary adjustments and vendor re-evaluations. The data reveals a clear intent to rectify this imbalance, with a substantial percentage of enterprises – ranging from 57% to 68% across the five measured control layers – planning to switch vendors or introduce new solutions within the next twelve months. Furthermore, a significant minority, approximately one-third of respondents depending on the specific control layer, intend to make these crucial changes within the next quarter, signaling an urgent drive to catch up with their own self-imposed technological advancements.

VentureBeat Research meticulously examined five critical control layers that enterprises must establish before they can confidently entrust AI agents with operational responsibilities. These layers are: identity, evaluation, cost telemetry, the context layer, and orchestration. Identity management is paramount, defining precisely which agent is authorized to perform specific tasks and under whose credentials it operates, thereby preventing unauthorized access and actions. Evaluation mechanisms are crucial for determining the quality and accuracy of an agent’s output, ensuring that its work meets established standards and business objectives. Cost telemetry provides indispensable visibility into the financial expenditure associated with each agent’s operation, allowing for resource optimization and budget adherence. The context layer serves as the intelligent reservoir of business data, definitions, and knowledge that agents draw upon to formulate their responses and execute their tasks, ensuring relevance and accuracy. Finally, orchestration acts as the central control plane, coordinating complex, multi-step agent workflows and ensuring seamless collaboration between different AI entities. Each of the five distinct reports generated by VentureBeat Research delves deeply into one of these critical control domains, offering a granular understanding of the current state of enterprise AI governance.

A particularly striking finding from the research, detailed in the Agentic Orchestration report, is the widespread mislabeling of AI deployments. A staggering 71% of enterprises indicated that a mere quarter or less of their deployed "agents" possess the capability to independently complete multi-step tasks. Conversely, only a meager 10% reported that true, autonomous agents constitute the majority of their AI implementations. This perception is informed by the individuals making purchasing decisions, as 81% of respondents either recommend or have the final say in AI-related acquisitions within their organizations. The implication here is profound: many of the systems currently branded as "agents" are, in reality, sophisticated chatbots. A simple, single-prompt chatbot that requires human oversight for every generated answer necessitates none of the sophisticated control mechanisms required by more advanced AI systems. In contrast, a genuine multi-step agent, capable of independent reasoning and complex task execution, demands the full spectrum of controls. The research highlights a significant disconnect, as most enterprises struggle to accurately identify which type of AI agent they have actually deployed, leading to a potentially dangerous overestimation of their AI capabilities and a corresponding underestimation of their governance needs.

The research on Agent Reliability & Evals further illuminates a troubling trend where the pursuit of AI autonomy is outpacing the development of trustworthy evaluation mechanisms. The findings indicate that a significant two-thirds of enterprises have either already granted AI agents the authority to push code or system changes directly into production based solely on automated evaluation results, bypassing human review, or are actively developing systems to enable this within the next year. This is occurring despite the fact that only 5% of these organizations fully trust the automated evaluations that would gate such critical changes. The stark reality of this disconnect is further emphasized by the fact that half of all surveyed enterprises have experienced an agent that, despite passing internal evaluations, subsequently caused a customer-facing failure within the past year. This underscores a critical need for a paradigm shift in how AI performance is assessed. Before relinquishing human oversight from any workflow, it is imperative to rigorously test AI evaluations against real-world production outcomes, rather than relying solely on internal benchmarks. This proactive approach is essential to bridge the gap between simulated performance and actual operational reliability, safeguarding against potentially catastrophic failures.

The Agentic Security & Identity report shines a spotlight on the inherent risks associated with allowing AI agents to share credentials. The findings are stark: 69% of companies permit at least some of their AI agents to operate using shared credentials, meaning multiple agents are functioning under a single API key or service account. Organizations that have adopted this practice are significantly more vulnerable, experiencing security incidents or near-misses at a rate of 63.5% (47 out of 74 companies), compared to 40.9% (nine out of 22 companies) where each agent is assigned its own distinct and scoped identity. This demonstrates a clear correlation between credential sharing and increased security exposure. The most effective remediation strategy, as highlighted by the research, is the implementation of scoped identity for every individual AI agent. This granular approach to access control, particularly prioritizing agents that interact with production systems, is a non-negotiable step towards bolstering AI security and mitigating the risk of widespread compromise. The principle of least privilege, extended to AI agents, is crucial for containing the blast radius of any potential security breach.

The AI Infrastructure & Compute report reveals a significant underutilization of valuable computational resources. More than 80% of enterprises that operate their own Graphics Processing Units (GPUs), the backbone of intensive AI processing, report a utilization rate of 50% or less. This means that a substantial portion of this expensive hardware is sitting idle, representing a significant financial drain and missed opportunity. Compounding this issue, only 44% of organizations rigorously track the actual cost and return on investment of their AI compute workloads. The research strongly suggests that the immediate priority for these companies should not be the acquisition of more GPUs, but rather a focused effort on optimizing the utilization of their existing hardware and gaining a clear understanding of the per-workload cost. Without this fundamental understanding of efficiency and cost-effectiveness, further investment in infrastructure risks exacerbating the problem of underutilized and expensive assets.

The Context Layers / RAG report uncovers a concerning trend where AI agents are confidently dispensing answers derived from ungoverned and often unreliable data. A substantial 57% of enterprises have traced confident, yet incorrect, agent responses within the past six months directly to their own deficiencies in business context, such as missing or inconsistent metrics, outdated definitions, or absent critical documents. alarmingly, most organizations have experienced this phenomenon more than once. This highlights a fundamental gap in data governance: the definitions and data sources that agents rely on must be meticulously governed and maintained before scaling the deployment of the agents themselves. Prioritizing the establishment of clear, authoritative definitions for key metrics and business entities is a prerequisite for building trustworthy AI systems. Without a solid foundation of governed data, even the most advanced agents are prone to generating erroneous outputs, eroding user trust and potentially leading to poor business decisions.

Across all five control layers examined, the research indicates a distinct lack of entrenched incumbents. The current default solutions are largely the built-in tools that are bundled with the major AI platforms that enterprises are already utilizing. However, the desire for more specialized and robust solutions is palpable, with the highest intent to switch or augment existing platforms observed in the realm of orchestration. In this critical area, 68% of enterprises plan to adopt, add, or replace platforms within the next twelve months, and a significant 34% intend to do so within the next quarter. The VentureBeat surveys did not delve into the specific direction of this market shift – whether enterprises are leaning towards the proprietary offerings of the major AI platforms or towards the specialized solutions being developed by independent vendors. This open question represents a significant area of market evolution that will likely define the competitive landscape over the next four quarters.

About this research:

VentureBeat Research, as part of its VB Pulse program, conducted five parallel surveys in June 2026. These surveys covered Agentic Orchestration (101 respondents), Agent Reliability & Evals (157), Agentic Security & Identity (107), AI Infrastructure & Compute (107), and Context Layers / RAG (101). In total, 573 qualified respondents participated, all representing organizations with 100 or more employees. It is important to note that these samples are self-selected, and some of the findings should be interpreted directionally. Each individual report contains a full methodology note. The overarching pattern, more compelling than any single percentage, points to a consistent direction: every survey, analyzed independently, reinforces the same critical message. VentureBeat is the producer of this research and also hosts VB Transform, the premier conference where these comprehensive reports were initially unveiled, providing a platform for industry leaders to discuss and address these pivotal findings.

By admin

Leave a Reply

Your email address will not be published. Required fields are marked *