Navigating the Gaps in Enterprise AI Agent Governance

As enterprises rapidly adopt AI agents, many find themselves lacking the necessary governance frameworks to manage them effectively. This article explores the critical areas where governance has fallen short and offers insights on how businesses can adapt.

0
Navigating the Gaps in Enterprise AI Agent Governance

The rapid rise of AI agents in enterprise settings has transformed the way businesses operate, enabling automation of tasks that previously required human intervention. However, this swift adoption has often outpaced the governance frameworks necessary to manage these sophisticated tools effectively. A recent study by VentureBeat Research highlights several critical gaps in enterprise AI governance, revealing that many organizations deployed AI agents without the proper controls in place. As these enterprises scramble to retrofit their governance models, understanding the pitfalls and addressing them becomes paramount.

In June 2026, VentureBeat Research conducted five parallel surveys across various layers of the agentic stack, encompassing over 570 qualified respondents from organizations with 100 or more employees. The findings paint a concerning picture: while enterprises are increasingly relying on AI agents, their governance mechanisms have not kept pace, leading to potential risks that could impact performance and security.

Understanding the AI Agent Governance Framework

To comprehend the governance gaps identified in the research, it is essential to first understand the five critical controls that form the foundation of effective AI agent governance:

  • Identity: This control governs which AI agents are allowed to perform specific tasks under certain credentials.
  • Evaluation: This assesses the quality of the work produced by AI agents.
  • Cost Telemetry: This tracks the operational costs associated with each AI agent.
  • Context Layer: This provides the necessary business data and definitions that AI agents rely on to deliver accurate responses.
  • Orchestration: This control coordinates the multi-step tasks that AI agents perform.
AI governance framework

These controls are crucial for ensuring that AI agents operate reliably and securely within an organization. However, the research indicates that a significant number of enterprises are not fully utilizing these controls, particularly when it comes to multi-step agent functionalities.

The State of AI Agent Deployment

A staggering 71% of enterprises revealed that merely a quarter or fewer of their deployed AI agents can perform multi-step tasks autonomously. This suggests that many organizations are relying on basic chatbot functionalities rather than truly autonomous agents capable of sophisticated operations. Furthermore, only 10% of respondents indicated that the majority of their AI agents are, in fact, true agents.

The implication here is significant: as enterprises rush to deploy AI agents, they risk overlooking the fundamental governance frameworks necessary to ensure effective operation. For instance, a single-prompt chatbot requires minimal governance controls, while a true multi-step agent necessitates a comprehensive governance strategy. The lack of clarity regarding the nature of deployed agents only complicates this issue further.

AI chatbots in action

Trust and Autonomy: A Dangerous Imbalance

One of the most alarming findings from the research is that two-thirds of enterprises are allowing AI agents to make critical changes to production systems based solely on automated evaluation results, bypassing human review. Despite this high level of trust in automated evaluations, only 5% of enterprises reported full confidence in these evaluations. Moreover, half of the organizations that allowed AI agents to operate without human oversight experienced failures that impacted customer-facing services.

This highlights a critical gap in trust and control: enterprises are moving toward greater autonomy for AI agents at the expense of rigorous evaluation and oversight. It is vital for businesses to establish a robust framework for testing AI evaluations against real-world production outcomes before eliminating human review from any workflow.

Credential Sharing and Security Risks

The research also revealed that many companies allow AI agents to share credentials, with 69% of organizations permitting at least some credential sharing among agents. This practice exposes enterprises to heightened security risks, as evidenced by the data: organizations that allowed credential sharing experienced security incidents or near-misses at a rate of 63.5%, compared to 40.9% for those that enforced scoped identity for each agent.

To mitigate these risks, businesses should prioritize implementing scoped identities for all AI agents, particularly those interacting with production systems. This approach would help contain potential breaches and enhance overall security posture.

cybersecurity risks with AI

Maximizing AI Infrastructure Utilization

Another concerning finding from the surveys is that over 80% of enterprises operating their own Graphics Processing Units (GPUs) reported utilization rates of 50% or lower. This underutilization signifies wasted resources and missed opportunities for cost efficiency. Only 44% of respondents rigorously tracked the actual costs and returns associated with their AI compute resources.

Instead of investing in more GPUs, organizations should focus on optimizing the utilization of their existing infrastructure. Understanding the per-workload costs and ensuring that AI compute resources are used effectively can lead to significant savings and improved operational efficiency.

Governance of Data Context

Lastly, the research points to a critical issue surrounding the context in which AI agents operate. A significant 57% of enterprises traced incorrect responses from their agents back to missing or inconsistent business context, such as outdated metrics or absent definitions. This underscores the necessity of governing the data and definitions that AI agents rely on to provide accurate outputs.

Before scaling AI agents, businesses must prioritize the establishment of a robust governance framework for the definitions and metrics that guide these agents. This will ensure that AI agents work from a solid foundation of accurate and reliable data.

data governance in enterprises

Key Takeaways

  • Many enterprises are deploying AI agents without adequate governance frameworks.
  • Trusting AI evaluations without human oversight can lead to significant failures.
  • Credential sharing among agents increases security risks.
  • Maximizing existing AI infrastructure utilization is crucial for cost efficiency.
  • Governing the context data used by AI agents is essential for accurate outputs.

Frequently Asked Questions

What are the main governance controls needed for AI agents?

The main governance controls necessary for AI agents include identity management, evaluation processes, cost telemetry, context layers, and orchestration capabilities. Each of these controls plays a crucial role in ensuring that AI agents function effectively and securely within an enterprise.

How can businesses improve their AI agent governance?

Businesses can improve their AI agent governance by prioritizing the implementation of scoped identities for each agent, ensuring rigorous evaluation processes, and establishing a comprehensive context layer. Additionally, organizations should focus on optimizing the utilization of existing AI infrastructure and tracking the costs associated with AI operations to enhance overall efficiency.

Why is human oversight important in AI evaluations?

Human oversight is essential in AI evaluations to prevent potential errors and failures that can arise from automated decision-making. Without rigorous human review, enterprises risk deploying AI agents that produce incorrect outputs or make critical changes without adequate assessment, leading to operational failures and customer dissatisfaction.

What are the risks associated with credential sharing among AI agents?

Credential sharing among AI agents poses significant security risks, as it can lead to unauthorized access and potential breaches. Organizations that permit credential sharing have reported a higher incidence of security incidents, emphasizing the importance of enforcing scoped identities to mitigate these risks effectively.

Comments

Read next

Protecting Your Business from Cl0p Ransomware Attacks: A Guide

The Cl0p ransomware group has recently targeted vulnerabilities in widely-used software, posing a significant threat to businesses. In this article, we delve into the implications of these vulnerabilities and how organizations can bolster their cybersecurity defenses.

Protecting Your Business from Cl0p Ransomware Attacks: A Guide

Related articles