VentureBeat Research: Where enterprise AI agent governance hasn't caught up
VentureBeat Research found that enterprises have deployed AI agents without adequate controls, with 57 to 68% planning to switch vendors or add new ones within 12 months to catch up. The research identified five control layers: identity, evaluation, cost telemetry, context layer, and orchestration, with most enterprises lacking these controls. Only 10% of enterprises reported that true agents, capable of multi-step work, are the majority of what they run. The practical implication for engineers building AI systems is to prioritize the development of these control layers to ensure trust and reliability in AI agents.
⚡ Key Takeaways
- 71% of enterprises said a quarter or fewer of their deployed "agents" can complete multi-step work on their own.
- 57 to 68% of enterprises plan to switch vendors or add new ones within 12 months to improve control layers.
- 63.5% of companies that allow credential sharing experienced a security incident or near-miss, compared to 40.9% of companies with scoped identity.
- 44% of enterprises rigorously track what their AI compute actually costs and returns.
- Only 5% of enterprises fully trust the evaluations that gate autonomy.
The lack of control layers in AI agent deployment poses significant risks to enterprises, including security incidents and unreliable autonomy. Engineers building AI systems must prioritize the development of these control layers to ensure trust and reliability in AI agents.
✅ Practical Steps
- Implement scoped identity for every agent, starting with those that touch production systems.
- Test evaluations against production outcomes rather than internal benchmarks before removing human review from workflows.
- Prioritize the development of control layers, including identity, evaluation, cost telemetry, context layer, and orchestration.
Want the full story? Read the original article.
Read on VentureBeat AI ↗