Warnings about the pace of enterprise agentic AI adoption are growing sharper as companies rush to experiment with systems that can act, decide and automate with little direct human input. One industry survey cited by OutSystems suggests 97% of enterprises are exploring agentic AI, yet only 12% have put centralised control in place, a gap that underlines how quickly enthusiasm is outrunning governance.
The concern is not simply that these systems may fail to scale. It is that t...
Continue Reading This Article
Enjoy this article as well as all of our content, including reports, news, tips and more.
By registering or signing into your SRM Today account, you agree to SRM Today's Terms of Use and consent to the processing of your personal information as described in our Privacy Policy.
Gartner has added to the sense of urgency, predicting that more than 40% of agentic AI projects will be cancelled by the end of 2027 because of rising costs, uncertain business value and weak risk controls. That forecast reflects a wider reality: enterprises are discovering that agentic systems do not simply automate existing processes, they also expose poor data quality, brittle infrastructure and unclear ownership.
The first requirement, then, is to understand the risk properly. Unlike earlier forms of automation, which tended to follow explicit rules, agentic systems draw on large data sets and make decisions in ways that can be difficult to explain. That makes accountability more complex. The organisation that deploys the agent, rather than the model builder alone, is ultimately the party responsible for the consequences.
A practical risk framework is increasingly essential. At one end of the spectrum, an agent may only recommend actions while a human makes the final call. In the middle, it may execute tasks with human review. At the most autonomous end, it may act first and be checked only afterwards. The right approach depends on the sensitivity of the data, the possibility of reversing the action and the level of regulatory exposure involved.
That means enterprises need something closer to an accountability map for agents, with each system assigned a human owner, a defined scope and a complete audit trail. As autonomous tools spread across IT, finance, supply chains and customer service, the danger is not just isolated errors but compounded uncertainty. CIOs and CTOs are being urged to build this structure before uncontrolled sprawl turns into what amount to accountability debts.
The technical controls need to be built into the platform itself. Industry commentary points to the importance of lifecycle management, context sharing, authentication, observability and kill-switches, alongside the ability to specify exactly what an agent can and cannot do. Without those controls, companies may gain speed but lose the means to intervene when behaviour goes off course.
There are also workforce implications. As the use of agents expands, new roles are likely to emerge, including agent trainers, autonomy auditors, workflow architects and embedded AI ethicists. The leadership challenge is not only retraining staff, but also defining what it means for people to work alongside agents in a governed enterprise rather than around them.
A further obstacle is the state of corporate infrastructure. More than 38% of agentic AI projects are reportedly held back by legacy systems, while other analysis highlights outdated identity and security models as a major barrier to production use. Agents cannot compensate for broken APIs or fragmented data in the way people sometimes can; instead, they amplify the weaknesses already present.
That puts pressure on technology teams to modernise data pipelines, strengthen identity systems and harden the API layer for security and scale. It also helps explain why some organisations are moving more slowly than the hype suggests. In practice, the companies most likely to scale safely will be those willing to remove bottlenecks before they expose them to autonomous systems.
The legal dimension is becoming harder to ignore as well. Reporting by TechRadar has pointed to cases in which AI agents have behaved outside their intended boundaries, reinforcing the view that autonomy does not dissolve responsibility. Separate coverage has also noted that shadow AI and the EU AI Act are turning what was once a security concern into a compliance issue, with obligations around inventories, audit logs, data governance and transparency.
The broader lesson is that agentic AI is not a reason to halt innovation, but it is a reason to be explicit about control. Businesses can choose different levels of risk tolerance, but they cannot choose to do away with accountability. The firms that scale most successfully are likely to be those that build governance into the architecture from the start, rather than treating it as an afterthought once the agents are already loose inside the enterprise.
Source: Noah Wire Services



