VentureBeat Research: Where enterprise AI agent governance hasn't caught up
Essential brief
VentureBeat Research's June 2026 surveys reveal that enterprises have deployed AI agents ahead of establishing adequate governance controls, doing so knowingly. Across five key control layers—ident
Key topics
Key facts
Highlights
Why it matters
The research highlights a critical gap between AI agent deployment and governance in enterprises, underscoring risks related to security, reliability, and operational costs. As organizations retrofit controls and reconsider vendor relationships, the findings emphasize the importance of establishing robust identity, evaluation, and context management to ensure trustworthy and efficient AI agent operations. This has broader implications for AI adoption strategies and risk management in enterprise environments.
VentureBeat Research conducted five parallel surveys in June 2026 to assess enterprise governance of AI agents across five control layers: identity, evaluation, cost telemetry, context, and orchestration. The findings show that enterprises have deployed AI agents before implementing sufficient controls, and they are now actively working to catch up. Between 57% and 68% of enterprises plan to switch or add vendors within the next year to improve governance, with about one-third intending to make changes within the next quarter.
The five control layers serve distinct functions: identity controls which agents can perform actions under specific credentials; evaluation assesses the quality of agent outputs; cost telemetry monitors operational expenses; the context layer provides business data and definitions for agent responses; and orchestration manages multi-step agent workflows. Despite widespread use of chatbots labeled as agents, 71% of enterprises report that only a quarter or fewer of their agents can complete multi-step tasks autonomously, and just 10% say true multi-step agents constitute the majority of their deployments.
Autonomy is advancing faster than trust in evaluation mechanisms. Two-thirds of enterprises either already allow agents to push code or system changes to production based solely on automated evaluations or plan to do so within 12 months. However, only 5% fully trust these evaluations, and half reported incidents where agents passed internal evaluations but caused customer-facing failures in the past year.
Security concerns arise from credential sharing among agents. Sixty-nine percent of companies permit some agents to share credentials, which correlates with a 63.5% rate of security incidents or near-misses, compared to 40.9% at companies enforcing scoped identities for each agent. Implementing scoped identities, especially for agents interacting with production systems, is recommended to reduce risks.
Regarding infrastructure, over 80% of enterprises running their own GPUs report utilization rates of 50% or less, and only 44% rigorously track AI compute costs and returns. Improving utilization and cost tracking of existing hardware is a priority before investing in additional resources.
Finally, agents often provide confident but incorrect answers due to unmanaged or inconsistent business context. Fifty-seven percent of enterprises traced such errors to missing or outdated business definitions, highlighting the need to govern metrics and entities before scaling agent deployments.
No single vendor dominates any control layer; most enterprises currently rely on built-in tools from major AI platforms. The highest intent to switch vendors is in orchestration, with 68% planning changes within 12 months and 34% within the next quarter. The direction of these vendor shifts remains an open question for the market's near future.
The research involved 573 qualified respondents from organizations with 100 or more employees, across the five surveys: Agentic Orchestration (101), Agent Reliability & Evaluations (157), Agentic Security & Identity (107), AI Infrastructure & Compute (107), and Context Layers / RAG (101). While samples were self-selected and findings should be interpreted directionally, the consistent patterns across surveys indicate a clear trend toward retrofitting AI agent governance.
Key topics in this update include venturebeat research, enterprise ai agent governance hasn, and enterprise ai agent.