AI agents get leash, lifeguard as oversight tightens

Venture Beat

The gist

Enterprises are slamming the brakes on unchecked AI agents, pivoting to 'bounded agency' and real-time human oversight after costly failures exposed gaping holes in governance.

What to know

  • By early 2026, 42% of enterprises still lacked formal data governance, missing revenue targets while unified-data organizations saw up to 96% forecast accuracy and 398% ROI.
  • Despite 41% of organizations using agentic AI daily, only 27% have mature governance in place, forcing companies to build adaptive, always-on oversight beyond what standards like the NIST AI RMF or EU AI Act cover.
  • Integrated platforms like AvePoint Confidence and Snowflake’s Project SnowWork now enable real-time policy enforcement and scalable security, as industry giants like Toyota and United Rentals demand compliant, reproducible AI workflows.

AI Agents Hit Reality Check

Enterprise AI deployments stalled as reliability, legacy workflows, and security failures forced companies to tightly supervise agents and overhaul foundational assumptions about risk and control.

By late 2025, even AI powerhouses like Google Cloud and Replit grappled with deploying AI agents reliably, primarily due to legacy workflows and fragmented data that clashed with immature governance models. Mike Clark of Google Cloud highlighted a fundamental cultural mismatch: AI agents operate probabilistically, whereas traditional enterprises are built around deterministic processes, necessitating a profound organizational shift to accommodate AI’s inherent uncertainty.

Reliability issues, rather than AI intelligence itself, emerged as the critical bottleneck in early deployments. Amjad Masad, Replit’s CEO, pointed out that AI agents frequently fail during extended runs or when confronted with poor data quality, underscoring the challenge of compound errors in multi-step tasks that drastically reduce success rates. Consequently, 2025 was characterized more by heavily supervised, narrow prototypes than full-scale autonomous adoption, reflecting a cautious experimental phase.

Security paradigms required a radical rethink as traditional perimeter-based models proved inadequate for AI agents needing broad resource access. Mike Clark questioned the viability of least privilege in a ‘pasture-less defenseless world,’ emphasizing the complexity of safeguarding AI operations. Complementing this, Replit’s major incident—where an AI coder wiped a company’s code base—exposed the immaturity of development tools and the necessity for resource-intensive practices like testing-in-the-loop, verifiable execution, and isolating development from production environments.

By early 2026, enterprises favored pragmatic approaches to governance and deployment, opting for stability over perfection by using off-the-shelf models with robust guardrails rather than bespoke, complex solutions. This led to a preference for ‘bounded agency’—AI agents performing limited tasks under human supervision—to mitigate risks from unpredictable outputs and compound errors. Manual checks remained essential due to immature automated testing frameworks, reinforcing the need to keep humans in the loop to ensure reliability and error correction.

Sources
Venture BeatGradient Flow

Governance Gaps Exposed

Despite widespread AI adoption, most organizations operated without mature oversight, resulting in costly mistakes and highlighting the urgent need for proactive, context-driven governance beyond regulatory checklists.

By early 2026, enterprises have recognized that effective AI governance hinges on robust data governance frameworks and strategic IT leadership. Clari Labs’ January 2026 survey revealed that 42% of enterprises lacked formal data governance, contributing to missed revenue targets despite heavy AI investments, while organizations with unified, governed data achieved up to 96% forecast accuracy and a 398% ROI. Reflecting this shift, 64% of revenue leaders reported CIO teams leading AI tool selection, underscoring the move toward integrated governance models that emphasize contextualized, trusted data as essential for AI-driven predictability, as Clari CEO Steve Cox emphasized: “AI doesn't just need data; it needs context.”

Despite growing adoption of agentic AI—used daily by 41% of organizations—governance frameworks remain immature, with only 27% reporting mature oversight capabilities, highlighting a critical lag in operational controls. This gap is starkly illustrated by incidents like autonomous robotaxis blocking emergency vehicles during a San Francisco outage, demonstrating that systems operating “as designed” can still cause real-world harm without proper human-in-the-loop governance. Analysts stress that effective governance must clearly define responsibility, oversight, and human intervention points to prevent accountability gaps, moving beyond corrective post-action reviews to proactive supervisory controls.

The enterprise AI governance landscape in early 2026 is marked by a pronounced gap in frameworks addressing agentic AI’s unique risks, as leading standards like NIST AI RMF, ISO 42001, and the EU AI Act notably omit any mention of autonomous agents. This disconnect stems from outdated, bureaucratically slow standards development and a divide between framework authors and technical practitioners. Consequently, 63% of organizations lack AI governance policies, and 97% have experienced AI-related security incidents, underscoring the urgent need for organizations to proactively develop adaptive governance models that incorporate agent autonomy, multi-agent interactions, and continuous runtime monitoring rather than relying on incomplete external standards.

Innovative governance frameworks and operational controls are emerging to meet the scale and complexity of agentic AI risks, exemplified by platforms like AvePoint’s Confidence Platform and Vijil’s adaptive trust system, which embed AI-driven oversight, continuous behavioral monitoring, and human verification workflows into the AI lifecycle. Open source initiatives such as Galileo’s Agent Control further enable enterprises to centrally enforce behavioral policies across diverse AI agents, addressing trust, scalability, and real-time policy updates. Complementing these technological advances, phased governance adoption models—progressing from shadow mode to full autonomy—allow organizations to empirically build trust and accountability, transforming governance from a reactive compliance exercise into a strategic competitive advantage.

Sources
Business WireTech XploreResilient CyberGlobeNewswire - Industry News on TechnologyBusiness WireGlobeNewswire - Industry News on Technology

Vendor Sprawl Spurs Integration Race

Fragmented data and AI vendor ecosystems drove enterprises to consolidate on unified platforms, prioritizing governance, observability, and operational safeguards to achieve scalable, production-grade AI.

By early 2026, enterprises grappled with managing an average of seven data vendors and eight to nine AI vendors, creating significant complexity that threatened AI ROI and scalability. Despite over half of data leaders (52%) believing multiple vendors improve data trust, this fragmentation often backfired, increasing costs and security risks. Consequently, organizations favored integrated platform models that build on familiar analytics and BI frameworks, consolidating cataloging, quality, privacy, and access management to streamline governance and reduce operational friction.

Responding to this complexity, vendors like AvePoint expanded their Confidence Platform in early 2026 to unify agentic AI governance with multi-SaaS, IaaS, and PaaS data protection, covering ecosystems from Microsoft to Salesforce. This integration enables organizations to define risk, monitor AI agents’ security posture, and remediate threats within a single platform, reflecting AvePoint’s mission to deliver rapid, scalable data protection to over 25,000 customers and simplifying governance across sprawling cloud environments.

The rapid rise of agentic AI workflows has shifted the competitive landscape from a feature race to an infrastructure race, with 94% of developers willing to switch vendors for more scalable, compliant platforms. As 67% already deploy agentic workflows and 85% anticipate AI agents becoming essential within three years, enterprises prioritize reliability, observability, and governance controls—such as permissioning, approvals, and audit logs—to move beyond demos to production-ready AI agents, emphasizing narrow, predictable UI paths and robust operational safeguards against automation drift and data corruption.

Innovations like the Cohesity-ServiceNow partnership and Galileo’s open source Agent Control platform exemplify the industry’s push toward integrated governance and resilience at scale. Cohesity and ServiceNow’s real-time recovery solution embeds immutable data protection and auditability into AI agent operations, setting a new standard for responsible deployment. Meanwhile, Galileo’s vendor-neutral control plane enables centralized policy enforcement across diverse AI agents, with major players such as Strands Agents, CrewAI, Glean, and Cisco AI Defense adopting it to simplify governance, enhance trust, and enable real-time policy updates—crucial as enterprise AI agent adoption accelerates.

Sources
Bernard MarrGlobeNewswire - Industry News on TechnologyBusiness WireLinear: A Vertical Software & Vertical AI NewsletterBusiness WireGlobeNewswire - Industry News on Technology

Sector-Specific Guardrails Emerge

Industries like healthcare, science, and supply chain are building tailored AI governance and monitoring to address unique risks, moving from isolated pilots to trusted, compliant workflows at scale.

By early 2026, industry-specific AI governance has become critical to unlocking advanced use cases across sectors such as scientific research, healthcare, and supply chain management. DataJoint’s February launch of the Agentic AI platform exemplifies this trend by enabling reproducible, provenance-rich AI workflows in regulated scientific R&D environments, already adopted by leading academic medical centers and pharma companies to reduce operational and regulatory risks. Meanwhile, healthcare providers like Wolters Kluwer embed trusted AI layers within clinical tools to mitigate hallucination risks, and Singulr AI’s Agent Pulse platform offers real-time monitoring of AI agent behavior to enforce compliance, highlighting a growing emphasis on safety and governance tailored to sector-specific challenges.

Supply chain AI adoption reveals a cautionary tale where initial successes in narrow use cases, such as invoice matching or risk monitoring, often stall due to fragmented architectures and siloed governance models. As analyses from March 2026 show, isolated AI agents with channel-specific logic create conflicting decisions and governance headaches, underscoring the necessity of foundational architectures that unify workflows, decision logic, and compliance guardrails. Snowflake’s Project SnowWork illustrates this approach by consolidating fragmented data sources into a governed, trusted AI interface, enabling enterprises like Toyota Motors and United Rentals to scale AI-driven productivity and insights reliably across distributed operations.

In procurement, AI adoption is evolving from cautious pilots to strategic enablers that automate routine tasks while exposing deeper organizational challenges. Leaders like John Eustis of Toray Industries advocate incremental AI deployment to manage costs, with agents handling specific tasks such as supplier pallet design reviews to save time. However, experts like Mario González warn that AI will reveal how much procurement still relies on process over judgment, necessitating redesigns of decision rights and accountability. This sector-specific adoption also grapples with foundational data quality, exception ownership, and security concerns, especially in regulated industries, as highlighted by SAP Ariba’s Rabih Suleiman and procurement specialists emphasizing the risks of AI hallucinations and data sensitivity.

The procurement function is undergoing a profound transformation driven by AI’s ability to integrate diverse data sources for dynamic demand forecasting, real-time supplier risk monitoring, and strategic sourcing automation. This shift from reactive, transactional operations to proactive, data-driven strategy is supported by investments in unified data pipelines and collaborative supplier partnerships that enhance resilience and sustainability. Boston Consulting Group reports AI can reduce procurement costs by up to 45% and workload by 30%, while market surveys reveal sustained executive prioritization of AI-driven analytics despite recent dips in usage. Nonetheless, cybersecurity remains a significant barrier, with 34% of leaders expressing concern, underscoring the ongoing need for robust governance frameworks to secure AI’s strategic value.

Sources
PR Newswire - Consumer TechnologyThoughts on Healthcare Markets and TechnologyLa SupplyThe ChainNew York Stock ExchangeYahoo Finance

Trust Through Human-in-the-Loop

Legal risks and high-profile failures pushed enterprises to embed mandatory human review, real-time audit loops, and adaptive oversight directly into AI production pipelines to ensure accountability.

By early 2026, enterprises recognized that transitioning AI from pilot phases to production-ready systems demanded embedding trust and accountability through human verification and comprehensive governance workflows. As highlighted in the January 2026 analysis, organizations were instituting mandatory human review of AI outputs—treating AI like an intern whose work must be checked—to address the growing legal liabilities exemplified by cases such as Air Canada’s loss in court. This approach was complemented by rigorous audit trails logging prompts, permissions, and approvals, creating a legal defense framework and closing the accountability void posed by autonomous AI agents.

The governance paradigm shifted dramatically from periodic compliance checks to a continuous, real-time 'audit loop' by February 2026, integrating drift detectors, shadow mode rollouts, and real-time alerts directly into AI production workflows. Morgan Lewis emphasized shadow mode as a critical safety net allowing new models to run in parallel without impacting live decisions until validated, while compliance teams evolved into AI co-pilots, nudging and intervening early to maintain trust without stifling innovation. This continuous monitoring ethos was exemplified by Treasure Data’s multi-tier pipeline combining AI-driven code review, automated testing, and human oversight, ensuring rapid detection and response to deviations.

Advancements in AI governance platforms like Causum’s Mars® and Vijil’s adaptive trust evaluation system marked a leap toward embedding governance directly into enterprise workflows by early 2026. Mars® formalizes AI decisions using ontologically structured knowledge graphs to enforce organizational rules pre-execution, while Vijil’s platform reduces time-to-trust from months to minutes by continuously evaluating agent behavior, enforcing policies, and proposing improvements. These innovations empower governance, security, and compliance teams to set and monitor standards throughout the AI lifecycle, reflecting a broader industry shift toward operationalizing trust as a continuous, embedded process rather than a static checkpoint.

By mid-2026, production AI maturity was understood as a phased governance journey progressing from shadow mode to bounded autonomy, with trust and auditability engineered through deliberate architectural design rather than raw model capability. Snowflake’s Project SnowWork demonstrated this by integrating accuracy and governance to reduce complex workflows from weeks to minutes across thousands of customers, including United Rentals’ deployment at 1,600 branches. Meanwhile, partnerships like Cohesity and ServiceNow advanced real-time recovery and resilience, embedding incident response and continuous monitoring into AI workflows. Experts like Hemant Kashyap and Nick Heddy underscored that AI agents must be managed like employees—with clear permissions, escalation paths, and cost controls—to maintain consistent, trustworthy outcomes over time.

Sources
TechnocraticBehind Product LinesVenture BeatVenture BeatPR Newswire - Consumer TechnologyBusiness Wire

Governance Becomes a Boardroom Imperative

With standards lagging, enterprises are embedding governance into business strategy and infrastructure, making operational trust, compliance, and resilient architectures central to competitive advantage in the agentic AI era.

By early 2026, the enterprise AI landscape is undergoing a pivotal transformation where governance is no longer confined to IT silos but has ascended to the boardroom, reflecting its strategic importance in scaling autonomous systems with trust and accountability. HCLSoftware’s XDO blueprint exemplifies this shift by integrating experience, data, and operations into a unified governance framework that treats autonomy as an intelligent, accountable, and sovereign system property. This governance-by-design approach, emphasized as critical alongside innovation, positions proactive governance, talent development, and architectural foundations as essential competitive differentiators for enterprises aiming to operationalize self-driving enterprises confidently over the next 24 to 36 months.

Despite the emergence of promising technical initiatives like NIST’s RFI on securing agentic AI and OWASP’s Agentic AI Top 10, existing standards and compliance frameworks lag significantly behind the rapid evolution of agentic AI technologies. This gap compels organizations to take the helm in developing adaptive, internally grounded governance frameworks rather than relying on incomplete or 'bolted on' external standards. As noted, waiting for formal guidance risks managing outdated risks while agentic AI systems operate unchecked, making it imperative for enterprises to 'build the plane while flying it' by embedding governance into people, processes, and technology to sustain both regulatory compliance and competitive advantage.

The competitive AI infrastructure market is rapidly realigning around vendors that deliver scalable, production-ready, and well-governed agentic AI platforms, as evidenced by 94% of developers willing to switch providers for better compliance and reliability. Strategic partnerships such as H2O.ai with CTC Global Singapore and Stelia AI with Nokia underscore this trend by combining governance, explainability, and security with flexible deployment options tailored for regulated industries like financial services and manufacturing. These collaborations not only accelerate enterprise AI adoption across regions like APAC but also highlight governance as a core enabler of operational resilience, auditability, and measurable business outcomes in the agentic AI era.

Emerging frontier AI models like Anthropic’s Mythos and OpenAI’s GPT 5.4 cyber model have exposed critical vulnerabilities across enterprise supply chains, revealing that traditional vendor risk management practices are insufficient in the face of real-time, AI-driven threat detection. The interconnectedness of modern enterprises means that a single vendor’s delayed patch or misconfiguration can cascade into systemic risks, exemplified by Microsoft’s April 2026 patch addressing over 167 vulnerabilities. In response, firms are increasingly adopting strategic partnerships and managed services to enable scalable, end-to-end third-party risk management (TPRM), integrating AI-driven automation and intelligent workflows to enhance governance, with a growing emphasis on robust data governance and expanded visibility into Nth-party relationships to manage deeper supply chain exposures.

Sources
PR Newswire - Consumer TechnologyResilient CyberResilient CyberBusiness WireBusiness WireBusiness Wire

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.