Enterprises adopted AI agents prematurely without the necessary governance controls in place
Enterprise AI is moving faster than enterprise governance. That is the central issue. Many organizations deployed AI agents before they had the controls needed to manage them properly. They understood the risks, but the opportunity to improve productivity and stay competitive was too important to ignore.
The next phase is different. The focus is no longer just on deploying AI. It is about making AI dependable. That requires governance across five critical areas identified by VentureBeat Research: identity, evaluation, cost telemetry, context management, and orchestration. Together, these determine whether an AI agent can operate safely, produce reliable results, control costs, use the right business information, and coordinate complex tasks.
Each of these controls serves a different purpose. Identity determines what an agent is allowed to access and under whose credentials it operates. Evaluation measures whether its outputs are actually correct. Cost telemetry tracks the financial impact of running AI workloads. Context management ensures agents rely on accurate business definitions and data. Orchestration coordinates multiple agents and processes as they work together across systems.
Many organizations are now investing heavily to strengthen these capabilities because they have realized that deploying AI is only the beginning. Long-term value comes from making AI systems reliable enough to support important business operations.
For executives, this changes how AI investments should be evaluated. The question is no longer whether an AI model performs well in a demonstration. The real question is whether the organization has enough visibility, control, and accountability to trust that system in production. Governance should not be viewed as slowing innovation. It is what allows innovation to scale safely across the business.
VentureBeat Research’s June surveys illustrate how widespread this shift has become. Across all five governance layers, between 57% and 68% of enterprises expect to add new vendors or replace existing ones within the next 12 months. Roughly one-third expect changes within the current quarter. This level of planned investment shows that governance has become a strategic priority rather than a compliance exercise.
A significant portion of deployed AI agents are basic chatbots
One of the biggest misconceptions in enterprise AI today is the meaning of the word “agent.” Many products are marketed as AI agents, but in practice they function as traditional chatbots. They answer questions, generate content, or complete a single task before handing control back to a person.
A true AI agent is different. It can complete multiple connected tasks independently, make decisions within defined limits, interact with different systems, and continue working toward an objective without requiring constant human input. That level of autonomy creates much greater business value, but it also creates much greater governance requirements.
This distinction matters because executives often evaluate AI investments based on vendor claims rather than operational capability. A chatbot that generates text is fundamentally different from an autonomous system that updates databases, interacts with customers, manages workflows, or changes production systems. Treating both as the same technology can lead to poor investment decisions and governance gaps.
The VentureBeat Research findings suggest that many enterprises have not yet reached widespread deployment of fully autonomous agents. According to the surveys, 71% of organizations said that no more than one-quarter of their deployed “agents” can complete multi-step work on their own. Only 10% reported that autonomous agents make up the majority of what they currently operate.
This reflects where the technology and enterprise readiness are today. Most organizations are still learning how to manage increasingly autonomous systems before expanding their use across critical business functions.
For business leaders, the practical implication is straightforward. Governance investments should match the actual level of autonomy. Simple chatbot deployments generally require fewer controls because people remain closely involved in reviewing outputs. As organizations introduce agents capable of making independent decisions and executing complex workflows, governance must become significantly more sophisticated. Identity, evaluation, orchestration, business context, and cost management all become essential capabilities rather than optional improvements.
The survey results also carry additional weight because the respondents were directly involved in enterprise AI decisions. According to VentureBeat Research, 81% of participants either recommend or make AI purchasing decisions within their organizations. Their responses provide a useful view of how enterprise AI adoption is evolving beyond marketing language toward operational reality.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.
Autonomous AI is advancing faster than the systems used to evaluate and control it
Many enterprises are becoming comfortable with giving AI agents more responsibility. In some organizations, agents can already push code or make system changes based only on automated evaluation results. Others are actively working toward that level of autonomy within the next year. This is a significant shift in how software and operations are managed.
The challenge is that confidence in evaluation systems has not kept pace with this increased autonomy. An evaluation framework determines whether an AI agent has completed its task correctly before its work is accepted. If that framework cannot accurately predict real-world performance, increasing autonomy also increases operational risk.
VentureBeat Research found that around two-thirds of enterprises either already allow AI agents to push production changes without human review or plan to do so within the next 12 months. Yet only 5% of organizations said they fully trust the evaluation systems making those decisions. That gap deserves executive attention because it means many organizations are expanding automation before validating the controls that support it.
The consequences are already visible. According to the research, half of enterprises experienced at least one customer-facing failure during the past year from an AI agent that had successfully passed internal evaluations. Internal testing alone is not providing enough assurance that an agent will perform reliably under real operating conditions.
Executives should view evaluation as an ongoing business capability rather than a one-time technical test. Evaluation systems need continuous improvement as AI models, business processes, and customer expectations evolve. Production data should be used to measure whether evaluation frameworks accurately predict success outside controlled testing environments.
Organizations also need different levels of evaluation depending on the business function. An internal knowledge assistant does not require the same level of validation as an AI agent that modifies financial records, updates production systems, or makes decisions affecting customers. Governance should reflect the potential business impact of each deployment.
The opportunity remains significant. Greater autonomy can improve speed, reduce repetitive work, and increase operational efficiency. Those benefits become sustainable only when organizations can demonstrate that automated decisions consistently meet business standards. Human oversight can then be reduced gradually as confidence is earned through measurable performance rather than assumptions.
Shared credentials create avoidable security risks for enterprise AI agents
Identity management becomes increasingly important as AI agents gain access to enterprise systems. Every agent should have clearly defined permissions that match its specific responsibilities. Without that discipline, organizations lose visibility into which agent performed which action and whether that action was authorized.
Many enterprises have not yet reached that level of control. Instead, multiple AI agents often operate under the same API key or service account. While this may simplify deployment, it weakens accountability and makes security investigations more difficult. If several agents share identical credentials, security teams cannot easily determine which one initiated a specific action or identify the source of unexpected behavior.
The VentureBeat Research findings show that this remains a common practice. Sixty-nine percent of companies allow at least some AI agents to share credentials. Those organizations reported security incidents or near misses at a rate of 63.5%, representing 47 out of 74 surveyed companies. Among organizations where every agent had its own scoped identity, the rate fell to 40.9%, or 9 out of 22 companies.
Although these survey results show a strong association between credential sharing and higher incident rates, they do not by themselves prove that credential sharing is the sole cause. Other differences in security practices may also contribute. Even so, the findings reinforce a well-established security principle: limiting access and assigning unique identities improves control and accountability.
For executives, identity management should be considered a strategic investment rather than a technical detail. As AI agents begin interacting with customer data, financial systems, software development environments, and operational infrastructure, identity becomes the foundation of governance. Every action should be attributable to a specific agent operating within clearly defined permissions.
This approach also supports regulatory compliance and audit requirements. Many industries increasingly expect organizations to demonstrate who accessed sensitive systems, when access occurred, and what actions were performed. Unique identities for AI agents make those records far more reliable and easier to verify.
Organizations do not need to redesign every AI system immediately. A practical approach is to begin with agents that interact directly with production environments or sensitive business data. Securing those systems first delivers the greatest reduction in operational risk while establishing governance practices that can be expanded as AI adoption grows.
AI infrastructure is underutilized, while many organizations still lack clear visibility into AI costs
Enterprise AI discussions often focus on acquiring more computing power. In many cases, that is not the immediate challenge. The larger opportunity is improving how existing infrastructure is used and understanding the real cost of running AI workloads.
VentureBeat Research found that more than 80% of enterprises operating their own GPUs reported utilization rates of 50% or less. This suggests that a significant amount of expensive computing capacity remains idle or is not being scheduled efficiently. At the same time, only 44% of organizations said they rigorously track the costs and returns of their AI compute resources.
This creates two separate problems. First, organizations may purchase additional hardware before maximizing the value of what they already own. Second, leaders cannot confidently evaluate whether AI initiatives are generating acceptable business returns without reliable cost data.
Cost telemetry addresses this challenge. It provides visibility into how much each AI workload costs to execute, how efficiently computing resources are being used, and whether the resulting business value justifies the investment. This information becomes increasingly important as organizations deploy more AI agents across different departments and business functions.
Executives should expect AI investments to be measured with the same financial discipline applied to other major technology programs. It is no longer enough to know that an AI application performs well. Organizations also need to understand which workloads generate meaningful business outcomes, which consume excessive resources, and where infrastructure can be optimized before additional spending is approved.
Improving utilization often produces faster financial benefits than expanding infrastructure. Better workload scheduling, removing unused capacity, matching workloads to appropriate hardware, and continuously monitoring resource consumption can increase efficiency without requiring new capital investments.
As AI adoption grows, cost visibility will become an important competitive advantage. Organizations that understand the economics of every AI workload will be better positioned to scale successful initiatives, discontinue low-value projects, and allocate computing resources where they create the greatest business impact.
Weak governance of business data is a major cause of inaccurate AI responses
The quality of an AI agent depends heavily on the quality of the information it receives. Even advanced models cannot consistently produce reliable answers when the underlying business data is incomplete, outdated, inconsistent, or poorly managed.
VentureBeat Research identified business context as one of the most common sources of AI errors. According to the surveys, 57% of enterprises traced at least one confident but incorrect AI response during the previous six months to missing or inconsistent business context. Most organizations reported experiencing this problem more than once.
Business context includes the internal information that allows AI systems to understand how an organization operates. This includes definitions of business metrics, customer information, product documentation, internal policies, operational procedures, and other enterprise knowledge. If these sources conflict or are not regularly maintained, AI agents may generate answers that appear accurate while relying on incorrect information.
This is an important distinction for executives. Many AI accuracy problems are not caused by the language model itself. Instead, they originate from weaknesses in enterprise data management. Replacing the model may not solve the underlying issue if the business information remains inconsistent.
The research emphasizes that governance should begin with the information AI systems use most frequently. Standardizing business metrics, maintaining consistent definitions across departments, and ensuring documents remain current can significantly improve AI reliability before organizations expand autonomous workflows.
Organizations should also recognize that data governance is an ongoing business responsibility rather than a one-time technical project. Business policies change, products evolve, regulations are updated, and new information is created every day. AI systems require processes that keep their knowledge sources aligned with these changes if they are expected to deliver dependable results.
For leadership teams, this means AI strategy and data strategy should be developed together. Investments in AI models, automation platforms, and orchestration tools deliver greater value when supported by accurate, governed business information. Reliable data strengthens decision-making, improves customer interactions, and increases confidence as organizations expand the role of AI across the enterprise.
The enterprise AI governance market remains open, giving organizations flexibility to shape their long-term strategy
Enterprise AI governance is still in an early stage of development. Unlike more mature enterprise software markets, there is no single vendor that has established clear leadership across every governance layer. This creates both opportunity and uncertainty for organizations building their long-term AI strategy.
Today, many enterprises rely on governance capabilities that are built into the major AI platforms they already use. These integrated tools offer a practical starting point because they reduce deployment complexity and simplify management. However, as AI deployments become larger and more autonomous, organizations are increasingly evaluating whether those built-in capabilities provide enough flexibility, visibility, and control.
VentureBeat Research found the strongest level of planned change in orchestration, which coordinates how AI agents work together across multiple tasks and systems. According to the surveys, 68% of enterprises plan to adopt, add, or replace orchestration platforms within the next 12 months, while 34% expect to make those changes within the current quarter. This suggests that many organizations are still determining what their long-term governance architecture should look like.
The research also notes an important limitation. It does not identify where this spending will go. Some organizations may expand their use of governance tools provided by large AI platform vendors, while others may choose specialist providers focused on identity, orchestration, evaluation, or observability. That competitive landscape remains unsettled.
For executives, this means vendor selection should focus on long-term capabilities rather than short-term features. AI governance platforms should integrate with existing technology investments, support changing regulatory requirements, and remain flexible as AI models and business needs evolve. Selecting a platform based only on current functionality may create unnecessary migration costs later as enterprise AI matures.
This also reinforces the importance of avoiding unnecessary vendor lock-in. As governance standards continue to develop, organizations benefit from architectures that allow components to be replaced or expanded without requiring major changes across the entire AI environment. Open integration, interoperability, and clear data ownership should be considered alongside performance and cost during procurement decisions.
The next several years are likely to define how enterprise AI governance evolves. Organizations that regularly reassess their governance strategy, validate vendor capabilities against business objectives, and remain adaptable as the market changes will be better positioned to scale AI safely and efficiently. The goal is not simply to choose the right vendor today. It is to build a governance foundation that continues to support innovation as enterprise AI capabilities advance.
The bottom line
Enterprise AI is entering a new phase. The conversation is shifting away from whether organizations should adopt AI and toward how they can operate it responsibly at scale. That shift requires more than better models. It requires stronger governance.
The findings from VentureBeat Research make one point especially clear. The biggest barriers to successful AI deployments are no longer purely technical. They are operational. Identity, evaluation, data quality, infrastructure efficiency, cost visibility, and orchestration have become core business capabilities. Organizations that strengthen these areas will be in a better position to expand AI with confidence, while those that overlook them will face increasing operational, security, and financial risks.
For executives, this is an opportunity to move beyond isolated AI projects and build an enterprise-wide strategy. Governance should not be treated as a compliance requirement that slows innovation. It should be viewed as the framework that allows AI to become a trusted part of everyday business operations. Strong governance gives leadership greater visibility into performance, clearer accountability for decisions, and the confidence to automate higher-value work.
The market itself is also evolving quickly. Vendor offerings will continue to improve, governance standards will mature, and AI capabilities will become more autonomous. Organizations that regularly reassess their governance strategy and remain flexible in their technology decisions will be better prepared to adapt as the landscape changes.
The companies that create lasting value from AI will not necessarily be those that deploy it first. They will be the ones that establish the right governance foundation early, measure outcomes consistently, and scale AI with the same discipline they apply to every other critical business capability. In the years ahead, that combination of innovation and operational control is likely to become one of the strongest competitive advantages an enterprise can build.
A project in mind?
Schedule a 30-minute meeting with us.
Senior experts helping you move faster across product, engineering, cloud & AI.


