AI agents: governance arrives after the incident
Deployment is growing fast and industry forecasts point to a high cancellation rate. The failure mechanism they anticipate is not technical: it is about accountability.
Executive summary
Scaled use of agents remains a minority practice. In almost every function it is measured in single digits. Only in the technology sector does it reach 24% in software engineering, 22% in IT and 21% in service operations.
The size gap is wider than for any other recent technology: 40% of large organizations say they are scaling agents, against 22% of small ones — a figure that did not move in a whole year.
Published industry forecasts agree on the failure mechanism: escalating costs, unclear business value and inadequate risk controls. These are analyst forecasts, not measurements, and should be cited as such.
An agent is not a model: it acts. That changes the governance question from "what did it answer" to "what did it do, with which permissions, against which systems, and who answers for it".
Context
The agent adds a capability the assistant did not have: it executes. It queries systems, writes to them and chains several steps in a row without a person approving each one separately.
That capability is what produces the value and also what produces the incident. Most organizations deploy it before defining permissions, audit trails and an owner, and discover the gap once something has already happened.
Figure 1 · Scaled use of agents by function, technology sector
% of organizations in the sector, 2025Table 1 · Published forecasts on AI agents
analyst forecasts, not measurements| Forecast | Horizon | Published |
|---|---|---|
| Over 40% of agentic AI projects will be cancelled | End of 2027 | Gartner, 25 Jun 2025 |
| At least 15% of day-to-day decisions will be made by agents, up from 0% in 2024 | 2028 | Gartner, 25 Jun 2025 |
| 33% of enterprise software will include agentic AI, up from under 1% in 2024 | 2028 | Gartner, 25 Jun 2025 |
| 40% of enterprises will demote or decommission agents over governance gaps | 2027 | Gartner, 26 May 2026 |
| 50% of deployment failures will stem from insufficient runtime enforcement | 2030 | Gartner, 11 Mar 2026 |
Business implications
Write the agent's scope the way you write a power of attorney. Which systems it touches, with what value or volume ceiling, and which actions require human approval before executing.
Demand traceability before autonomy. An agent whose actions cannot be reconstructed afterwards cannot be audited or corrected: it can only be switched off.
Start with reversible processes. An error in a reconciliation gets fixed the next day. One in a payment or a customer communication does not.
Methodology & data
Two types of source are combined and explicitly distinguished. Measurements come from McKinsey's 2025 global survey as republished by Stanford HAI's AI Index 2026. Forward-looking figures are forecasts published by Gartner in three press releases between June 2025 and May 2026.
No forward-looking figure in this document should be read as an observed data point.
References
Stanford HAI (2026). The AI Index 2026 Annual Report, chapter 4. · Gartner (25 June 2025). Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027. · Gartner (11 March 2026). Gartner Announces Top Predictions for Data and Analytics in 2026. · Gartner (26 May 2026). Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure.