Enterprise AI agent governance lags deployments, VentureBeat finds
VentureBeat Research says 57% to 68% of enterprises plan vendor changes across AI agent control layers within 12 months.
By Renata Fuchs · Policy Reporter
· 3 min read
VentureBeat Research says enterprise AI agent governance is trailing the pace of deployment: companies have put agents into production before identity, evaluation, cost, context and orchestration controls are mature. Across five June 2026 surveys of 573 qualified respondents, 57% to 68% of enterprises in each control layer said they expect to change vendors or add new ones within 12 months, with about a third planning action within the current quarter.
The findings point to a market that is still forming around controls for agentic systems, rather than one already locked by incumbent suppliers. VentureBeat Research said default tooling today tends to be whatever ships with the AI platforms enterprises already use. Its surveys did not ask whether planned spending will move to platform-native products or specialist vendors.
What is enterprise AI agent governance?
In the research, governance is the set of controls that determines what an agent may do, whether its output is reliable, what it costs to run, what business context it uses and how multi-step work is coordinated. VentureBeat Research measured five layers: identity, evaluation, cost telemetry, context and orchestration.
Those controls become more consequential when an agent can take multi-step action without a person checking every response. Yet VentureBeat Research found that many deployed "agents" do not meet that bar: 71% of enterprises said a quarter or fewer of their deployed agents can complete multi-step work independently, while 10% said true agents make up a majority of what they run. The respondent base was positioned close to buying decisions, with 81% saying they recommend or decide AI purchases.
Evaluation and identity are the sharpest risk areas
On evaluation, VentureBeat Research reported a mismatch between automation plans and confidence. Two-thirds of enterprises either already allow an agent to push code or a system change to production based only on automated evaluation results, without human review, or are building toward that capability within 12 months. Only 5% said they fully trust those evaluations. Half said an agent passed internal evaluations and later caused a customer-facing failure in the past year.
Identity controls also remain uneven. Sixty-nine percent of companies said at least some agents share credentials, such as one API key or service account used by multiple agents. Among organizations that allow credential sharing anywhere, 63.5%, or 47 of 74, reported a security incident or near miss. The rate was 40.9%, or nine of 22, among companies where every agent has its own scoped identity.
Compute and context controls are also immature
The infrastructure findings show that enterprises are buying or running AI compute faster than they can measure its return. More than eight in 10 enterprises operating their own GPUs said utilization was 50% or less. Only 44% said they rigorously track the cost and return of their AI compute.
Business context remains another weak point. VentureBeat Research said 57% of enterprises had traced a confident but wrong agent answer in the past six months to missing or inconsistent internal context, including incorrect metrics, stale definitions or absent documents. Most of those enterprises saw the issue more than once.
Orchestration showed the strongest near-term vendor movement. In that layer, 68% of respondents said they plan to adopt, add or replace platforms within 12 months, and 34% said they plan to do so within the quarter.
The five surveys were conducted under VentureBeat Research's VB Pulse program and covered Agentic Orchestration, Agent Reliability & Evals, Agentic Security & Identity, AI Infrastructure & Compute, and Context Layers/RAG. Respondents came from organizations with at least 100 employees. VentureBeat Research said the samples were self-selected and that some findings should be read directionally, but said the parallel surveys point to the same overall direction.
This story draws on original reporting from VentureBeat.