Corporate AI Agents Outpacing Governance
According to five surveys conducted by VentureBeat Research in June 2025, many enterprises are deploying AI agents ahead of establishing management frameworks, with governance infrastructure lagging behind. Only 10% of companies report that true agents capable of autonomous multi-step processing account for the majority of their deployments, with risks evident across both security and quality dimensions, including credential sharing and low confidence in agent evaluation.

Many enterprises are deploying AI agents first while postponing the development of systems to safely manage them—findings that emerged from five surveys conducted by VentureBeat Research in June 2025. Survey respondents centered on decision-makers involved in corporate AI purchasing, with 81% in positions to recommend or determine their company's AI procurement. Currently, enterprises are retrofitting management frameworks onto already-deployed agents, and those planning to switch vendors or add new ones within the next 12 months reached 57–68% across all five governance domains.
The survey measured five governance domains necessary for enterprises to trust and operate agents effectively. Specifically: 'Identity and Access Management' defining what each agent can do, 'Evaluation' confirming agent output quality, 'Cost Visibility' tracking operational expenses, 'Context Layer' supplying business data and definitions referenced by agents, and 'Orchestration' coordinating multi-step agent tasks. All of these form essential foundations when agents operate without human supervision.
In reality, however, most of what is called an 'AI agent' closely resembles an ordinary chatbot. Seventy-one percent of enterprises reported that agents currently operating at their company capable of autonomously performing multi-step tasks represent a quarter or less of their total deployments, while only 10% of companies said true agents account for the majority. While single-turn chatbots require almost none of these five governance functions, true agents that autonomously chain multiple processes require all of them. The problem is that many enterprises cannot identify which category their 'agents' fall into.
Trust in the 'Evaluation' that should provide safety assurance is also low. Two-thirds of enterprises have already adopted or plan to adopt within 12 months the practice of deploying code or system changes to production without human review once an agent passes evaluation. Yet only 5% of companies said they 'completely trust' the evaluation system on which that judgment rests. Moreover, half of enterprises reported that agents passing internal evaluation have caused incidents in customer-facing services within the past year, revealing significant gaps between evaluation results and actual operational outcomes.
Security presents equally grave challenges. Sixty-nine percent of enterprises share identical API keys or service accounts across multiple agents. Organizations engaging in even partial 'credential sharing' experienced security incidents or attempts at a rate of 63.5% (47 of 74 organizations). By contrast, organizations assigning unique identities and permissions to every agent saw that rate drop to 40.9% (9 of 22 organizations), revealing that credential management methods directly correlate with risk exposure.
The structural problem illustrated by these findings is the asymmetry of 'deployed at speed while safety management lags behind.' As agent autonomy increases, the impact of a single failure on customers and operations grows proportionally. At present, many enterprises are budgeting governance infrastructure as an 'additional investment,' rendering governance retrospective rather than proactive. Moving forward to realize the full potential of agent AI will require a shift toward 'security by design' thinking, where deployment and governance are architected together from the start.
This article is an original work independently written and edited by the AI issue editorial team based on factual reporting. © AI issue. Unauthorized reproduction, redistribution, or use for AI training is prohibited.