READ. SCROLL. LISTEN.

Original briefings. Zero spin.

Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.

← Back to headlines

Survey: Most Companies Deployed AI Agents Before Building the Controls to Manage Them

Survey: Most Companies Deployed AI Agents Before Building the Controls to Manage Them
VentureBeat Research surveyed enterprises across five layers of AI agent infrastructure and found most knew they were skipping governance before deploying. Now they're scrambling to retrofit identity checks, evaluation systems and cost tracking, with over half planning vendor changes within a year. The kicker: most of what companies call 'AI agents' are just chatbots with a fancier name.

Enterprises rolled out AI agents before they had the guardrails to control them. They knew it at the time, according to VentureBeat Research, which fielded five parallel surveys in June covering every layer of what it calls the "agentic stack."

Now the bill is coming due. Companies are budgeting to fix what they built too fast. Across all five control areas measured, between 57% and 68% of enterprises plan to switch AI vendors or add new ones within 12 months, VentureBeat Research found. Roughly a third plan to make that move within the current quarter alone.

That's a large chunk of corporate America admitting its AI rollout needs a redo, and paying real money to get there.

Five Things You Need Before You Trust a Robot With Your Business

VentureBeat identified five controls a company needs before it can actually trust an AI agent to act on its own: identity (who is this agent and what is it allowed to touch), evaluation (is its output any good), cost telemetry (what does running it actually cost), the context layer (what business data and definitions it's pulling from), and orchestration (how multi-step tasks get coordinated across agents).

Skip any one of those and you don't have a governed system. You have a black box with a corporate credit card.

Most "AI Agents" Are Just Chatbots in a Costume

Seventy-one percent of enterprises said a quarter or fewer of their deployed "agents" can actually complete multi-step work without a human stepping in, according to VentureBeat Research. Only 10% said true autonomous agents make up the majority of what they've deployed.

These aren't junior staffers guessing. Eighty-one percent of the people surveyed recommend or decide AI purchases at their companies. They know what they bought. They're just admitting most of it isn't what the marketing promised.

A basic chatbot that answers one prompt at a time, watched by a human the whole way, doesn't need identity controls, evaluation frameworks, or any of the rest. A real multi-step agent needs all of it. VentureBeat's finding: most companies can't even say for certain which one they're running.

Companies Are Letting Robots Ship Code With Nobody Watching

Two-thirds of enterprises either already let an AI agent push a code or system change straight to production based solely on automated evaluation results, no human review required, or are actively building toward that within the year, according to VentureBeat Research.

Only 5% of enterprises say they fully trust the evaluation systems that would be making that call. And half of enterprises reported an agent that passed its internal evaluations and then caused a customer-facing failure anyway in the past year.

Companies don't trust their own testing systems. Their own testing systems have already failed in production. And companies are moving toward giving those same systems the final word on what ships. VentureBeat's recommendation is straightforward: test evaluation systems against what actually happens in production, not against internal benchmarks that clearly aren't catching the problems.

Sharing Login Credentials Between AI Agents Is Getting Companies Hacked

Sixty-nine percent of companies let at least some of their AI agents share credentials, meaning multiple agents operate under a single API key or service account, according to VentureBeat Research. That's a security shortcut, and it's showing up in the incident numbers.

Companies that allow credential sharing anywhere in their operation experienced a security incident or near-miss at a 63.5% rate, 47 out of 74 organizations surveyed. Companies that give every single agent its own scoped, individual identity saw that rate drop to 40.9%, nine out of 22.

That's a 22-point gap in incident rates tied directly to a basic access-control decision. The fix VentureBeat lays out is not complicated: every agent gets its own scoped identity, starting with any agent that touches production systems.

None of this is theoretical anymore. Companies are already voting with their budgets: the 57-to-68% vendor-switching numbers show enterprises don't think their current tools are cutting it, and they're not waiting for a crisis to act.

What's unresolved is whether the fixes keep pace with how fast companies keep expanding what they let these systems do unsupervised. The survey data shows a widening gap between what agents are being trusted to do and how much the evaluation and identity systems around them are actually trusted to catch a mistake before it hits a customer. Until that 5% trust number in evaluations climbs a lot higher, giving agents unsupervised production access looks less like innovation and more like a bet companies haven't finished pricing.

Sources used for this briefing

This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.

center
VentureBeatVentureBeat Research: Where enterprise AI agent governance hasn't caught up
center
VentureBeatVentureBeat Research: Where enterprise AI agent governance hasn't caught up
center
ForbesBridging the AI governance divide