Enterprises deployed AI agents ahead of the controls needed to manage them. They did it knowingly. That is the central finding of a VentureBeat Research study published July 24, 2026, spanning five parallel surveys and 573 enterprise leaders. Not a surprise to anyone running agents in production. But now there is data behind what practitioners have been saying for months.
The numbers are specific enough to be useful. Seventy-one percent of enterprises said a quarter or fewer of their deployed “agents” can actually complete multi-step work on their own. Only 10% said true autonomous agents are the majority of what they run. Most of what companies call agents are chatbots with the label. And the organizations that know this best are the ones making the purchasing decisions: 81% of respondents recommend or decide AI purchases at their companies.
The gap is not between companies that have agents and companies that do not. The gap is between companies that have agents and companies that have the operational infrastructure to trust them.
Five controls, zero shortcuts
VentureBeat measured five control layers an enterprise needs before it can trust an agent at scale: identity, evaluation, cost telemetry, the context layer, and orchestration. Each one is an operations problem. None of them are model problems.
Identity determines which agent is allowed to do what, under whose credentials. Sixty-nine percent of companies let at least some of their agents share credentials, meaning multiple agents operating under one API key or service account. Organizations that allow credential sharing experienced security incidents or near-misses at a 63.5% rate. Companies where every agent has its own scoped identity dropped to 40.9%. The fix is straightforward: scoped identity for every agent, starting with the ones that touch production systems. The reason most companies have not done it is that nobody owns the decision.
Evaluation determines whether the agent’s work is any good. Two-thirds of enterprises either already allow an agent to push changes to production based on automated evaluation alone, with no human review, or are engineering toward that within 12 months. Only 5% fully trust the evaluations that would make that call. Half of enterprises shipped an agent that passed internal evaluations and then caused a customer-facing failure in the past year. The evaluations are not aligned with real-world outcomes. They test what the model can do in a sandbox. They do not test what happens when the sandbox opens.
Cost telemetry tracks what each agent costs to run. More than eight in ten enterprises running their own GPUs reported utilization of 50% or less. Only 44% rigorously track what their AI compute actually costs and returns. The most expensive hardware in the building runs at half capacity, and nobody can tell the CFO what it produces.
The context layer supplies the business data agents draw on when they answer. Fifty-seven percent of enterprises traced a confident, wrong agent answer in the past six months to their own missing or inconsistent business context. Wrong metrics. Stale definitions. Missing documents. The agent was not hallucinating. It was answering accurately from data nobody governed.
Orchestration coordinates multi-step agent work. This is where switching intent runs highest: 68% plan to adopt, add, or replace platforms within 12 months. Thirty-four percent plan to move within the quarter. No layer has an entrenched incumbent, which means the playbook is being written right now by whoever moves first with operational discipline.
The retrofit is underway
The spending data tells you this is not theoretical. Across all five control layers, 57 to 68% of enterprises plan to switch vendors or add new ones within 12 months. Roughly a third, depending on the layer, plan to move within the quarter. This is not experimentation. This is companies realizing they built the car and forgot the brakes, and now they are installing brakes while driving.
The pattern is familiar if you have watched enterprise technology cycles before. The urgency to deploy outran the discipline to govern. The governance gap did not appear because governance tools do not exist. It appeared because nobody owned the decision to require them before agents went live.
The question that matters this week
This research confirms something I keep seeing in the field. The conversation about AI agents in most organizations is still happening in the language of capability. Which model is best. What the agents can do. How much faster they are.
The organizations pulling ahead are having a different conversation entirely. They are asking: who in our company owns the controls? Not the technology. The controls. Identity, evaluation, cost visibility, data governance, orchestration. Five decisions. Each one needs an owner with the authority to enforce standards across teams.
If your organization has deployed agents without answering that question, you are in the majority. The VentureBeat data says 71% of enterprises are running agents that cannot even complete multi-step work autonomously. The agents are not the problem. The operating infrastructure around them is.
The companies that close this gap in the next 12 months will not be the ones with the best models. They will be the ones that treated governance as the first operational decision, not the last. The data says most companies are still retrofitting. The question is whether you retrofit now, while the gap is closable, or later, when the cost of catching up has compounded into something structural.
Fifty-seven percent of enterprises traced wrong agent answers to their own ungoverned data. That is not an AI problem. That is a process problem wearing an AI label. And process problems have process solutions. Someone needs to own it. This week.