Skip to main content Scroll Top
Recent Post
Subscribe to our newsletter and get your daily dose of The Tech Insider straight to your inbox:

    Hidden fields
    Popular Posts
    58% Feel Covered. 18% Actually Are.

    For three years the AI risk question was “is the answer right?” Agentic systems have quietly replaced it with a harder one: “was it allowed to do that?”

    What the research found

    New data from AI governance platform Optro puts numbers on something most enterprise teams have only felt anecdotally: agent deployment has run ahead of the controls meant to contain it.

    A third of organisations already have AI embedded in critical resilience workflows — the processes that are supposed to hold when everything else fails. Nearly a third have never once tested what happens when an agent in those workflows makes a bad call.

    The confidence gap is the sharpest finding. 58% of business leaders say their governance controls are keeping pace with adoption. 18% report having dedicated AI risk safeguards in place. That’s a forty-point spread between belief and infrastructure.

    The consequences are already showing up in the operating data:

    Incident typeShare of organisations, past 12 months
    Misleading or inaccurate AI output40%
    AI-linked data breach27%
    Regulatory scrutiny tied to AI use26%

    None of those are hypothetical future-of-work scenarios. They are last year’s incident log.

    Why “generation risk” and “action risk” are different animals

    Every governance framework currently in production was designed around a human who decides and a process that approves. The model is sequential: someone proposes, someone reviews, someone signs.

    Generative AI stressed that model but didn’t break it, because a draft is inert. A wrong paragraph sits there until a person acts on it. The failure mode is embarrassment, and the containment mechanism is a second pair of eyes.

    An agent has no inert state. It reads a signal, decides, and executes — often across systems, often at machine speed, often at volume. A wrong decision doesn’t wait for review. It propagates. By the time it surfaces on a dashboard, it has already touched a segment, sent a sequence, adjusted a bid, or updated a record several thousand times.

    That is the shift the research is really describing. The governance question moves upstream, from verifying output to scoping authority. Reviewing what an agent produced is a lagging control. Deciding what it can reach is the leading one.

    The CMO version of this problem

    Marketing is unusually exposed here, and unusually slow to notice.

    AI is already sitting inside campaign execution, lifecycle messaging, personalisation logic, lead scoring, and increasingly the first-touch customer conversation itself. Most of that was adopted at team level, tool by tool, through budgets that never triggered a formal risk review. There is rarely a single inventory of it.

    Which produces three questions almost no marketing org can currently answer cleanly:

    • Which of our AI systems talk directly to customers? Not “which tools do we use” — which ones can generate an outbound touch without a human seeing it first.
    • Who owns the failure? An agent that pulls a customer record, drafts a message, and sends it has crossed marketing, IT, legal, and security in a single action. Four functions with a shared incident and no shared owner is how a fixable problem becomes a public one.
    • How much oversight is proportionate? This is the genuinely hard one, and the reason most governance programmes stall. Approve everything and you’ve built an expensive workflow that nobody uses — teams route around it within a quarter. Approve nothing and you’re relying on vendor defaults you never read.

    Optro’s Guru Sethupathy frames the mismatch directly: controls built for static, manual processes were never designed to supervise systems that act on their own. Newell Brands’ Mark Taylor makes the practical version of the argument — the organisations that get this right will define agent behaviour and agent reach up front, deciding deliberately where a human sits in the loop versus merely on it.

    That distinction is worth borrowing. In-the-loop means the agent cannot proceed without you. On-the-loop means it proceeds and you can stop it. Most marketing teams have never made that choice explicitly for a single system — it was made for them, by a default setting.

    Five things worth doing this quarter

    1. Build the inventory before you build the policy. You cannot govern a system you haven’t listed. Start with a blunt question to every team: which tools here can take an action without a human clicking approve? Expect the list to be longer than leadership assumes and to include at least one thing nobody remembers buying.
    2. Classify by blast radius, not by vendor. The relevant axis isn’t which platform an agent lives in. It’s what it can touch and how far a mistake travels. An agent drafting internal copy and an agent with send permissions to your full customer base are not the same risk class, however similar the licence agreement looks.
    3. Test the failure, not the feature. Thirty percent have never tested for agentic failure — largely because pilots are designed to prove value, not find breaking points. Run the ugly scenarios deliberately: bad input data, ambiguous instruction, conflicting signals, an edge-case customer record. What the agent does when it’s confused matters more than what it does when it’s right.
    4. Name a single accountable owner per agent. Not a committee. One name, with the authority to suspend the system. Cross-functional governance forums are useful for setting standards and useless during an incident, when what you need is someone who can pull the plug in under ten minutes.
    5. Write down the in-loop / on-loop decision. For every customer-facing agent, record which mode it runs in and why. The exercise takes an afternoon and surfaces more risk than most formal audits, because it forces you to articulate what you’re currently trusting by default.

    The uncomfortable read on this research isn’t the incident numbers — it’s the forty-point gap between the 58% who feel governed and the 18% who are. Confidence that outruns infrastructure is the precondition for most operational failures, in AI and everywhere else.

    The teams that come out of the next eighteen months well probably won’t be the ones that deployed agents fastest. They’ll be the ones that could answer, on any given day, exactly what each of their agents was permitted to do — and who was accountable when it did it.

    Related Posts

    Add Comment

    More news