They Knew They Were Moving Too Fast
Enterprises deployed AI agents ahead of the controls needed to manage them — and they did it knowingly. It’s hard to find a better example of tech-driven recklessness in recent history. A new study from VentureBeat Research confirms it: organizations across the board skipped the foundational groundwork, and now they’re paying the price in a mad, expensive scramble to retrofit governance tools before everything hits the fan.
This isn’t just some theoretical "move fast and break things" philosophy run amok. We’re talking about 573 enterprise leaders who admit they put the cart before the horse. Now, for each of the five core control layers—identity, evaluation, cost telemetry, the context layer, and orchestration—over half plan to switch vendors within a year. Some are even moving within the quarter. That’s not strategic migration; that’s panic-buying.
The Five Layers of Our New Agentic Headache
If you’re wondering why this is happening, look at the stack. You can’t just turn on an agent and expect it to behave. You need to build five distinct, interlocking control layers that manage the chaos.
Identity governs who does what. Evaluation tells you if it’s actually good. Cost telemetry keeps you from bleeding out before you see a return on investment. The context layer is the brain—without it, your agent is just guessing, confidently, and often entirely wrong. Finally, orchestration tries to manage the whole thing.
Most enterprises are missing all five.
The Chatbot Masquerade
Here is the most laughable part of the report: only 10% of enterprises claim that a majority of their deployed "agents" are true multi-step agents. For most companies, the technology they're calling an "agent" is, in reality, just a chatbot dressed up in corporate labeling.
Seventy-one percent of these enterprises admit that a quarter or fewer of their bots can handle multi-step work. And that’s a crucial distinction. A single-prompt chatbot interacting with a human needs almost zero governance. A real, multi-step agent—one that makes decisions, calls APIs, and interacts with systems without human oversight—needs all of it. Most companies are essentially treating chatbots like autonomous systems, and that’s a recipe for disaster.
The Trust Gap: Automating Failure
Perhaps the most alarming finding in the report is how we handle autonomy. Two-thirds of enterprises already let agents push code or system changes based solely on automated evaluation results—or they are engineering to do this within 12 months.
Here’s the gut-punch: only 5% of these organizations fully trust their evaluation frameworks. Let that sink in for a second. We’ve collectively decided that "we don't really trust this evaluator" is a fine justification for letting it change production systems without a human ever seeing the output.
Unsurprisingly, half of these companies reported that an agent passed these internal evaluations and subsequently caused a customer-facing failure in the past year. If you aren't testing your evaluators against actual, observed production outcomes—rather than just abstract internal benchmarks—you are literally flying blind.
Credential Sharing: The Security Multiplier
We’ve seen this movie before, multiple times. When we run short of time, we take shortcuts. For enterprises, that shortcut is credential sharing. Sixty-nine percent of companies let at least some of their agents share credentials, running multiple bots under the same API key or service account.
It’s almost charming how predictable the consequences are. Organizations where credential sharing happens saw security incidents or near-misses at a 63.5% rate. Compare that to the 40.9% rate at companies where every agent gets its own, scoped identity. Scoped identity isn't just best practice; it's the bare minimum for not burning your organization down from the inside.
For a deeper dive into the governance necessary for these platforms, read our analysis on AI Cybersecurity Governance: Why Agentic AI Demands a New Foundation.
The GPU Trap
Then there is the hardware. Every company is buying GPUs like they’re going out of style, but few are tracking the actual returns. More than 80% of enterprises running their own GPUs report utilization at 50% or less. Only 44% track what those compute costs actually translate into in terms of productivity or revenue. We’re in the middle of a massive compute-capacity glut, and the primary response is to buy more capacity. Efficiency matters, and yet it's treated like a secondary concern.
Confident and Wrong: The Context Problem
Finally, we hit the RAG report. Fifty-seven percent of companies have traced confident, inaccurate agent responses to stale definitions, missing documents, or general business context failures. This isn't a "too many models" problem; it's a data-integrity problem.
You cannot build a smart agent on top of a dumb, disorganized data layer. Governing your business definitions, your metrics, and your entities—that’s the actual hard work of artificial intelligence. Scaling agents before you've mastered the context they depend on is just speeding up the rate at which you generate misinformation.
Where Does the Money Go?
The most interesting question left unanswered by the research is where the budgets are shifting. Every layer is up for grabs, and no vendor has an entrenched incumbent advantage.
Switching intent is highest in orchestration, with 68% of organizations planning to add or replace their platforms within the next year. Are they moving toward the built-in, "easy button" tools that ship with the big platforms, or are they moving toward the specialists? That single question—the direction of that spend—will almost certainly define the market for the next four quarters.
Enterprise AI is moving away from the "look what our chatbot can do" phase and into the "why did our agent just delete our production database in the middle of the night" phase. Governance isn't just about security or compliance anymore; it’s about simple, basic operational survival. Anyone still rushing to deploy without it needs to take a long, hard look at the map. We’ve been here before.