Enterprise AI agent deployments have outpaced the security controls and governance frameworks required to manage them safely, according to findings from VentureBeat Research’s June 2026 Pulse program. Organizations rushed to implement agentic workflows, only to discover significant gaps in identity management, evaluation accuracy, and cost tracking. Consequently, 57 to 68% of surveyed enterprises across five control layers now plan to switch vendors or add new ones within a 12-month window.
The Reality of Autonomous Agent Deployment
Most organizations currently operate single-prompt chatbots rather than fully autonomous systems. According to VentureBeat Research, 71% of enterprise respondents reported that a quarter or fewer of their deployed agents can complete multi-step work independently. Only 10% stated that true autonomous agents form the majority of their active deployments. These insights stem from a survey pool where 81% of respondents directly recommend or decide artificial intelligence purchases for organizations with 100 or more employees.
Basic chatbots require minimal oversight. However, true multi-step agents demand robust control layers covering identity, evaluation, cost telemetry, context, and orchestration. Organizations deployed these tools rapidly, and they are now retrofitting safeguards to meet internal standards.
Autonomy and Reliability Deficits
Enterprises are granting software agents production access despite widespread distrust in automated evaluation systems. VentureBeat Research data shows that two-thirds of organizations either already allow an agent to push code or system changes to production based solely on automated evaluation results, or they plan to engineer that capability within 12 months. Yet, only 5% fully trust the evaluations making those operational calls. Highlighting this disconnect, half of the surveyed enterprises reported shipping an agent that passed internal evaluations only to cause a customer-facing failure over the past year.
Credential Sharing Amplifies Security Incidents
Security vulnerabilities often stem from lax identity management practices. Sixty-nine percent of companies permit at least some agents to share credentials, meaning multiple agents operate under a single API key or service account. Organizations allowing credential sharing experienced a security incident or near-miss at a rate of 63.5%, matching 47 out of 74 companies. By contrast, organizations where every agent maintains its own scoped identity recorded a 40.9% incident rate, corresponding to nine out of 22 companies.
Infrastructure Utilization and Governance Gaps
Hardware investments in enterprise artificial intelligence frequently operate well below full capacity. More than eight in ten enterprises running proprietary graphics processing units reported utilization rates of 50% or less. Furthermore, only 44% of organizations rigorously track the actual costs and returns associated with their compute resources.
Data governance presents a parallel challenge. Fifty-seven percent of enterprises traced a confident yet incorrect agent response over a six-month period to missing or inconsistent business context, such as wrong metrics, stale definitions, or absent documents. Most affected organizations experienced this issue multiple times.
Vendor Switching and Market Consolidation
Enterprise software stacks lack entrenched market leaders, leaving built-in tools from major platforms as the current default. Intent to switch vendors runs highest within orchestration controls, where 68% of enterprises plan to adopt, add, or replace platforms within 12 months, and 34% intend to make changes within a single quarter.
Related reading