Enterprises are running AI agents in production without the guardrails to know if those agents are doing good work, wasting money, or impersonating the wrong people.
The Summary
- VentureBeat Research surveyed enterprises across five control layers for AI agents — identity, evaluation, cost telemetry, context, and orchestration — and found 57-68% plan to switch or add vendors within 12 months
- 71% of deployed "agents" are just chatbots labeled as agents; only 10% of enterprises run true multi-step autonomous agents
- Two-thirds of enterprises either already let agents push code to production without human review, or plan to soon
- Companies deployed first, are retrofitting governance second, and roughly a third plan to move vendors within 90 days
The Signal
VentureBeat Research went deep on enterprise AI agent governance and found a gap wide enough to drive a supply chain through. Enterprises deployed agents before they built the controls to manage them. They did it knowingly. Now they're scrambling to catch up with their own standards, and the vendor churn is about to be spectacular.
The research identified five control layers enterprises need before they can trust an agent to work unsupervised. Identity controls which agent does what under whose credentials. Evaluation determines if the agent's output is any good. Cost telemetry tracks what each agent costs to run. The context layer supplies business data and definitions. Orchestration coordinates multi-step work. Between 57% and 68% of enterprises plan to switch or add vendors in each layer within a year. A third are moving within the quarter.
"71% of enterprises said a quarter or fewer of their deployed 'agents' can complete multi-step work on their own."
The label inflation is real. Most deployed "agents" are chatbots wearing the wrong name tag. Only 10% of enterprises said true autonomous agents make up the majority of what they're running. A single-prompt chatbot with a human checking every answer doesn't need sophisticated controls. A true multi-step agent that can rewrite your codebase and push to production needs all five layers locked down. Most enterprises can't tell you which one they deployed.
The autonomy problem is even sharper. Two-thirds of enterprises either already allow agents to push code or system changes to production based on automated evaluation alone, or they're planning to. No human review. The trust is running ahead of the tooling to earn it. These aren't startups moving fast and breaking things. The respondents are positioned to know what's happening: 81% recommend or decide AI purchases at their companies.
Key gaps the research surfaced:
- No unified view of which agents are running where, doing what
- Cost telemetry so thin that finance can't budget for agent work
- Context layers that can't tell an agent the difference between "revenue" in sales ops versus accounting
The orchestration layer is the linchpin. Without it, you can't coordinate multi-step agent work across systems. Without cost telemetry, you're flying blind on spend. Without evaluation, you don't know if the agent's work is hallucination or insight. The enterprises that shipped agents first are now buying the control plane second. The vendor market for agent governance tooling is about to see a land rush.
The Implication
If you're selling agent infrastructure, the next 12 months are your window. Enterprises know they have a governance gap and they're budgeting to fix it. The churn numbers say they're not waiting for their current vendors to catch up.
If you're running agents in production, audit what you actually deployed versus what you call it. A chatbot labeled "agent" doesn't need orchestration. A true agent pushing code to prod without evaluation controls is a liability waiting to surface. The gap between autonomy and governance is where the expensive mistakes live.