54% + 56% =100% of the Agent Problem, and Governance Is the Fix
Stay updated with us
Sign up for our newsletter
TrueFoundry recently surveyed more than 200 enterprise AI leaders. 54% cannot fully trace what their AI agents are doing, and 56% lack a centralized governance layer. Those are two symptoms of the same problem, and together they touch almost every organization we talk to. The root cause is a missing control plane for agentic AI.
How did enterprises get here? Agentic AI did not arrive through a grand corporate initiative. It came in through the side door. One team connected an LLM to Slack. Another wired an agent into GitHub. The data team shipped an analytics copilot, support began experimenting with autonomous ticket triage, and finance connected a model to invoices and approval workflows. On top of that, every vendor platform now ships its own agents, from personal productivity assistants to sales agents, ITSM agents, and pro-code agent runtimes, and every one of them acts on behalf of a user. No single project looked risky. Together, they quietly created dozens of agents with different permissions, different vendors, and different identity systems, with no shared record of what any of them are doing.
That is where enterprise AI stands in 2026. Adoption is real and the value is real, but unified control is nearly nonexistent.
Two Capabilities Every CIO Wants and Almost No One Has
The same two gaps come up in nearly every conversation with CIOs and CISOs. The first is unified agent identity, one identity system for every agent regardless of which platform it runs on. The second is the kill switch, the ability to halt any agent on any platform instantly. For regulated enterprises, the kill switch is non-negotiable, and today most organizations cannot do it.
Cost and model quality dominate boardroom AI discussions. But in production, the bigger risk is operational. Enterprises often don’t know which agents can access what, what decisions they made, or how to reconstruct those decisions after the fact. In regulated industries like financial services, healthcare, and insurance, an untraceable agent decision is a legal liability waiting for an audit.
Why Agents Change the Risk Equation
A plain LLM’s failure mode is contained. It gives a wrong answer, someone reads it, and someone catches it before it does damage. Agents are different because they act. A wrong answer becomes a wrong action, a refund issued to the wrong account, a CRM record overwritten, or customer data exposed through a tool call nobody scoped properly.
The uncomfortable truth is that in most of these incidents, the agent did not malfunction. It did exactly what it was allowed to do. The failure was that nobody defined what “allowed” meant with any precision, and nobody could see the action until after it happened.
The place this shows up first is the tool layer. Every agent platform reaches the same enterprise systems, CRM, code repositories, email, ticketing, through tool integrations, and that layer has become the biggest operational blind spot in enterprise AI. When a tool breaks or misbehaves, most organizations cannot answer the basics, like which agents and users are accessing it, which integrations are production-ready, and which ones have proper access control. The practical consequence is that leading enterprises now govern agents at the point where they touch tools, because that is the one place every agent, from every vendor, has to pass through.
The Bill Is Rising, and the CFO Has Noticed
There is a second force pulling governance up the agenda, cost. Per-token prices keep falling, yet total enterprise AI bills keep rising, because agentic workflows burn 5–30x more tokens per task than simple queries, per Gartner. Coding agents and personal-assistant tools now carry more token volume, and more cost, at many enterprises than anything the platform team built in-house. Cost control has become a board-level topic, and the conversation about routing, caching, budget enforcement, and per-team attribution is now driven by the CFO as much as the platform team.
There is also a resilience angle. Standardizing on one model provider simplifies procurement, but it creates a single point of failure. Recent provider outages have shown what happens when business-critical workflows sit on one model with no fallback. The organizations that weathered them had a routing layer that turned a provider outage into a routing event instead of a business outage.
Governance Has to Live Where the Agent Acts, and It Has to Be Neutral
Here is the structural problem. Every AI platform wants to be the platform, and none of them wants to be governed by another. Interoperability protocols exist on paper, but no vendor exposes its own agents to a competitor’s control plane. That means governance cannot sit inside any one model provider, any one cloud, or any one application vendor. It has to be an independent, model-agnostic, cloud-agnostic layer that every model call, API request, and autonomous action passes through, with defined permissions, policy enforcement, and complete traceability.
For example, a sales operations agent may legitimately need CRM records, call transcripts, and approval workflows. That does not mean it needs every customer record or discounting authority. An engineering agent might open pull requests and run tests in staging, but it does not deploy to production unreviewed, and it does not touch secrets without a policy check. These are the same least-privilege principles enterprises have applied to human employees and service accounts for decades, now extended to the fastest-growing class of actors in the organization.
The regulatory clock makes this concrete. The EU AI Act’s high-risk obligations become enforceable this August, including automatic logging and retained audit trails. The audit trail regulators will ask for is precisely the record most enterprises cannot produce today. The companies 12 to 18 months into AI deployment that got this right treated governance as infrastructure from day one. Everyone else is retrofitting controls onto systems that were never built for them, and discovering that “oops, it shouldn’t have been able to do that” does not hold up in front of an auditor.
The CIO’s Actual Mandate
Enterprise AI’s first phase was experimentation. This phase is about production and scale, and the questions have changed. Can it run safely, economically, and reliably? Increasingly, the CISO is at the table too, because agents with production access are a security surface as much as an IT project. The security industry’s recent moves into the AI gateway layer show where the control point is heading.
Agentic AI raises the stakes precisely because the upside is real — less manual work, faster operations, genuine ROI. That upside is exactly why it should be evaluated like any other production infrastructure, with guardrails built in before it becomes business-critical, not bolted on after.
This is about making agent adoption sustainable, not about slowing it down. Enterprises need better control over the agents they already have, a single registry of every model, tool, and agent, one identity system, and one place to pull the plug.
Go back to the numbers. 54% cannot trace their agents, and 56% cannot govern them. Those are two symptoms of the same root cause, and one control plane for agentic AI closes both. The organizations that fix this early will be the ones comfortable handing AI increasingly critical work. The rest will find out what their agents have been doing the hard way.