AI

AI Agent Governance Is Falling Behind Enterprise Adoption, Optro Research Finds

Bakhtawar Majid

By: Bakhtawar Majid

4 min read

As AI agents move into critical enterprise workflows, Optro's latest research highlights a growing gap between AI adoption and accountability. 

[For more news, click here]

The enterprise AI conversation is changing. Companies are moving beyond using AI to generate content, summarize information and answer questions, and are beginning to give AI systems a role in carrying out work. When an AI agent can access business systems, use tools and take actions with limited human intervention, it becomes harder to answer a basic question: who is responsible for what it does? 

That accountability gap is the focus of a new report from Optro, When AI leaves the chat and enters the workflow. The governance company argues that enterprises are adopting agentic AI faster than they are adapting the controls needed to oversee it. 

AI is Moving into the Workflow 

Optro's research found that one in three organizations surveyed already use AI in critical resilience workflows, while 30% said they have never tested for an agentic AI failure scenario. 

The governance challenge changes as AI becomes more capable. An assistant might generate a recommendation that an employee reviews before acting on it. An agent can potentially carry out several steps itself, using connected tools and enterprise systems to complete a task. Organizations therefore need to know not just whether an AI system produces a reliable answer, but what it is authorized to do once it has one. 

Optro's research suggests that gap is already visible in how companies assess their own AI governance controls. While 58% of respondents said their governance controls were keeping pace with AI adoption, only 18% reported having active risk mitigations in place. The report draws on four surveys conducted between February 2025 and May 2026, covering audit, risk, compliance, business continuity and information security professionals across North America, Europe and the UAE. The individual surveys had between 403 and 612 respondents. 

The Visibility Problem 

One of the more interesting parts of Optro's research is its focus on AI visibility. The company describes autonomous agents as non-human identities because they can authenticate, access systems and perform actions on behalf of an organization. That makes the question of where those systems exist, what they can access and who owns them increasingly important. 

Optro's earlier 2026 research found that 85% of organizations had integrated AI into core operations or multiple functions, but only 25% had comprehensive visibility into how employees were using AI. That is particularly relevant as AI use spreads beyond centrally managed deployments. An employee using an unsanctioned chatbot is one governance problem. An employee deploying an agent that can interact with enterprise applications creates another, because the system may be capable of acting rather than simply generating information. 

Who approved the agent? What permissions does it have? Who is responsible for monitoring it? And if it makes a consequential mistake, who is expected to explain what happened? These are the accountability questions enterprise AI governance is now being asked to answer. 

The issue is not unique to Optro's research. PwC's 2026 Trust and Safety Outlook similarly argues that enterprise agents need verified identities, defined roles, task specific permissions and auditable records, with human oversight increasing as an agent's autonomy and potential consequences increase. 

Accountability has to Follow the Agent 

The implication is not necessarily that companies should slow AI adoption, but that governance needs to change as AI moves from assistance to action. 

"AI adoption is fast outpacing governance," said Guru Sethupathy, GM of AI Governance at Optro. "But to harness its potential responsibly, leaders must recognize that governance models designed for static manual processes cannot keep pace with autonomous systems of action. Redesigning governance isn’t about pulling back on innovation; it’s about building the control structure to give organizations the confidence to scale AI faster and more reliably than the competition." 

Once AI starts taking action, governance can no longer stop at setting policies for how employees use it. As agents gain access to business systems, controls need to extend into the workflow itself. For enterprise leaders, the challenge may ultimately be less about whether agents are capable of doing useful work and more about how much authority they can safely be given. 

The first phase of enterprise AI was largely about getting employees to use the technology. The next phase is about deciding what the technology is allowed to do on the organization's behalf. 

As AI agents move deeper into enterprise workflows, the real test may not be what they can do, but whether anyone knows who is responsible when they do it. 


Related Articles

How AI Is Redrawing the ERP Industry and Reshaping Who Runs It

Acronis Bets on Autonomous IT for MSPs, With VMware's Former CEO Charting the Off-Ramp

Exclusive: Why AI Governance and Global Digital Cooperation Are Entering a Defining New Era

Share this article

Related Articles