elmerdata.ai blog

My blog

Governance Arrived Too Late for Agentic AI

Two reports show that most organizations govern agentic AI loosely — but the deeper problem is that every binding compliance framework was written before agentic AI existed, so the controls are stale by construction rather than by neglect.


Two 2026 reports on the agentic governance gap, and why only one explains it

Sources: OutSystems, "2026 State of AI Development," survey of 1,879 IT leaders, April 2026 (via TechHQ). Eticas, "The Eticas AI Risk Taxonomy: Open Infrastructure for Operationalizing AI Audits," arXiv 2607.02201, July 2026.

Backgrounder: this piece follows on from The Adoption Curve Is the Finding, which examined the MIT Sloan and BCG agentic enterprise report and its argument that governance infrastructure should precede deployment. That post's central figures — 35% agentic adoption in two years, 76% of executives describing agents as coworkers rather than tools — are the baseline this one measures against.

In short


Last November's MIT Sloan and BCG report gave organizations a clear instruction: build centralized governance infrastructure before deploying autonomous agents. Two reports published since suggest almost nobody followed it. They disagree, interestingly, about whose fault that is.


infographic

Technology adoption in U.S. households over time. Historical diffusion typically unfolded across decades, providing a useful contrast with the rapid organizational adoption of agentic AI. Source: Our World in Data (2020). CC BY 3.0.


What the survey found

OutSystems surveyed 1,879 IT leaders and found that 97% of organisations are already exploring agentic AI strategies, with 49% describing their abilities as advanced or expert. Only 36% have a centralised approach to agentic AI governance, and just 12% use a centralised platform to maintain control over AI sprawl.

The figure circulating in coverage of this report is 97% against 12%, which overstates a real gap by comparing exploration to platform adoption. The defensible comparison is 97% exploring against 36% centrally governed. That is still a substantial spread, and the texture underneath it is more revealing than the headline.

Some 94% of organisations say AI sprawl is increasing complexity, technical debt, and security risk, but only 39% describe themselves as very or extremely concerned. Awareness is close to universal; alarm is not. And 41% rely on project-level rules rather than any centralised framework — governance exists, but at the wrong altitude, negotiated deployment by deployment.

The most useful finding is about mechanism rather than attitude. Two thirds of leaders — 66% — find building human-in-the-loop checkpoints technically difficult, requiring an orchestration layer that can pause agents and produce decision logs for human review. Most settle for a passive human-on-the-loop model instead, which works only when governance structures are already in place. That is a precise account of how oversight degrades. Nobody decides to abandon supervision. The supervising mechanism turns out to require infrastructure that was never built, and the weaker version becomes the default by attrition.

Two caveats on this source. It reaches me through TechHQ's coverage rather than the underlying report, and OutSystems sells a unified platform for building and governing agents. Its closing finding — 96% of leaders call such a platform important while only 7% have adopted one — is a vendor measuring unmet demand for its own category. The governance figures are plausible and consistent with other 2026 surveys, but they were commissioned by a company with an interest in the gap looking wide.


What the taxonomy explains

The OutSystems data describes a gap. It does not explain why the gap persists, and the intuitive explanation — organizations moved too fast, governance teams moved too slow — turns out to be incomplete.

The Eticas AI Risk Taxonomy, published this month, organizes AI risks across ten top-level categories mapped to 18 external frameworks, and treats Agentic AI as a first-class category. Doing so surfaced what the authors call a structural governance gap: the major regulations predate agentic AI as a deployment paradigm.

Among major audit-oriented taxonomies, Eticas is among the first to treat agentic AI as a first-class category, and every framework it can map that category to emerged in 2025 or 2026. The thinness of mappings everywhere else is itself the finding.

This reframes the problem. An organization that wanted to govern its agents against binding compliance frameworks would find that those frameworks were finalized for a different technology. The controls are not weak because anyone neglected them. They are stale by construction — written for systems that predict rather than act, and inherited unchanged by systems that plan, invoke tools, and execute multi-step chains without asking.

Eticas is specific about why the older categories do not transfer. Agentic systems decompose goals, invoke tools, persist state, adapt plans, and interact with other agents, which produces risk profiles absent from passive prediction systems: an agent with deletion access may over-interpret an instruction, an agent network with conflicting objectives may produce emergent behavior no agent intended, and an agent acting at machine speed forecloses meaningful per-decision oversight.

That last item deserves emphasis, because it connects directly to the OutSystems finding. If machine-speed action forecloses per-decision oversight, then the two thirds of organizations struggling to build human-in-the-loop checkpoints are not failing at implementation. They are discovering that a control designed for human-paced decisions does not survive contact with a system that does not operate at human pace.

Where the two reports meet

Read together, the reports reveal institutions operating on different clocks. Governance frameworks emerge through regulatory negotiation and standards consensus, on cycles measured in years. Agentic AI arrived as a deployment paradigm in roughly eighteen months, distributed as a feature inside software organizations already owned. One process is deliberative by design and the other is frictionless by design, and no amount of diligence closes a gap produced by that difference.

This is a provenance problem, though not the familiar kind. Data governance traditionally asks where a piece of data originated. What the agentic gap exposes is the need for a second question: where did the control originate? Controls inherit assumptions exactly as data inherit lineage, and those assumptions expire. A control takes its authority from the conditions it was written under, and when those conditions change without the control changing, the control keeps its formal status while losing its actual coverage. An organization can pass an audit against a framework that does not contemplate the systems it is running. The compliance record stays clean. The lineage is broken.

Which is where the Sloan report's instruction looks less like advice and more like a description of a road not taken. Build governance infrastructure before deploying autonomous agents was the right sequence, and the OutSystems figures suggest it was widely inverted. But the Eticas finding complicates the reproach: an organization that had genuinely tried to sequence correctly in 2025 would have reached for frameworks that could not yet see what it was deploying. The instruction was sound and the materials were missing.

Organizations should stop treating framework coverage as evidence of governance and start asking, for each system in production, which framework was written with that class of system in view. On the current evidence, for agentic systems, the honest answer is usually none of the binding ones.


Further Reading


AI Assistance Statement ▾
Preparation of this blog entry included drafting assistance from ChatGPT using a GPT-5 series reasoning model. The tool was used to help organize ideas, propose structure, refine language, and accelerate revision. It was also used to assist in identifying image sources and verifying that selected images appear to be released for reuse (for example through public domain or Creative Commons licensing). The author selected the topic, determined the argument, reviewed and edited the text, confirmed image licensing, and takes full responsibility for the final published content.