What happened

Deloitte's 2026 State of AI in the Enterprise report, covered by MarketScale on June 25, 2026, put a number on something a lot of enterprise leaders already sense: adoption is outrunning oversight. According to the report, 23% of companies now report at least moderate use of agentic AI — AI systems that act and make decisions with minimal human review — and that figure is projected to grow substantially over the next two years. Set against that growth, only about one in five companies currently has a mature governance model for these autonomous agents.

The same report found the broader AI rollout is real, not just talk: worker access to AI across enterprises rose 50% in 2025, and the number of companies with at least 40% of their AI experiments running in production is on track to double within six months. But depth of change hasn't kept up with breadth of access — Deloitte splits organizations into three tiers: 34% are deeply transforming the business (new products, reinvented processes, rethought business models), 30% are redesigning key processes, and 37% are using AI at a surface level with little or no change to how work actually gets done.

Why it matters

Governance gaps in AI tooling are old news. A governance gap in autonomous, decision-making systems is a different category of risk, because the systems in question don't wait for a human to notice the process broke — they act, then the organization finds out. Deloitte's data says roughly 4 in 5 companies deploying agentic AI today are doing so without a mature control layer for exactly that failure mode.

It also matches a pattern Deloitte's report surfaces elsewhere: 42% of companies now say their AI strategy is highly prepared, but that confidence drops sharply the moment the question shifts from strategy to infrastructure, data management, risk and governance, and talent. Strategy confidence and operational readiness are measuring two different things, and the gap between them is exactly where agentic AI incidents happen.

The risk isn't that agentic AI doesn't work. It's that most organizations deploying it can't yet answer basic questions about it: who owns a given agent's decisions, what data it can touch, and how an action gets traced and reviewed after the fact.

Business and enterprise implications

For organizations already running or piloting agentic systems, the practical exposure sits in three places identified by the report and its companion NVIDIA survey: customer interactions, financial processes, and logistics chains — the exact places where an autonomous action is hardest to unwind quietly. The 37% of companies still applying AI at a surface level face a different but related risk: they're not exposed to agentic failure yet, but they're also not building the governance muscle before they need it, which means the transition from "surface-level AI" to "agentic AI" is likely to happen without the operating model catching up in time.

Deloitte's finding that education — training employees on AI tools — is the top talent response to AI adoption, while redesigning roles or workflows around AI ranks lower, reinforces the same gap from a different angle: organizations are investing in people knowing how to use AI tools before they've decided who's accountable for what those tools do autonomously.

Practical takeaway

Governance for agentic AI isn't a compliance checkbox to backfill after deployment — it has to be part of the same operating-model work as the deployment itself: clear ownership per agent or agent class, explicit data-access boundaries independent of the agent's own identity, and an audit trail sufficient to reconstruct what an agent did and why, after the fact. That's an operating-model and workflow-design problem before it's a tooling problem, which is exactly where a Discover → Prioritize → Design → Govern → Implement → Measure approach earns its keep instead of a bolt-on AI policy document nobody follows.

Sources