The next enterprise AI challenge is not deploying more autonomy. It is creating an operating model that can decide where autonomy belongs, control it and prove that it creates value.
Enterprise AI has reached an awkward stage. Organisations have spent the past few years building assistants, copilots and pilots. Agents are now beginning to execute work: calling systems, coordinating tasks, generating code, moving information and initiating actions.
The management system around them has barely caught up.
New research published this month makes that gap increasingly difficult to ignore. A Harris Poll study commissioned by Dataiku surveyed 685 CIOs across eight countries. 67% estimate that at least 51 AI agents are already running in production, yet 72% cannot consistently confirm whether all of those agents are delivering the business outcomes they were created to achieve. The same research found that 60% lack a central AI governance layer spanning enterprise applications, tools and IT environments.
IDC research sponsored by Leah presents the same issue from another angle. Among 410 enterprise decision-makers in the UK and US, 66% reported agents already in production. The average organisation reported 2.7 agents in January 2026 and expects 15.6 by January 2027. Only 7% reported advanced multi-agent collaboration with monitoring.
This is not principally a technology problem. It is an operating-model problem created by delegated work.
Deployment creates activity. It does not automatically create value.
The first wave of enterprise AI made experimentation inexpensive. That was useful: employees learned what models could do, functions discovered use cases and technology teams accumulated experience.
Agentic AI changes the economics because experimentation can now create action. An assistant produces something for a person to evaluate. An agent can participate in the workflow itself.
Once that happens, leadership needs clear answers to questions that are fundamentally organisational:
- What business outcome is the agent responsible for supporting, and who owns that outcome?
- What authority has been delegated, and which systems, data and tools can the agent access?
- Which decisions can the agent make independently, and where is human approval mandatory?
- What does the agent cost to run, including model, integration, assurance and exception-handling costs?
- What evidence shows that the agent is improving the end-to-end workflow rather than merely increasing activity?
- Who decides when the agent should be changed, constrained or retired?
Enterprises already answer equivalent questions for employees, suppliers, outsourced services and software systems. The mistake is assuming that agents require only another technology-control framework. They require an operating framework for delegated work.
The leakage begins when agent count becomes the metric
An organisation can deploy dozens of agents and still create very little enterprise capability. Agent count therefore risks becoming the next misleading transformation metric.
The Dataiku/Harris Poll findings show why. Only 28% of CIOs consistently measure both operational performance and business outcomes across all of their AI agents, while 81% lack complete oversight of agents created outside approved systems or formal channels.
An agent can therefore be technically operational while remaining economically ambiguous. It may execute tasks successfully but increase downstream review. It may reduce activity in one team while creating exceptions elsewhere. It may save employee time while adding inference, integration or assurance costs. It may duplicate another agent or optimise a task that should have been removed from the workflow altogether.
Counting agents, licences, prompts or automated tasks tells leadership very little about transformation. The relevant unit of analysis is the end-to-end workflow and its outcome.
The economic consequence is beginning to surface
The most useful evidence comes from comparing executive ambition with operating readiness. Oliver Wyman’s 2026 parallel surveys of CEOs and technology leaders found that 64% of CEOs expect agentic AI productivity gains of 11% to 20% over the next two to three years. Almost half of CIOs and CTOs, however, said current funding is sufficient to support only a 1% to 10% gain.
The funding gap matters. Only 29% of CEOs had ring-fenced funding for the platform, data and change work needed to make agents productive. The same research found that 61% of CEOs said the greatest gains come from re-engineering how work is performed and governing data, while only 4% pointed to buying and deploying the best tools.
These are survey findings and consultancy analysis, not audited ROI outcomes, so they should not be extrapolated into a universal business case. The direction is nevertheless important: organisations risk funding autonomy while underfunding the environment that makes autonomy useful.
AI does not repair an inefficient workflow merely because part of it becomes autonomous. It can automate the inefficiency, accelerate the exception rate, create more output for a downstream bottleneck and compound weaknesses faster than traditional processes can respond.
Governance has to move into the work
This also changes what governance means. A policy can state that an agent must not expose sensitive information, but it cannot physically prevent inappropriate access. A policy can define human accountability, but it cannot determine where a workflow pauses for judgement. A policy can impose a spending threshold, but it cannot enforce that threshold when an agent acts at machine speed.
Gartner’s September analysis of agentic AI governance makes the distinction explicit: written policies cannot control autonomous actions at machine speed. Gartner forecasts that by 2029, at least 70% of organisations running production agentic AI in infrastructure and operations will experience a material service, security or cost incident linked partly to inadequate runtime controls. This is a forecast rather than a measured outcome, but it illustrates the operational direction of travel.
Governance-by-design therefore means translating organisational intent into the architecture of work. Every production agent should have defined controls covering:
- Identity and ownership: who is accountable for the agent and the outcome it supports.
- Permissions: which systems, data, tools and actions are available.
- Decision rights: what can be executed autonomously and what requires approval.
- Financial limits: bounded spend, token usage and transaction authority where relevant.
- Human checkpoints: clear escalation routes and stop authority for exceptions.
- Evidence: logging, traceability and records sufficient for assurance and review.
- Performance thresholds: measurable operational and business outcomes, not simply task completion.
- Lifecycle criteria: explicit conditions for redesign, restriction or retirement.
This is where AI governance stops being a compliance document and becomes part of the operating model.
Enterprise autonomy should be earned, not assumed
The IDC/Leah research contains an important detail: none of the surveyed organisations reported fully autonomous operations with policy guardrails. Forty-six per cent allowed low-risk actions to be executed autonomously, 37% used agents to recommend actions that still required sign-off, and 9% permitted execution across workflows with audit controls.
That should not be read as failure. It suggests that autonomy is better treated as a spectrum rather than a destination.
A low-risk agent may retrieve information and recommend an action. A more mature implementation may prepare the transaction but require human authorisation. Bounded execution can become appropriate once performance, exceptions and controls are understood.
The objective is not maximum autonomy. It is the minimum human intervention consistent with acceptable value, risk and accountability.
The TFx operating-model perspective
The operating-model principles behind TFx are informed by prior enterprise transformation work where measurable AI outcomes came from the surrounding system: workflow integration, governance, enablement, ownership and measurement.
In an anonymised Fortune 500 environment spanning approximately 15,000 users, adoption increased from 15% to 68%. Alongside operating-model and workflow changes, measured outcomes included 38% greater efficiency, 73% lower resolution time and 63% lower compliance effort, contributing to $10–12 million in annualised ROI.
Those results should not be generalised into a universal AI business case. They demonstrate something narrower and more useful: technology becomes economically meaningful when the organisation changes the work around it.
That principle becomes more important, not less, when the technology can act autonomously.
The next operating model needs an agent portfolio, not an agent catalogue
Enterprises now need to treat agents as a managed portfolio of delegated capabilities. Every production agent should have:
- a defined business purpose and accountable owner;
- a mapped workflow and human decision boundary;
- explicit permissions and delegated authority;
- a transparent cost profile;
- an operational KPI and a business-outcome KPI; and
- a lifecycle state covering pilot, production, constrained, redesigned or retired.
This is not bureaucracy for its own sake. Without those attributes, the organisation cannot answer three basic questions: What is working? What is safe to scale? What should we stop funding?
The organisations that answer those questions will be able to decentralise AI development without losing organisational control. The strategic advantage will not come from having the largest digital workforce. It will come from having the clearest operating model for deciding where machine autonomy creates value, where human judgement remains essential and how the two operate as one system.
The executive question
If every AI agent in your organisation had to justify its authority, cost and measurable contribution tomorrow, how many would still deserve to be running?
Sources
- Dataiku / The Harris Poll — Global AI Confessions Report: CIO Edition, 24 September 2026
- IDC InfoBrief sponsored by Leah — The Three Pillars of the Agentic Enterprise, September 2026
- Oliver Wyman — Why IT operating models need to change before agentic AI, September 2026
- Gartner — Agentic AI Fails Where Governance Stops, 24 September 2026
Leave a Reply