Briefing at a Glance

  • A Gartner report found that applying a unified governance strategy to all AI agents will increase the failure rate of enterprise projects. The firm predicts that by 2027, 40% of enterprises will decommission some agents because technology teams fail to distinguish between an agent's ability to take action and the scope of access it is granted.
  • Gartner Senior Director Analyst Shiva Varma told CIO Dive that many teams, when scaling tools to production, discover that agents have capabilities to perform actions beyond what was expected. "Many organizations either have no AI governance or agent governance at all, or they adopt a very generic policy approach," he said.
  • Gartner believes that adopting a proportional governance approach, setting different levels of permissions and autonomy for different agents, can help enterprises avoid such failures.

Deep Insights

Almost as soon as enterprises began adopting AI tools, companies had to establish human oversight and governance policies for autonomous agents with access to sensitive information. AI vendors have also invested in providing governance features to adapt to rapidly evolving agent workflows.

Gartner Senior Director Analyst Shiva Varma said many enterprises take a binary approach to AI agent governance: either full control or full trust. When all agents receive the same controls, organizations may over-restrict simple agents, slowing delivery and triggering shadow development; or they may under-restrict autonomous agents, increasing security and risk concerns.

Gartner recommends a proportional governance approach, setting four different levels of autonomy and boundaries based on the agent's role—observe, suggest, act with approval, and act autonomously. Varma said agents primarily used for reading or summarizing documents may only need baseline controls, such as limiting data access scope or user authentication.

But agents used to provide suggestions or generate recommendations requiring human review need higher levels of oversight, such as output quality review, hallucination testing, and training users on appropriate reliance. Varma noted that agents capable of acting with approval—such as sending communications or modifying configurations—require "meaningful controls."

Gartner said agents capable of performing independent actions autonomously need the most guardrails.

Varma said: "That's when you need to calibrate guardrails very, very specifically and carefully, and ensure you also do some human sampling."

Although 80% of technology leaders surveyed recently by Solvd said they feel pressure to make AI projects successful, Varma noted that enterprises with successful guardrails typically work with cross-functional teams, including technology executives, engineers, business units, and legal teams.

He said: "Governance shouldn't be the responsibility of just one person—that's already a failure mode. The key is that it's a shared, repeatable classification process, not a top-down directive from a single executive."