Over the past months almost every IT leadership team has seen the same demo: an AI agent receives a request, queries three separate systems, drafts a response and closes the case without anyone touching a keyboard. It works, and it works well.

Then the agent leaves the demo and enters a real process, and the story goes in one of two opposite directions. In one, it is surrounded by so many approval steps that it becomes slower than the person it was meant to support. In the other, it operates with overly broad permissions until it reaches data or a system it should never have touched.

The common reading is that the problem is model maturity. But in organisations actually moving agents into production, a less comfortable and more useful question emerges: autonomy should not be an on/off switch, but a design parameter calibrated against risk. And that is not a policy choice made downstream — it involves architecture, security, process and accountability, and it has to be settled before the agent goes live.

The problem: autonomy granted as a switch

In May 2026 Gartner put a number on the pattern: by 2027, 40% of enterprises could demote or decommission autonomous AI agents because of governance gaps that surfaced after deployment. It is a forecast rather than an observed outcome, but it points at where the risk sits

The point is not that agents are inherently unreliable, but that organisations apply one control model to systems with completely different autonomy and access perimeters. Treating governance as a binary choice — fully locked down or fully trusted — then produces two mirror-image failures.

On one side, simple agents — an assistant that reads documents and proposes a classification — get controls designed for systems that modify data or execute critical operations: the value disappears into approval latency and the project is filed away as “interesting but impractical”. On the other, agents that genuinely act on production systems end up with permissions that are too broad, without granular monitoring, a dedicated identity or a way to interrupt them: that project does not die of slowness, it risks producing an incident.

Both share the same confusion: what an agent is capable of doing and what it is permitted to do are treated as one property. They are independent dimensions. A highly capable agent can sit inside a very narrow perimeter; a simple one can become risky with excessive credentials.

Photo by Steve A Johnson on Unsplash

What is changing

The difference between a copilot and an agent is not the amount of “intelligence” involved: it is where the work ends. A copilot produces an output that someone reviews, and control happens at the result. An agent executes an action — opens a ticket, updates a record, changes a configuration — and once the action has been taken it may already be too late. Control therefore moves to the perimeter: which data the agent sees, which identity it uses, which tools it can call, which actions it can and can never perform, what must trigger a stop.

Not every automation using a language model is an “agent”, though. The boundary between automated workflows, copilots and genuinely agentic systems is not sharp: before selecting a solution, define how much autonomy is actually being introduced.

Evidence and data

Adoption, meanwhile, is accelerating. According to McKinsey’s State of AI 2026, 40% of respondents at organisations above $1bn in revenue are scaling AI agents, against 22% at smaller ones. But growth in adoption does not mean growth in value: in the same research 37% report an AI impact on EBIT, unchanged year on year, and only around 6% attribute at least 5% of EBIT to AI.

Where agentic deployment is still early, the picture sits one step further back. In Italy, the AI market reached €1.8bn in 2025 (+50% on 2024) and 71% of large enterprises had already started at least one AI project (Artificial Intelligence Observatory, Politecnico di Milano). Many organisations still have to decide not only whether to use agents, but how to govern them.

The problem is not the technical maturity of the models, but the difficulty of turning them into systems that are reliable, sustainable and governable. Gartner forecasts, for that matter, that over 40% of agentic AI projects will be cancelled by the end of 2027 because of escalating costs, unclear business value and inadequate risk controls.

1. Not everything labelled “agentic” actually is

Gartner has highlighted “agent washing”: the market uses the term agentic AI for solutions with very different levels of autonomy. The issue is not terminological. If you cannot distinguish an automated workflow from an agent able to plan and act across multiple tools, you cannot assess its risk, cost and governance: vendor selection therefore becomes part of governance itself.

2. Data remains a precondition

An agent cannot be more reliable than the data and the systems it operates on. In 2025 Gartner forecast that through 2026 organisations would abandon a significant share of AI projects unsupported by properly prepared data, while also finding a widespread shortfall in data readiness practices. Before automating a decision, you need to know which data feeds it, who owns that data and how dependable it is.

Agents, in other words, can fail upstream, through problems of data and process, and downstream, through insufficient permissions, security and governance.

What it means for businesses

The first consequence is that agent governance cannot be just a document: it belongs in the architecture, the processes and organisational accountability. A policy stating that “agents operate under human supervision” is worthless if the agent acts with the credentials of a shared service account, because it becomes impossible to reconstruct who did what. A dedicated identity, least privilege, logging and traceability are technical preconditions, designed alongside the use case.

The second is that the cost of control must be proportionate to the risk. Every human approval carries a price in time and attention: placing one where it is not needed does not produce safety, but an approval rate close to 100% from people who have stopped reading.

The third concerns security. An agent that reads data, calls tools and takes actions is a new attack surface: prompt injection, tool misuse, privilege escalation and the chaining of errors across systems have to be considered at design time. The question is therefore not only “what happens when the agent gets it wrong?” but also “what happens if someone deliberately tries to make it behave badly?”.

The fourth is organisational. Whoever approves needs to know what they are approving, whoever receives an output needs to know how it was produced, whoever owns the process needs to know when to stop the agent. AI literacy is not merely a useful skill: it is the condition for human oversight to work.

Photo by Kelly Sikkema on Unsplash

The EU AI Act: a moved deadline is not postponed work

The Digital Omnibus on AI was formally adopted as Regulation (EU) 2026/1744, published in the Official Journal on 24 July 2026 and in force since 27 July. The revised timetable defers certain high-risk provisions: to 2 December 2027 for systems classified under Article 6(2) and Annex III, and to 2 August 2028 for those falling under Article 6(1) and Annex I.

This is not a general suspension of the AI Act: Chapters I and II have applied since 2 February 2025, with specific exceptions, and the Article 50 transparency obligations keep their original date of 2 August 2026.

A deferred deadline therefore does not remove the work of classifying use cases, governing data, assigning accountability and building effective controls: the same components required to run an agent reliably in production.

Photo by Sasun Bughdaryan on Unsplash

A practical perspective: four levels and an exit criterion

The model Gartner proposes is simple but operational: classify each agent by its level of autonomy and apply proportionate controls.

  1. Observe. Read-only access: the agent analyses documents, retrieves information, flags anomalies. Baseline controls on data access, authentication and logging are enough.
  2. Advise. The agent produces recommendations; execution stays human. The risk is not only AI error but automation bias: the tendency to over-trust an automatically generated recommendation. This calls for output quality testing and user training.
  3. Act with approval. The agent executes actions, but only on explicit approval. You need traceable workflows, audit trails, security testing and incident handling — and verification that the approval stays meaningful.
  4. Act autonomously. The agent executes permitted actions within defined guardrails, with continuous monitoring, operational limits, fast rollback, circuit breakers and assigned accountability.

The framework becomes operational with four questions per agent, closed before it goes live: which data does it see, and under which identity? Which actions can it take, and which never? What happens when it gets something wrong, or when it is attacked? Who notices, and what gets stopped?

The missing piece: the promotion criterion

An agent should not move up a level because the programme is behind schedule or because manual approvals have become inconvenient, but because it has accumulated measured evidence: human correction rate, number and severity of incidents, accuracy on representative samples, cost per case, adherence to security limits.

The same criterion has to work in reverse: an agent crossing an error or risk threshold drops back automatically, rather than waiting for an incident to become a meeting. Autonomy is not a permanent promotion, but a revocable level granted on evidence.

Three recurring mistakes

  1. Starting from the agent instead of the process: without redesigning the flow, automation reproduces existing inefficiency faster.
  2. Defining no exit criteria, turning autonomy into a decision taken once and never revisited.
  3. Confusing oversight with security: if the agent can be manipulated, a human in front of the approval does not remove the risk.

The DMBI perspective

An effective approach starts from the business problem, not from the agent. Before the technology comes the process: where the data originates, who uses it, which decisions are taken, where errors concentrate. From there the sequence builds up step by step — business problem, process, data, technology, controls, business value — avoiding the most expensive trap of this phase of AI: choosing the tool before defining the problem.

This is why a significant part of the work on an agentic project does not look like AI work at first sight: it is data architecture, data quality, data governance, cybersecurity and process design. Disciplines that matter even more once a system does not merely suggest a decision but can help execute it.

Conclusion

The problem with AI agents is not deciding whether to trust the technology. It is deciding where autonomy creates value, where it introduces risk, and which conditions must be met before granting it.

The organisations that will have agents genuinely embedded in their processes in the coming years will not be the ones that trusted most, nor the ones that controlled everything. They will be the ones able to answer, for each individual agent, a more concrete question: how autonomous can it be, in this process, with this data, these permissions and this level of risk? Autonomy is not a property granted once and for all: it is a design parameter, to be measured and revised over time.

Edited by Claudia Paniconi  — Marketing Manager, DMBI Consultants

Featured photo by Towfiqu barbhuiya on Unsplash

Sources

  • Gartner, “Gartner Says Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure”, 26 May 2026 — https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
  • Gartner, «Gartner Predicts Over 40% of Agentic AI Projects Will Be Canceled by End of 2027», 25 giugno 2025 — https://www.gartner.com/en/newsroom/press-releases/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027
  • Gartner, «Lack of AI-Ready Data Puts AI Projects at Risk», 26 febbraio 2025 — https://www.gartner.com/en/newsroom/press-releases/2025-02-26-lack-of-ai-ready-data-puts-ai-projects-at-risk
  • McKinsey & Company, «The State of AI: Global Survey 2026 — On the road to ROI», 25 agosto 2026 — https://www.mckinsey.com/capabilities/quantumblack/our-insights/the-state-of-ai
  • Artificial Intelligence Observatory, Politecnico di Milano, press release on the Italian AI market, February 2026 — https://www.osservatori.net/comunicato/artificial-intelligence/intelligenza-artificiale-italia/
  • European Union, Regulation (EU) 2026/1744 (Digital Omnibus on AI), published in the Official Journal on 24 July 2026 — https://eur-lex.europa.eu/eli/reg/2026/1744/oj
  • European Commission, “AI Act — Regulatory framework for artificial intelligence” — https://digital-strategy.ec.europa.eu/en/policies/regulatory-framework-ai
  • NIST, “Artificial Intelligence Risk Management Framework (AI RMF 1.0)”, 2023 and subsequent updates — https://www.nist.gov/itl/ai-risk-management-framework

Related content

AI & climate change

Last summer’s reports clearly show how delicate and precarious the balance of our ecosystem is. For experts in the field, extreme climate phenomena are destined to increase in frequency and intensity, if the levels of CO2 in the atmosphere are not reduced as soon as possible.

Read more »

DMBI consultants

via Candido Galli, 5 – Frascati
00044 – Roma
info@dmbi.it
Fax | Tel +39 06 9422 421
Part. IVA 09913981008