Agentic AI is scaling faster than the controls around it
Agentic AI has already moved from experiments into everyday operations for many organisations. Governance, however, is really struggling to keep pace.
New research by ProofID and Coleman Parkes, based on a survey of 300 enterprise decision-makers and influencers across the US, UK and Europe, shows how quickly adoption is moving. Almost 1 in 5 organisations already has agentic AI in production, while a further 47% expect to deploy it within the next 12 months.
But those headline numbers only tell part of the story. Every organisation surveyed reported some use of agentic AI. Among those without sanctioned production deployments, 43% said informal use was already quite extensive. This means a lot of agentic AI activity is already happening outside of formal deployment initiatives.
This can leave a significant blind spot. If you’re waiting for a formal production rollout before putting governance and control in place, you may already be living with agent activity you haven’t accounted for.
As agents become capable of accessing systems, using tools and taking actions with limited human intervention, you need to answer five fundamental questions:
- Discover: What agents exist across your organisation?
- Govern: Who owns each agent and its lifecycle?
- Connect: How does each agent interact with systems and services?
- Trust: What identity and permissions does each agent have?
- Observe: Can you see and intervene in what an agent is doing?
These aren’t five separate boxes to tick. They all depend on each other. You can’t govern an agent you haven’t discovered, control its access properly without a reliable identity, or respond effectively if you can’t see what it’s doing.
The objective is to make autonomy controlled, accountable and scalable.
Five pillars for agentic AI readiness
Our research points to five connected areas organisations need to address as agentic AI moves from experimentation into production.
1. Discover: Know what is operating
You cannot control what you cannot see. AI agents can enter your environment through sanctioned platforms, embedded capabilities, internal development and third-party tools. That makes visibility harder than it might first appear.
Only 22% of organisations surveyed maintain a complete central repository of their agents, while 40% are not confident they know every AI agent operating within their organisation.
Discovery isn’t a one-and-done job. Before you can decide whether an agent is appropriately governed or secured, you first need to know that it exists – and keep knowing as your agent estate changes.
2. Govern: Establish accountability
As agents take on more autonomous roles, you need clear accountability for how they operate, the decisions they enable and what happens throughout their lifecycle. Somebody needs to own each agent from the point it is introduced through to when it is retired.
The research found that 86% of organisations do not assign a human accountable for every agent, while only 14% have formal onboarding, offboarding and periodic re-certification processes for every agent.
Without a clear owner, a manageable experiment can quickly turn into an enduring control gap. Good governance puts the accountability and lifecycle discipline around agentic AI that you need if you’re going to scale it safely.
3. Connect: Control how agents interact
What an agent can reach shapes what it can affect. The more systems, tools and data it can interact with, the greater the potential impact of its actions.
If those connections are controlled differently from one system to the next, it becomes much harder to understand and limit that impact.
As many as 81% of organisations lack organisation-wide standards for agent integrations, while 88% do not route all agentic AI traffic through a central AI or MCP gateway.
As your agent estate grows, fragmented integrations can leave you with a patchwork of authentication, policy, logging and intervention mechanisms. Standardising how agents connect to enterprise systems gives you a much stronger foundation for applying control consistently.
4. Trust: Give agents an identity
For identity teams, the question is straightforward: which agent is acting, what is it authorised to do and how is that authority being controlled?
According to the research, only 17% of organisations give every AI agent a unique authenticated identity. Meanwhile, 52% report that many or all agents use shared credentials, shared identities or unmanaged identities.
Without a distinct identity, it becomes much harder to say with confidence which agent did what, or to apply access controls precisely. As the actor shifts from a person to an autonomous system, your approach to identity and access has to shift with it.
5. Observe: Make visibility actionable
Seeing activity is one thing. Being able to act on it quickly is what makes that visibility useful.
When autonomous systems can take actions without direct human intervention, you need to spot potentially risky or unauthorised behaviour quickly and intervene before the consequences spread.
As many as 82% of respondents lack full, real-time, organisation-wide visibility, and only 22% can automatically terminate a rogue agent in real time.
For systems capable of taking multiple actions in seconds, simply collecting activity data isn’t enough. You need enough context to understand what an agent is doing, whether it is still operating within its authorised boundaries and, crucially, the ability to step in quickly when it isn’t.
From adoption to controlled autonomy
Agentic AI adoption is accelerating, but our research suggests that organisational control is not advancing at the same pace.
Giving agents room to act doesn’t mean giving them free rein. As adoption scales, the boundaries around that activity need to keep pace.
That means treating discovery, governance, connectivity, identity and observation as connected disciplines rather than separate security tasks. As your agent estate grows, you need to know where agents are being used, how much authority they have, who is accountable for them and whether you can see – and stop – what they are doing when necessary.
The full 2027 State of Agentic AI Readiness report explores what 300 enterprise decision-makers told us about agentic AI adoption, visibility, identity, governance and real-time control, and examines the five pillars organisations need to build a more controlled and scalable agentic AI estate.
Download the full report to explore the research, findings and five pillars in more detail.
Frequently Asked Questions
Agentic AI readiness is your organisation’s ability to identify, govern, secure and monitor AI agents as they move into production. It goes beyond adopting the technology itself: you also need appropriate controls around agent identity, access, accountability and behaviour.
Visibility is the place to start. ProofID's research found that 40% of respondents are not confident they know every AI agent operating within their organisation, while only 22% maintain a complete central repository.
No. A risk-based approach allows you to distinguish between routine, low-risk actions and activities involving sensitive data, critical systems or higher consequences. The right level of human involvement depends on what the agent is doing and the risk attached to that action.
The five pillars identified in the research are Discover, Govern, Connect, Trust and Observe. Together, they provide a framework for putting visibility, accountability and control around agentic AI as adoption scales.