New AI University AI Topics
← AI News

VentureBeat Research: Where enterprise AI agent governance hasn't caught up

Source: VentureBeat AI

Summary

  • Seventy-one percent of enterprises said a quarter or fewer of their deployed "agents" can complete multi-step work on their own.
  • This means most of their AI agents are actually chatbots that can only answer a single prompt.
  • Enterprises are planning to switch vendors or add new ones within the next year, and some are even planning to move within the next quarter.
  • The biggest issue is that autonomy is outrunning trust in the evaluations that gate it.
  • Two-thirds of enterprises are allowing agents to push code or system changes to production on automated evaluation results alone, without human review.
  • Companies that let agents share credentials are more likely to experience security incidents.
  • Sixty-nine percent of companies let at least some of their agents share credentials, and those that do are more likely to have experienced a security incident or near-miss.

Why It Matters

  • The rapid deployment of AI agents is outpacing the development of necessary controls to manage them.
  • This is putting enterprises at risk of security incidents and making it difficult for them to trust the evaluations that gate autonomy.
  • The lack of governance and controls is also leading to wasted resources, as the most expensive hardware is running at half capacity or less.
  • This is a warning sign for the AI industry as a whole, as the lack of proper governance and controls can lead to a loss of trust in AI systems.

GenAI EXPLAINED

What is an "agent"? An "agent" is a type of software that can perform tasks on its own, without human intervention. It can be a chatbot, a virtual assistant, or a more complex system that can complete multiple tasks. What is "autonomy"? Autonomy refers to the ability of an agent to make decisions and take actions on its own, without human oversight. What is "scoped identity"? Scoped identity refers to the practice of giving each agent its own unique identity, with its own set of permissions and access controls. This helps to prevent agents from sharing credentials and reduces the risk of security incidents.