I can’t remember the last time a CDO or CIO couldn’t tell me how many AI models they’d licensed. I also can’t remember the last time one could tell me how many agents were actually running in their environment, what data those agents could reach, or who signed off on giving them access. That gap between deployment and oversight isn’t a rounding error. It’s the defining risk of enterprise AI in 2026, and most leaders I talk to already sense it, even when they can’t yet put a number on it.
OutSystems’ 2026 State of AI Development report, based on a survey of nearly 1,900 IT leaders, puts a number on it. Ninety-six percent (96%) of enterprises are already running AI agents in some capacity. Ninety-seven percent (97%) are exploring organization-wide agentic strategies. Only 12% have a centralized platform to manage and govern those agents. That’s an 84-point gap between how many organizations have agents in production and how many can actually see what those agents are doing.
Ninety-four percent (94%) of the same respondents say agent sprawl is adding complexity, technical debt, and security risk. They know the gap exists. I don’t think that’s naivety. I think it’s a bet: that governance can be retrofitted later, faster than a competitor can pull ahead now. I’ve watched that bet lose before, on data platforms long before anyone said the word “agent.”
The Wrong Fix Is Already Shipping
Watch where the vendor money is going and you’ll see the industry’s working theory: the gap is a tooling problem. Buy a control plane. Bolt on an audit dashboard. License a real-time monitoring layer that sits on top of whatever agents already exist. Several major consultancies have launched exactly this kind of product in the past month alone, and I understand the appeal. It’s a fast thing to sell and a fast thing to buy.
I don’t think it’s the fix. A monitoring layer doesn’t answer the question that actually matters: who decided this agent could touch this data, and on what basis? If the honest answer is “nobody decided, it just got connected,” a dashboard will surface that fact faster. It won’t be the thing that fixes it.
This is where the OutSystems data gets more interesting. Thirty-eight percent of organizations report mixing custom-built and pre-built agents inside the same environment, which means most enterprises don’t have one AI stack. They have several, assembled at different times by different teams, each with its own access assumptions. You can’t centrally govern something that was never centrally designed. The sprawl isn’t a symptom of missing tools. It’s a symptom of agents being deployed faster than anyone decided who owns the data they run on.
Governance Is a Data Problem Wearing an AI Costume
Every AI governance conversation I sit in eventually turns into a data conversation, whether the room realizes it yet or not. An agent’s risk profile is entirely a function of what data it can reach and how well that data is classified, owned, and controlled. Strip away the agent framing and the question underneath is one data leaders have faced for twenty years: do we know what data we have, who’s accountable for it, and what it’s allowed to touch?
Most organizations don’t, which is why the governance conversation stalls at the same point every time I see it happen. Someone proposes a policy. The policy requires data classification that doesn’t exist, ownership that no one has claimed, and access controls the platform team hasn’t prioritized because it was never anyone’s job. Getting from policy to working governance takes longer than the roadmap says, and it depends entirely on whether the data foundation underneath it was built to support the decision in the first place.
That’s the reframe worth sitting with: the agent is not the control point. The data is. An organization that knows exactly which datasets are sensitive, exactly who owns them, and exactly what “approved for agent use” means for each one can govern any number of agents, built by any number of teams, on any platform. An organization that doesn’t will keep buying monitoring tools that watch a problem they can’t actually stop.
What the 12% Are Probably Doing Differently
I’d bet – and the OutSystems data is consistent with this, even if it doesn’t state it directly – that the 12% with centralized governance didn’t get there by adopting a platform first. They got there by doing the less visible work: establishing data ownership before agents needed it, classifying sensitive data before an agent tried to access it, and building the operating model that makes “who approved this” a five-minute answer instead of a forensic exercise.
None of that shows up in a product demo. I’ve seen it show up in outcomes instead: incident response measured in hours instead of weeks, audit questions answered from a system of record instead of a scramble across five teams, and a straight answer when a regulator or a board member asks which agents can touch customer data.
The regulatory runway for figuring this out is getting shorter. The EU AI Act’s general-purpose AI obligations take full effect on August 2. Waiting for a governance platform to solve a data ownership problem is not a strategy so much as a delay.
The Implication
Ninety-six percent adoption and 12% governance isn’t a technology gap. It’s an operating model gap wearing a technology problem’s clothes. Organizations that close it will do so by fixing the data foundation underneath their agents, not by adding a layer on top of them. Organizations that don’t will keep discovering, one incident at a time, that the agent was never the risk. The ungoverned data behind it always was.
By Jeremy Stierwalt, Chief Data & AI Officer
