Deloitte's latest State of AI in the Enterprise research, drawn from 3,235 IT and business leaders across 24 countries, puts a hard number on something most operators already feel: only 21% of enterprises report having a mature governance model for agentic AI. Roughly four in five don't.

Meanwhile adoption isn't slowing down to wait for governance to catch up. 74% of organizations expect to use AI agents at least “moderately” by 2027, and 23% expect “extensive” usage. Agents are being handed real decisions well before most companies have defined which decisions they're allowed to make alone.

Deloitte's researchers point to three specific gaps in the organizations without mature governance: no clear boundary between what an agent can decide autonomously versus what needs human sign-off, no real-time monitoring for anomalous agent behavior, and no audit trail documenting the chain of actions an agent actually took.

That last one matters more than it sounds. When something goes wrong — a bad provisioning action, a data exposure, an agent that escalated a decision it shouldn't have made — “we're not sure what it did or why” is not an answer that survives a board meeting, let alone a regulator.

None of this is an argument against agentic AI. It's an argument for sequencing: guardrails and audit trails shipped alongside the agent, not bolted on after the incident that finally gets budget approved for them.