Connect with us

AI

Firms That Skip AI Control Deploy Far Fewer Agents

IBM’s 2026 Tech Leader Study finds firms that still govern AI by hand run a fraction of the agents, while spend heads toward a quarter of IT budgets.

Published

on

Organizations that build control into AI systems deploy 16 times as many agents as those still using manual governance, IBM’s Institute for Business Value found.

Chief executives ordered the scale-up anyway. Four in five of the 2,000 CIOs and CTOs in the 2026 Tech Leader Study, run with Oxford Economics, now sit under a CEO mandate to transform with AI, and only 11% said they were fully ready for the agent load expected in the year ahead.

The CEO Mandate Meets an 11 Percent Readiness Floor

The survey ran from January to April 2026 across 33 geographies and 19 industries. Two-thirds of the technology chiefs said they are held to account for AI systems they do not fully control, a gap the study traces to architectures still built for slower, more predictable software.

Matt Lyteson, IBM’s CIO, put the bind in operational terms rather than in strategy-speak.

For CIOs and CTOs, the challenge now is scaling AI systems that operate continuously and autonomously, often within governance models and architectures designed for a far slower, more predictable environment.

Matt Lyteson, CIO, IBM

The readiness numbers sit far below the mandate. 80% of respondents reported CEO-driven AI transformation orders. 77% said adoption is already outrunning current governance. 70% said teams across the business are deploying technology faster than IT can track.

THE MANDATE VERSUS THE FLOOR

  • CEO orders: 80% of tech chiefs reported a CEO-driven AI transformation mandate.
  • Ready for agents: 11% said they were fully prepared for the scale of AI agent deployment expected in the next year.
  • Governance lag: 77% said AI adoption is already outpacing current governance capabilities.
  • IT tracking: 70% said business teams are deploying technology faster than IT can track.

This is not a new crack in the IT stack. A 2024 IBM Institute for Business Value survey of 2,500 tech chiefs found that only 47% thought their IT organization was effective at basic services, down from 69% in 2013. Generative AI arrived after that confidence had already fallen, and agentic systems now act inside the same foundations.

Shadow AI, and the Partnership Roush’s CIO Wants

The 2026 study draws a sharper line than “teams move fast.” More than two-thirds of the CIOs and CTOs said business units bypass IT to adopt AI. That is a different question from the 70% who cannot track deployments, and it is the one that turns a visibility problem into an authority problem.

Experimentation was handed to the business. The blast radius stayed with the CIO. Unapproved AI does not sit idle on a laptop the way old shadow software did. It can recommend, reach sensitive data, and act inside a process. A policy describes intended behavior. It cannot stop an agent that nobody has listed.

Chris Pesola, CIO at Roush, said the aim is not to stamp out shadow IT. He wants visibility and a partnership so teams can get help when they need it without slowing down. That is a political settlement, not a control plane, and it only works if IT can see what is running.

Sanchit Vir Gogia, chief analyst at Greyhound Research, wrote that control becomes shared the moment AI touches several platforms at once, while accountability does not move with it. The operating test, in that view, is whether leaders can know what is running, what it can reach, what it can do, who owns it, and how it is stopped.

What 54 AI Agent Incidents a Year Cost

Surveyed organizations recorded an average of 54 AI agent incidents in the prior year, defined as an unintended or harmful occurrence that needed human correction. 17% of those incidents were high severity, meaning they took more than four hours to contain.

IBM’s write-up of the high-severity slice is not a complete partition, so the shares below should be read as overlapping outcomes rather than a tidy 100% split.

HIGH-SEVERITY AGENT INCIDENT OUTCOMES

Outcome Share of high-severity incidents
Data exposure or security breaches 37%
Cascading system failures 33%
Compliance issues 17%

59% of the tech chiefs named security and compliance concerns as the top barriers to scaling AI agents. Incident risk rose with adoption in organizations that still rely on manual governance. Firms that embed control directly in the AI systems had 25% fewer incidents.

Those security fears have a bill attached from a separate IBM document. The 2025 Cost of a Data Breach Report, conducted by Ponemon Institute across 600 organizations, found that 13% reported breaches of AI models or applications, and 97% of that group lacked proper AI access controls. One in five reported a breach tied to shadow AI. Organizations with a high level of shadow AI added $670,000 in breach costs compared with those that had little or none, $4.74 million against $4.07 million. Only 37% had policies to manage or detect shadow AI, and 63% of the breached organizations lacked AI governance policies.

Victoria Medina, chief technology and data officer at Allianz Spain, said AI has a light side and a dark side, and that many organizations are more exposed than they realize. Security is already the barrier most tech chiefs name, and IBM has separately moved to pair frontier models with enterprise security while this survey was in the field.

AI Spend Is Climbing Toward a Quarter of IT Budgets

The money is moving faster than the ledgers. IBM projects AI spend will grow from just under 15% of IT budgets in 2025 to nearly 25% by 2027, a 71% increase on the study’s own rounding of those bounds. 84% of the tech CxOs have not fully operationalized AI financial management. 85% still lack full visibility into real-time AI spend.

That is a control gap with a budget attached. Firms are about to put a quarter of the technology envelope into systems most of them cannot watch as the invoices land. Organizations with strong financial discipline, in IBM’s cut of the same survey, deploy 2.4 times as many agents with no higher AI or IT budget and are three times as likely to say they are fully prepared for scale.

Dalton Gouws, group IT director and board member at VWG UK Ltd, said his shop is keeping models plug-and-play because it does not know who will win over the next five years. Surveyed organizations that designed for adaptability early, keeping workloads portable and models replaceable, reported a 10% higher return on AI investment in 2025. Boris Alexandre, head of the ARP programme at Airbus in Canada, described the same idea as modular architecture that can absorb change without breaking products that live for decades.

16 Times as Many Agents When Control Is Built In

The ironic split is in IBM’s own segmentation. Organizations the study classifies as having orchestrated control, meaning control built into the system rather than layered on as human review of every output, do not scale less. They scale more, on less of the AI budget, with fewer incidents.

HOW IBM CUT THE SAME SURVEY

Segment What IBM’s analysis found
Orchestrated control vs manual governance 16 times as many agents; 18% higher operating margins; four times less of the AI budget; 25% fewer incidents
Strong financial discipline 2.4 times as many agents with no higher AI or IT budget; three times as likely to say they are fully prepared
Early adaptability, portable workloads 10% higher return on AI investment in 2025
Adaptability plus governance by design plus portfolio discipline 2.6 times as many agents already; 38% higher expected revenue growth and 7% higher expected operating margin for 2026

Those rows are different cuts, not four names for one elite club. The 16-times figure compares orchestrated control with manual governance. The 2.6-times figure is the group that stacked infrastructure adaptability, governance by design, and portfolio discipline. The 2.4-times figure is the finance cut. Mixing them into one league table would invent a ranking IBM did not publish.

By 2027, the surveyed leaders expect an average of 1,661 AI agents per organization, a 38% increase from the survey window. The study warns that each agent may make hundreds or even thousands of decisions a day, which is how a human review cycle falls behind the math. Manual governance, in that framing, is not cautious. It is too slow to be a real brake, so people go around it.

Gartner’s 150,000-Agent Forecast for the Fortune 500

IBM’s 1,661 figure is an average across the surveyed enterprises by 2027. Gartner is counting a different pile. On April 28, 2026, the firm said an average global Fortune 500 enterprise will have over 150,000 agents in use by 2028, up from less than 15 in 2025. Only 13% of organizations, in that research, think they have the right AI agent governance in place.

Max Goss, a senior director analyst at Gartner, said CIOs are already dealing with ungoverned sprawl that exposes firms to misinformation, oversharing, and data loss. He also said blocking sanctioned tools is a poor long-term answer, because staff will go around the controls and use shadow AI, which carries greater risk. That matches the IBM finding that business units already bypass IT.

GARTNER’S SIX STEPS AGAINST AGENT SPRAWL

  • Governance rules: Set when agents can be built, who may create and share them, and which connectors are allowed.
  • Central inventory: Discover sanctioned and shadow agents, then apply controls by risk level.
  • Identity and life cycle: Manage agent identity, permissions, review, and retirement so redundant agents do not pile up.
  • Information access: Govern what each agent can see, keep that data current, and archive it when it is obsolete.
  • Behavior watch: Monitor usage, catch agents that exceed their scope, and correct them.
  • Workforce practice: Train staff and share working patterns so the sanctioned path is the easy path.

The incident path is getting worse on Gartner’s clock as well. On April 9, 2026, the firm predicted that by 2028, 25% of enterprise generative AI applications will see at least five minor security incidents per year, up from 9% in 2025. It also said 15% will see at least one major security incident a year by 2029, up from 3% in 2025. Aaron Lord, a senior director analyst at Gartner, tied part of that rise to Model Context Protocol designs that optimized for ease and interoperability first, so mistakes show up without continuous oversight.

Afonso Eça, an executive board member at Banco BPI in Spain, described the job CIOs are being asked to do as flying at 10,000 feet, then being told to climb to 12,000, replace both engines mid-flight, and keep the ride smooth. He said no one would choose to pilot that plane, and that this is what companies are doing. The IBM numbers say the shops that rebuilt the controls before the climb are the ones that actually got more agents into the air.

Harry is the editor of Oton Technology, an independent site he owns and edits, covering the part of technology that people actually have to act on. After ten years in journalism, first reporting and then editing, he works from primary material by habit: the advisory rather than the write up of it, the filing rather than the press release, the changelog rather than the launch video. Every figure in an article carries its source and its date, and where a number comes from a vendor or an analyst model rather than a count, he says so plainly instead of letting it stand as established fact. What he leaves out is anything he could not verify himself, which on a beat full of unnamed supply chain claims removes a great deal. That standard applies across all the sections the site publishes for an international audience, from artificial intelligence and security to phones, computers, gaming, crypto and the software businesses depend on. He corrects errors in the open and labels them, because a site that hides its mistakes is asking readers to trust the rest on nothing.

Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending