- The AI controls most organisations have built are controls for AI that advises: check the output, protect the data, guard the intellectual property. Agents act, which is a different kind of risk.
- Mitigation has genuinely improved. McKinsey's 2025 State of AI finds the average organisation now actively manages about four types of AI risk, up from two in 2022, led by inaccuracy, cybersecurity and IP.
- But those are yesterday's risks. As 23% of organisations scale agents that plan and act across steps, the question shifts from "was the answer right" to "did it take the right action, and could we stop it."
- The gap is showing up. Gartner expects over 40% of agentic AI projects to be cancelled by 2027, largely for weak controls, and only 21% of organisations have a mature model for governing autonomous agents.
- Upgrade control to match: govern the action not just the output, design where a human must approve, and make sure every agent can be stopped mid-task.
You did the responsible thing. Over the last couple of years you built real controls around AI: someone reviews the outputs, the data is protected, legal keeps an eye on the intellectual property. It felt like maturity, and it genuinely was. Then you switched on your first agents, the ones that do not just answer a question but go and carry out the task, and a quieter question arrived that your control framework does not obviously answer. If this thing acts on its own and gets it wrong, what actually stops it?
Here is the distinction worth holding onto. The controls most organisations have built are controls for AI that advises. McKinsey's 2025 State of AI finds the average organisation now actively manages about four types of AI risk, up from two in 2022, and the ones they manage most are inaccuracy, cybersecurity and intellectual property. Those are the risks of a system that produces an output a human then checks and acts on. Agents are a different animal: 23% of organisations are already scaling them, and they plan and execute across several steps rather than waiting to be checked. When the machine acts, "was the answer accurate" stops being the whole question, and "did it take the right action, and could we halt it" becomes the rest.
What changes when AI acts instead of advises?
The point of control moves. With advisory AI, the human is the circuit breaker by default: nothing happens until a person acts on the output, so reviewing the output is genuinely enough. An agent removes that pause. It acts, and you find out afterwards. So control has to shift upstream and wrap around the action itself: what is this agent allowed to do unsupervised, where must it stop and ask a human, and how exactly would you stop it in the middle of a task that is going wrong.
McKinsey's own numbers hint at the lag. Risk mitigation is rising, which is good, but it is rising on the familiar risks, inaccuracy and cybersecurity and IP, not on the new ones that autonomy introduces: an agent acting outside its intent, chaining a small error into a large one, or making a string of decisions nobody watched. Your job is increasingly to design the loop the agent runs inside, and the guardrails are part of that loop, not a review that happens after it.
Is the risk theoretical, or is it already showing up?
It is showing up in the failure rate. Gartner expects more than 40% of agentic AI projects to be cancelled by the end of 2027, largely for weak controls and unclear value. And the foundation is thin: only 21% of organisations report a mature model for governing autonomous agents, according to Deloitte. So the two curves are diverging. Adoption of agents is accelerating, while the controls actually designed for them remain the exception rather than the rule.
That divergence is exactly where an unattended action does quiet, expensive damage. It is the same shape as why most organisations fail at AI adoption: the capability lands faster than the human system built to hold it, and the gap between the two is where the value leaks out and the risk seeps in.
Upgrade your AI controls before your agents outrun them
The AI Strategy Session helps you move from controls built for AI that advises to ones that can govern, and stop, AI that acts, in ninety minutes.
Book your Strategy SessionHow do I upgrade controls for AI that acts?
By re-earning control rather than assuming the old controls still cover you. A few moves make the difference.
- Keep the human as a designed circuit breaker, not an accident. Decide deliberately where a person must approve before an agent acts, rather than trusting that someone happens to be watching.
- Govern the action, not just the output. For each agent, define what it may do unsupervised, where it must stop and ask, and what it must never do at all.
- Build a stop. Every agent in production needs a way to be halted mid-task and a named person whose job is to pull it. These are precisely the oversight questions a board should be asking.
- Widen the risk list on purpose. Add the risks autonomy creates, acting outside intent, chaining errors, unmonitored decisions, to the four you already manage well.
- Measure the action, not only the accuracy. Review what your agents actually did, on a cadence, rather than only checking whether their answers looked right.
Controls for AI that advises check the answer. Controls for AI that acts must govern the action, and be able to stop it. Agents need the second kind.
What does this change for me as a leader this quarter?
It reframes the maturity you have already built. Those controls are real and worth keeping; they are simply scoped to yesterday's AI, the kind that suggests. As you move to AI that does, treat control as something to re-earn rather than assume, and check that your guardrails cover the action and not just the answer.
The organisations that scale agents safely will not be the boldest ones. They will be the ones who upgraded their guardrails at the same pace they upgraded their ambition, so that autonomy arrived with a brake attached rather than a hope. Before you hand an agent the keys this quarter, make sure you have kept the ability to stop the car.
| Source | Finding on AI risk and control |
|---|---|
| McKinsey, State of AI (2025) | The average organisation now actively manages about four types of AI risk, up from two in 2022, led by inaccuracy, cybersecurity and intellectual property, all risks of AI that advises |
| McKinsey, State of AI (2025) | 23% of organisations are scaling an agentic AI system somewhere and 62% are experimenting with agents, which plan and act across steps rather than waiting to be checked |
| Gartner (2025) | Over 40% of agentic AI projects will be cancelled by the end of 2027, largely for weak controls and unclear value |
| Deloitte, State of AI in the Enterprise (2026) | Only 21% of organisations have a mature governance model for autonomous AI agents |
Frequently asked questions
Why aren't existing AI controls enough for AI agents?
How risky is deploying AI agents without stronger controls?
What controls do AI agents actually need?

About the author
British technology futurist, AI keynote speaker and advisor. Thirty years across enterprise technology and AI strategy, helping leaders navigate the future of work. The futurist who died.