Skip to main content
TechnologyJul 23, 2026· 3 min read

Agentic AI: The Race to Implementation Outpaces Governance Capabilities. An Analysis by Economist Enterprise

Agentic AI: The Race to Implementation Outpaces Governance Capabilities

The race for artificial intelligence is progressing rapidly. Both those who develop models and infrastructures, as well as those who adopt them, are involved. It’s a phenomenon we have seen with every disruptive technology to some extent. This time, however, there is one aspect that should not be underestimated: despite significant advances, AI, particularly agentic AI, is not yet a perfect tool, and allowing it to operate freely can create numerous issues, as we have recently seen with the case of OpenAI/Hugging Face.

A case that was extreme, fortunately without severe consequences, but which is likely to be repeated: according to the research "Power without control: Rethinking cybersecurity for the age of agentic AI" by Economist Enterprise and supported by Rubrik, companies are implementing AI agents too rapidly and are neither able to control them nor to swiftly restore systems in case of critical errors.

The fear of falling behind drives companies to take excessive risks.

According to the research, 98% of businesses that have adopted agentic AI have experienced at least one significant incident caused by this technology. However, no one seems interested in slowing down.

The point is that the business drive to implement new AI agents is strong, but security teams do not have the resources to govern all these entities.

Managers are not unaware: according to the analysis, 90% are aware of the problem but prefer to take risks rather than hold back on innovation, running serious risks. From heavy penalties for non-compliance with regulations to actual incidents that could compromise the enterprise's operations.

The study also shows that two-thirds of companies still do not have full visibility over their AI agents and, most importantly, are unable to react promptly if something goes wrong. Only 30% of sampled companies have robust, fully tested rollback capabilities, and 43% report that their recovery processes do not cover all agents or all types of incidents.

As Kavitha Mariappan, Chief Transformation Officer of Rubrik, explains, "Two-thirds of organizations cannot tell you what their agents did five minutes ago. When an incident develops at machine speed, this is not just an inconvenience; it's the difference between containment and catastrophe. We are implementing autonomous systems faster than we are building means to understand them."

What Should Companies Do to Control AI Agents?

The research identifies three capabilities that distinguish more resilient organizations from those likely to face greater difficulties in the event of an incident.

  1. Observability: Two out of three organizations do not have complete visibility over the agents in use. Without knowing what activities they are performing and with what effects on systems, detection, containment, and recovery become inevitably more complex.

  2. Response Speed: Incidents caused by agents can spread within minutes, drastically reducing the available time to intervene. Yet, only 30% of organizations have solid, already tested procedures to block or revert harmful actions.

  3. Periodic Verification of Recovery Plans: Defining a minimum configuration necessary to keep the business operational is not enough; among the 73% of organizations that have identified it, less than half subject it to regular testing. The risk is discovering only during an incident that the planned procedures do not work as expected.

For decades, cybersecurity has focused on keeping external threats out. Agentic AI fundamentally changes this paradigm. As the risk shifts inside organizations, strengthening the walls does not replace restoring the foundation," explains Vaibhav Sahgal, principal of technology at Economist Enterprise, who led the research program. "Disruption must now be taken for granted. Leaders should stop asking how to prevent it and instead think about how prepared their organization is to contain its impact and recover swiftly when it occurs."