Companies face governance gaps as agentic AI adoption grows

Agentic AI is beginning to emerge as a new phase of enterprise automation.
Unlike traditional AI models, these systems do not simply generate recommendations — they also execute tasks and make decisions inside complex technology environments.
By: Octavian Tanase, Chief Product Officer at Hitachi Vantara.
Technology teams inside organizations are increasingly overwhelmed by growing data complexity, expanding cyber threats and rising infrastructure demands.
As a result, companies need more than AI-generated recommendations. Agentic AI represents the transition from systems that advise to systems capable of acting and executing tasks autonomously. Organizations that continue using AI only as an assistant risk falling behind those deploying it as an operational layer.
This shift is not incremental. It reflects a structural transformation in how enterprise technology operates, moving from reactive support functions toward autonomous execution.
However, according to McKinsey & Company’s State of AI 2025 report, fewer than 10% of organizations have successfully scaled AI agents within any business function, highlighting the persistent gap between AI ambition and operational reality.
What agentic AI really means.

Most enterprise AI systems today still function primarily as advisory tools. Users submit requests and systems respond. Agentic AI operates differently: it monitors conditions, applies human-defined policies and acts on behalf of users without waiting for direct instructions.
The degree of autonomy granted to these systems makes a significant difference. A more cautious approach involves starting in recommendation mode before advancing toward full autonomy.
This allows organizations to establish governance mechanisms, test policies and introduce explainability into AI-driven decisions before operational risks increase.
Oversight and auditability are what make agentic AI suitable for enterprise deployment. Even so, according to Deloitte, only one in five companies currently has a mature governance model for autonomous AI agents.
Agentic AI also creates value in another area. Compute power has increasingly become commoditized through GPUs and cloud infrastructure, while many algorithms are now open source.
Data remains one of the few elements of the technology ecosystem that organizations can still differentiate and control. Companies need to correlate, enrich and fine-tune AI models using proprietary information they govern directly.
In an environment where models are becoming increasingly interchangeable, the quality, governance and accessibility of enterprise data are emerging as the true competitive differentiators.
The data foundation problem.
These governance gaps point to a deeper issue: data itself. If the foundation is weak, even highly sophisticated agentic systems will fail.
Agentic AI can only operate responsibly when it has governed access to trusted data.
Understanding this requires examining the three stages AI systems move through inside organizations.
Data preparation.
Organizations integrate structured and unstructured data into large-scale data lakes capable of scaling from petabytes to exabytes while maintaining sustainable cost structures.
Model training.
A curated subset of that data undergoes intensive processing, shifting infrastructure requirements from storage scale toward compute capacity.
Inference.
Trained models are deployed closer to users and operational environments, where infrastructure priorities shift toward ultra-low latency.
The phase receiving the least attention is often data preparation. Yet this is where governance is either established or neglected.
Organizations must manage data traceability, GDPR requirements and personally identifiable information before training begins. Data must be understood before it is used.
The governance imperative.
When deploying agentic AI, governance must be embedded directly into system operations. If a system cannot explain what it did, why it acted and which policy it applied, it is not ready for enterprise deployment.
According to a report from Hitachi Vantara, around 77% of organizations are actively developing AI governance programs, while 90% are already deploying AI technologies.
However, only 45% currently maintain a formal governance framework.
As a result, embedded governance is becoming a competitive advantage.
Still, governance frameworks alone are not enough. Zero Trust architecture functions as the enforcement layer that ensures governance is actually applied.
In an environment where agentic AI systems make autonomous decisions across complex infrastructures, the principle of “never trust, always verify” becomes increasingly essential.

