Enterprise AI Governance Is Missing Its Third Layer
Article excerpt
Highlighted: the sentence this signal was extracted from
By Joseph Ours, Forbes Councils Member. Joseph Ours leads the AI Strategy Practice at Centric Consulting. Gartner researchers project that 40% of enterprise applications will embed task-specific AI agents by the end of this year, but many organizations racing toward that number have governance frameworks that weren't designed for it. Those frameworks were built to answer two questions: Does the technology work, and has it been approved internally? Although both matter, a March 2026 federal court ruling established that a third question now carries legal weight: Does the platform your agent is operating on permit it to be there? For most enterprises, the question hasn't been asked and, worse, it can't be answered. Most organizations have invested in model risk management, human-in-the-loop checkpoints, role-based access controls and deployment review boards. However, according to McKinsey's 2026 AI Trust Maturity Survey of approximately 500 organizations, agentic AI controls lag behind every other governance dimension, with just 30% reaching meaningful maturity in that area. Those frameworks were designed for AI systems operating within organizational boundaries, on internal data, against internal systems and under internal supervision. By design, agentic AI operates across those boundaries. Agents interact with supplier portals, partner platforms, SaaS tools and...
Keep reading with a free account
The rest of this article, and every signal for Gartner, is in your free account.
