AI adoption is accelerating faster than enterprise oversight. Learn why human review, governance, and security remain essential for production AI agents.
Continue exploring similar guides and insights
OpenAI has reached a historic user milestone while continuing to invest heavily in AI infrastructure. Here's what the latest financial and adoption numbers actually mean.
Right now, inside a mid-sized financial services company somewhere, an AI agent is pulling a customer's account history from three internal systems and deciding what happens next. There's a decent chance nobody is watching it happen in real time.
That's not a hypothetical. It's the working baseline described in Gravitee's State of AI Agent Security 2026 report, and it's the clearest picture yet of a gap that's opened up faster than most companies have noticed.
The number that matters: the average enterprise AI agent fleet roughly doubled between December 2025 and April 2026. Monitoring coverage over that same window barely moved.
Gravitee surveyed 750 senior technology leaders across the UK and US in two waves, December 2025 and April 2026. Two numbers from that survey tell the whole story on their own:
That gap shows up in the incident data too:
Cross-referencing more than 200 open-text survey responses across both waves, Gravitee's researchers identified six failure patterns showing up again and again:
One more detail worth sitting with: confirmed incident rates actually dropped between the two survey waves, from 59.3% down to 34.9%. The report's read isn't that security genuinely improved while the agent fleet doubled and monitoring stayed flat, it's that more incidents are simply going undetected, not fewer are happening.
A separate June 2026 survey of enterprise leaders, run by VentureBeat's VB Pulse, found something almost paradoxical:
Researchers studying human oversight point to a specific mechanism: automation complacency. The more reliable a system appears to be, the less vigilant the humans watching it become, until the oversight exists on paper without actually functioning day to day. It's the same failure pattern documented in aviation and industrial safety literature for decades, just showing up now in a much newer context.
Not every "AI agent" means the same thing, and that ambiguity is part of why the trust gap is so hard to close. Researchers tracking the field describe autonomy as a ladder, and most enterprise deployments today are sitting on the first two rungs, not the top ones headlines tend to imply:
| Stage | What it actually does | Where it stands in 2026 |
|---|---|---|
| Task execution | Carries out a specific task using tool access, one job at a time | Today's frontier for most production deployments |
| Plan, execute, adapt | Handles a multi-step workflow, consulting a human at defined decision points |
That gap between where the technology actually is and where the marketing language implies it is matters. A company confident it's operating at "plan, execute, adapt" while its actual controls were only ever built for simple task execution is exactly the kind of mismatch that shows up later as an incident report.
This isn't only a research finding anymore, it's now a legal one in a major market. The EU AI Act's Article 14, which mandates demonstrable human oversight capabilities for high-risk AI systems, became enforceable on August 2, 2026.
In the US, similar pressure is building through existing frameworks:
The common thread across all of it: regulators are no longer satisfied with a human being loosely "available" somewhere in the process. What they're actually asking companies to demonstrate is three specific things, together, not just one:
Miss any one of the three, and "human in the loop" becomes a phrase on a compliance slide rather than something that functions under real pressure.
| Metric | Figure |
|---|---|
| Agent fleet growth, Dec 2025 to Apr 2026 | ~2x |
| Organizations with a suspected agent incident in 12 months | 54% |
| Enterprises moving toward zero-human review | 66% |
That last point is where most companies are quietly failing, according to researchers at Strata who study agentic identity and oversight design.
Most organizations confuse presence with practice. They assign someone to be "in the loop" without ever training that person on what to approve, when to escalate, or how to recognize the early signs of automation complacency in themselves. A named reviewer on an org chart isn't the same thing as a reviewer who's actually equipped to catch a bad decision under time pressure, any more than a pilot is ready for an emergency because they technically sat in the cockpit once.
McKinsey's research on what it calls "the agentic organization" found that 100% of surveyed companies now have agentic AI somewhere on their 2026 roadmap, while 89% are still running on the same industrial-age org structures built for a world without autonomous software making decisions. Only 1% have moved to the kind of decentralized structure the researchers argue agentic AI actually requires.
That mismatch, cutting-edge technology bolted onto organizational structures never designed to govern it, is arguably the real story underneath every statistic in this piece.
A schematic version of this same idea, the autonomy ladder with the two lower rungs lit and the upper two dimmed, is rendered directly above as an illustrative diagram.
Nobody serious is arguing AI agents should be pulled back to zero autonomy. The productivity case for delegating routine decisions is real, and it's why adoption is accelerating so fast in the first place.
The actual argument is narrower and harder to ignore: autonomy that outpaces verifiable oversight isn't a productivity story, it's a liability sitting quietly on the balance sheet until the first bad decision surfaces it.
| Emerging in the more mature deployments |
| Multi-agent coordination | Several agents working together, inter-agent driven | Projected for 2028-2029, not broadly live yet |
| Fully agent-driven operations | Minimal human involvement across an entire function | Early experiments only, requires governance maturity nobody has yet |
| Leaders who fully trust their own AI evaluations |
| 5% |
| Companies with agentic AI on the 2026 roadmap | 100% |