
Enterprises have put AI agents ahead of the controls needed to manage them, and they’ve done it deliberately. That’s the central finding of VentureBeat Research’s June survey of five parallel surveys covering every layer of the agent stack. Now, those businesses are updating and budgeting to catch up: In each of the five control layers we measured, 57-68% of businesses plan to change vendors or add new ones within 12 months, and about a third, depending on the layer, plan to move within a quarter.
VentureBeat Research measured five controls that an enterprise must establish before trusting an agent: identity, assessment, cost telemetry, context layer, and orchestration. Identity controls which agent is allowed to do what under whose authority. Evaluation determines whether the agent is doing well. Spend telemetry tracks what each agent spends on. The context layer provides business information and definitions that agents use when responding. And the orchestration control plane coordinates multi-step agent work. Each of our five reports measures one of these controls.
Most placed "agents" are chatbots wearing the label. 71 percent of businesses said a quarter or less of them were accommodated "agents" able to perform multi-stage tasks independently; only 10% said real agents are the majority of what they manage. These respondents should know: 81% recommend or decide to purchase AI in their company. A one-line chatbot that reads every human response doesn’t need any of the controls that the other four reports measure. A true multi-stage agent needs them all, and most businesses can’t tell which one they’re deploying. (Full findings: Agent Orchestra report.)
Autonomy transcends trust in the evaluations that surround it. Two-thirds of enterprises either already allow an agent to make code or system changes to production based on automated assessment results without any human review, or are actively engineering to do so within 12 months. Only 5% fully trust assessments to make this call, and half of businesses sent an agent who went through internal assessments and then failed a customer-facing one in the past year. Before taking the human view out of any workflow, check assessments against production results, not internal benchmarks. (Full findings: Agent Reliability and Ratings report.)
Companies that allow agents to share their credentials are hit more often. Sixty-nine percent of companies allow at least some of their agents to share credentials—multiple agents operating under a single API key or service account. Organizations that allow credential sharing anywhere have experienced a security incident or hijack at a rate of 63.5% (47 of 74) versus 40.9% (9 of 22) in companies where each agent has their own scope. The fix is a comprehensive identity for every agent, starting with those that touch production systems. (Full findings: Agency Security and Privacy report.)
The most expensive equipment in the building is operating at half capacity or less. More than eight in 10 enterprises that manage their own GPUs report 50% utilization or less, and only 44% seriously track what AI computing actually costs and returns. First, the number worth chasing isn’t more GPUs—it’s the utilization of the overclockers and the cost per workload. (Full findings: AI Infrastructure and Computing report.)
Agents respond with confidence from data that no one else controls. 57 percent of enterprises have experienced a confident, incorrect agent response to their missing or inconsistent business context—incorrect metrics, outdated definitions, missing documentation—in the past six months, and most have seen it happen more than once. Managing the definitions to which agents respond—primarily metrics and institutions—must come before measuring the agents that depend on them. (Full findings: Context layers / RAG report.)
No layer has an entrenched incumbent: Today, the defaults are in-house tools powered by the big AI platforms that enterprises already use. Intent to switch is highest in the orchestra itself, with 68% planning to adopt, add or change platforms within 12 months, and 34% within the quarter. Our polls didn’t ask which way the money was moving — toward the platforms’ internal tools or the experts challenging them — and that open question is the next quarter of this market.
About this study
VentureBeat Research In June 2026, VB conducted five parallel surveys under the Pulse program: Agency Orchestration (101 respondents), Agent Reliability and Evaluations (157), Agency Security and Identity (107), AI Infrastructure and Computing (107) and Context Layers / RAG (101) – organizations with a total of 570 or more responsible employees. The samples are self-selected and some findings should be read in direction; each report carries its own full methodology note. It is the direction that the sample supports more strongly than any percentage: each survey, independently, points the same way. VentureBeat covered both this research and VB Transformconference where these reports debuted.





