Optro Study Finds AI Governance Lagging Agent Adoption

New research from Optro has found that enterprises are deploying autonomous AI agents into core workflows faster than they are building the governance structures needed to control them, with nearly two-thirds of organisations reporting an AI agent-related incident in the past year.

The findings, drawn from Optro’s report “When AI Leaves the Chat and Enters the Workflow”, land as Singapore rolls out its own Model AI Governance Framework for Agentic AI, alongside a government-led sandbox for testing agentic systems — both of which emphasise human accountability, traceability and ongoing oversight as AI systems gain autonomy.

Confidence outpacing control

Optro, formerly AuditBoard, surveyed audit, risk, compliance and governance professionals across the US, Canada, UK, Germany, Ireland and the UAE. It found that while 58 per cent of leaders believe their governance controls are keeping pace with AI adoption, only 18 per cent have active risk mitigations in place.

  • 40 per cent of organisations reported inaccurate AI outputs in the past 12 months
  • 27 per cent reported data breaches tied to AI use
  • 26 per cent reported regulatory action linked to AI systems
  • 30 per cent have never tested for agentic AI failure at all
  • 85 per cent have integrated AI into core operations, but only a quarter have comprehensive visibility into how staff use it

Agents as unmanaged identities

The report frames autonomous agents as a new category of non-human identity — authenticating, accessing systems and acting on their own — that many IT departments have not inventoried. Business units are deploying agents that IT teams do not know exist, the study found.

“The reality today is that agentic AI adoption is fast outpacing governance,” said Guru Sethupathy, GM of AI Governance at Optro.

Sethupathy said the fix is not to slow AI adoption but to build the control structures that let organisations scale it with confidence. A separate executive quoted in the report, Mark Taylor, Director of Information Security Risk Management at Newell Brands, said teams that get agentic compliance right will build frameworks for how an agent behaves and what it can touch.

For Singapore and the wider region, the study’s authors said the closing window on governance design gives organisations a choice: redesign accountability on their own terms now, or do so later under enforcement or after an incident forces the issue.

Author


Discover more from techcoffeehouse.com

Subscribe to get the latest posts sent to your email.

Use promo code “TCH15” to get 15% off on checkout.

Share your thoughts

This site uses Akismet to reduce spam. Learn how your comment data is processed.

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading

Discover more from techcoffeehouse.com

Subscribe now to keep reading and get access to the full archive.

Continue reading