Key Takeaways
- Enterprise adoption is shifting from generative assistants toward agents that execute multi-step business processes.
- Rapid growth in agent activity could create substantial infrastructure costs and new security exposures.
- Access controls, approval gates, audit logs, and rollback procedures can help contain operational risk.
Warnings about artificial intelligence are getting louder, but capital spending and enterprise deployment continue to move in the opposite direction. The technology buildout is charging ahead despite unresolved questions about safety, accountability, and economic impact. The next phase is already taking shape: AI agents that do more than draft emails or answer questions.
These systems can plan tasks, call APIs, retrieve company data, and take actions across business applications. Gartner forecasts that 40% of enterprise applications will include task-specific AI agents by the end of 2026, compared with fewer than 5% in 2025. That is an unusually fast change in software design, particularly for technology that may receive permission to update records, contact customers, or initiate transactions.
Products such as Microsoft Copilot Studio, Salesforce Agentforce, and OpenAI’s Operator show where the market is heading. Rather than waiting for a user to enter each prompt, an agent can break an objective into steps and use connected systems to complete them. For businesses, the attraction is straightforward: more work completed with less manual coordination.
Every additional action creates another point where an agent can make a poor decision, expose sensitive information, or consume more computing resources than expected. Traditional chatbots generally return content for a person to review. Agents may act first, sometimes across several systems, which raises the potential consequences of inaccurate output or excessive permissions.
The scale envisioned by IDC makes those concerns harder to treat as edge cases. IDC predicts that agent use among Global 2000 companies will increase tenfold by 2027, while related token and API-call volumes rise 1,000-fold. It also projects more than 1 billion actively deployed AI agents by 2029, collectively executing over 217 billion actions each day.
That activity carries a financial dimension. IDC estimates that annual token-delivery costs could exceed $68 billion. A single agent request may trigger multiple model calls, database searches, validation steps, and external services. Multiply that workflow across millions of employees and customers, and an apparently inexpensive automation can become a material infrastructure expense. Who owns that bill when several departments deploy agents independently?
Cost is only part of the challenge. BERI has highlighted why enterprise agent projects can fail when organizations move from controlled pilots into production. Common pressure points include unclear objectives, unreliable integrations, weak cost controls, and insufficient supervision. An agent that performs well in a demonstration may behave differently when exposed to incomplete records, unusual customer requests, or conflicting instructions.
Practical controls can reduce the exposure. Least-privilege access limits agents to the data and functions required for a specific assignment. Sandboxing keeps early deployments away from production systems. Approval gates allow people to review high-impact actions, such as transferring funds, changing customer accounts, deleting records, or publishing external communications. Detailed audit logs and rollback procedures also make it easier to investigate and reverse problematic activity.
That said, governance cannot sit entirely with security or compliance teams. Business leaders define the process, technology teams connect the systems, and risk owners decide which actions require human authorization. Clear accountability matters because an autonomous action still has an organizational owner. The commercial race is unlikely to pause while those structures mature, so enterprises face a more immediate task: expanding agent use while maintaining explicit human accountability and monitoring.
⬇️