The old startup motto “Move fast and break things” takes on a decidedly different meaning when agentic AI is involved.
In just nine seconds, an AI agent destroyed PocketOS’s entire production database. A Claude Code agent deleted the production database of course management platform DataTalks.Club, including more than two years’ of students’ submissions and homework. A Replit agent wiped yet another production database — and then lied about it.
These are far from the only horror stories of agentic AI gone rogue. McKinsey's State of AI 2025 reported that about 51% of orgs have experienced an AI-related incident, and that number is almost certainly climbing as we speak. These incidents add up to a single, very valuable lesson for organizations of all sizes: Without the proper governance and controls, agentic AI can be dangerous, deceptive, and very costly.
Leading organizations learned this lesson early on. Rather than running headlong into the latest and greatest agentic systems and worrying about the oversight later, the companies getting the most value from AI agents built governance capabilities first and adopted agentic AI second.
They also understood that governance isn’t just a set of guardrails. It’s an enabler of innovation, a backstop against costly rework — and a preventative layer between the company and potentially devastating rogue actions.
Here’s a hypothetical: What might happen if your organization made a new hire and, in the interest of enabling them to make an impact quickly, gave them complete access to all your systems and tools and the ability to communicate externally when and where they saw fit?
That’s exactly what’s happening with agentic AI in many organizations today, and it’s going about as well as you’d expect.
This is precisely why governance matters so much for AI agents. It may seem like an impediment to speed, but speed without control is a recipe for disaster. In fact, the organizations moving fastest with AI are the ones that built in controls from the start, not the ones that skipped them. Today’s highest-performing organizations are managing AI risk deliberately with human-in-the-loop rules, centralized oversight, and executive accountability.
And everyone else?
Gartner predicted that 40% of agentic projects would be cancelled by 2027, due, in part, to inadequate controls. McKinsey reported that 80% of organizations had already encountered risky agent behavior, including improper data exposure and unauthorized system access. Deloitte, meanwhile, reported in 2026 that just 21% of organizations have a mature model for governing autonomous agents.
In other words, too many organizations are focused on finding the right tools, while too few are building the governance required to avoid fragmentation, minimize duplication, mitigate risk, and scale effectively. When the agents misfire — and they will — these organizations will discover that they have too little oversight, too little control, and, in many cases, no way to limit the extent of the damage.
Many organizations have some degree of AI governance already, but it’s rarely the degree of control required by agentic AI.
Non-agentic AI governance — the kind most organizations have today — typically focuses on foundational elements, like model accuracy and transparency and general usage and cost controls. Agentic AI, on the other hand, requires those same elements of governance, but it also creates the need to answer other, much more difficult, questions.
Namely, when a system plans its own steps, calls tools, and acts across your environment with little or no human intervention, the questions become “Who is accountable when it acts?” and “Can you stop it in time?”
If your organization has already begun following guidance from a source like the NIST AI Risk Management Framework, the good news is that you don't need to reinvent the wheel. The NIST Framework already offers a workable spine in its four functions: Govern, Map, Measure, and Manage.
What it doesn't give you is agent-native controls. However, organizations can still use NIST's structure as a baseline, and extend each function for systems that act on their own.
Be cautious here, though: Applying uniform governance to every agent regardless of autonomy isn’t sufficient. The more sophisticated the agent, the more sophisticated its governance should be. Also, be sure to define your unacceptable-risk threshold and a documented plan to halt an agent before you deploy, not after.
Underpinning all four of NIST’s functions is identity management. Organizations can gain the highest level of control and risk mitigation by giving every agent a unique, IAM-linked identity with scoped, short-lived, revocable credentials, rather than a shared API key. This will enable your team to contain the damage when an autonomous agent makes a misstep.
Agentic AI can be a massive difference-maker for efficiency, productivity, and innovation. It can also cause considerable damage to an organization’s reputation, systems, and bottom line. To maximize the former and mitigate the latter, tech leaders must:
Lastly, remember that agentic AI is still an immature field, and the governance it requires will evolve alongside the agents themselves. Treat this checklist as a living document, revisit it as formal standards arrive, and let every incident — near-misses included — sharpen it.
To get more additional best practices and real-world guidance on AI governance, transformation, and more, visit our resources page today.