Enterprises are rapidly deploying AI agents, with over half already in production or active piloting. However, this swift adoption rate is not consistently matched by adequate governance frameworks or clear measurement strategies, leading to significant operational and reputational risks. A recent study, the Liferay 2026 Agentic AI Adoption and Governance Report, reveals that only 24% of companies possess a company-wide AI usage policy, and just 25% consistently measure AI’s impact with clear Key Performance Indicators (KPIs). This imbalance between adoption speed and strategic oversight necessitates a focused approach to policy, data readiness, and performance measurement to truly realize AI agent value.
The AI Agent Adoption Paradox: Speed vs. Strategy
Organizations are integrating AI agents into core operations at an accelerated pace, reflecting a clear intent to leverage these technologies for efficiency and innovation.
The Liferay 2026 Agentic AI Adoption and Governance Report indicates that 54% of companies are currently running AI agents in production environments or actively piloting them. This widespread adoption spans various industries, with technology companies leading at 72% adoption, followed by healthcare at 66% and transportation/logistics at 64%. Key use cases for AI agents are concentrated in areas requiring extensive data processing and customer interaction. Data analysis and reporting is cited by 35% of companies as the most useful application, followed by customer support at 32%, and IT service desk operations at 21%. For example, a telecommunications provider might deploy an AI agent to analyze customer call transcripts for sentiment trends or automate routine customer support inquiries regarding billing.
Despite this aggressive deployment, a substantial governance gap persists across enterprises. Only 24% of companies have a formal, company-wide AI usage policy in place, and merely 25% consistently measure the impact of their AI agents using defined KPIs. This disparity implies that many organizations are embracing AI agent capabilities without establishing the necessary guardrails or accountability mechanisms. For a financial institution, this could mean deploying agents for fraud detection without a clear policy on human oversight or without defined metrics for false positives and financial impact. The absence of a formal policy and robust measurement capabilities hinders an organization’s ability to assess true return on investment (ROI) and manage potential risks effectively.
Summary: The rapid deployment of AI agents underscores their perceived utility, yet the lagging development of governance policies and measurement frameworks introduces substantial operational and strategic vulnerabilities. Without clear policies and metrics, organizations risk deploying agents that operate without adequate oversight, potentially creating more complexity than value.
Addressing Critical Concerns: Privacy, Trust, and Utility
The effective integration of AI agents hinges on proactively addressing core concerns related to data integrity, security, and human-centric factors. These elements are critical for building confidence in AI systems.
Data privacy emerges as the top concern regarding AI agents, cited by 21% of companies, closely followed by employee trust at 17%, and security risk at 13%. For a healthcare provider, the deployment of AI agents necessitates stringent data privacy protocols (e.g., HIPAA compliance) and transparent communication to staff about how patient data is handled. Employee trust, often overlooked, is vital for successful AI integration; without it, resistance can undermine adoption and effectiveness. Simultaneously, the utility of AI agents is directly linked to their accuracy and reliability. Forty-two percent of companies state that better accuracy is what AI agents need most to become more useful, while 36% demand stronger security controls and 35% call for improved employee training. This indicates a foundational need for technically robust, secure, and user-friendly AI systems.
Further exacerbating the challenge, specific barriers prevent organizations from fully realizing value from AI. Security or privacy concerns (30%) and cost (29%) are the leading barriers, followed by a lack of adequate training (27%) and legal or compliance concerns (22%). Interestingly, “unclear ROI” ranks last among identified barriers, suggesting that while organizations recognize the potential value, they are struggling with the practical implementation aspects that directly impact security, budget, and employee enablement. For a large retail e-commerce firm, addressing security vulnerabilities in AI agents that handle customer transactions is paramount, as a breach could have significant financial and reputational consequences. Investing in comprehensive training for customer service teams on how to interact with and leverage AI agents is equally important for improving customer experience metrics like First Contact Resolution (FCR) and Customer Satisfaction (CSAT).
What this means: Enterprises must shift from a purely technical view of AI agent deployment to a holistic approach that prioritizes data privacy, robust security, employee enablement, and clear operational guidelines. Overlooking these foundational elements will limit the strategic impact of AI and expose the organization to unnecessary risks.
Forging a Path to Governed AI Value
Closing the AI governance gap requires a structured approach centered on comprehensive policies, clear operational models, and rigorous measurement.
Establishing a robust operating model is fundamental for governing AI agents effectively. This model must define roles, responsibilities, and decision-making authority within the AI agent lifecycle.
- Operating Model and Roles:
- AI Governance Committee: Defines enterprise-wide AI policies, risk tolerances, and ethical guidelines.
- Data Governance Lead: Ensures AI agents access and process data in compliance with privacy regulations (e.g., GDPR, CCPA) and internal consent frameworks.
- AI Product Owners: Responsible for specific agent deployments, including defining use cases, performance metrics, and human approval workflows.
- AI Operations Team: Manages agent deployment, monitoring, and maintenance, ensuring adherence to security standards and performance SLAs.
- Guardrails and Thresholds:
- Data Access Permissions: Implement strict role-based access control (RBAC) to ensure AI agents only access data they are authorized to process (e.g., a customer support agent may access customer CRM data but not sensitive payment information unless explicitly required for a specific, audited transaction).
- Actionable Limits: Define explicit boundaries for agent autonomy. For instance, an AI agent in financial services might process a loan application but require human approval for final disbursement exceeding a predefined threshold ($10,000). In a B2B SaaS context, agents can automate initial lead qualification but require human interaction for complex product demonstrations.
- Human-in-the-Loop Protocols: Establish clear escalation paths. Complex customer service inquiries, high-value transactions, or any scenario exceeding a defined risk score (e.g., a RAG status of Red) must be routed to a human agent for review and resolution.
- Content Generation Policies: For agents generating content, specify brand voice guidelines, factual verification steps, and human review before public dissemination.
- Measurement and Metrics:
- Moving beyond basic containment rates, enterprises must define specific KPIs that reflect business outcomes.
- Customer Experience: Increase First Contact Resolution (FCR) by 15%, reduce Customer Effort Score (CES) by 10%, improve CSAT/NPS by 5 points.
- Operational Efficiency: Decrease average time-to-resolution by 20%, reduce manual data entry errors by 25%.
- Business Impact: Increase lead conversion rates by 10% in marketing, reduce procurement cycle time by 15%, lower complaint rates by 8%.
- Risk Management: Track the number of human interventions for agent corrections, audit compliance violations, and data privacy incidents.
What to do:
- Establish formal AI usage policies: Define ethical considerations, data handling, and operational guidelines.
- Define clear, measurable KPIs: Link AI agent performance directly to strategic business outcomes.
- Implement robust data governance for AI: Ensure data readiness, quality, and secure access for agent training and operation.
- Invest in comprehensive employee training: Equip staff with the skills to collaborate with AI agents effectively and understand their limitations.
- Create explicit human approval workflows: Embed human oversight at critical junctures, especially for high-risk or sensitive operations.
What to avoid:
- Deploying agents without an oversight framework: This creates unmanaged risk and potential compliance breaches.
- Ignoring data privacy and security implications: Failure to comply with regulations can lead to severe penalties and loss of trust.
- Failing to define clear human-in-the-loop processes: This can result in agents making incorrect or inappropriate actions without intervention.
- Neglecting employee training and change management: Resistance or misuse by employees can negate AI benefits.
- Focusing solely on efficiency metrics: Over-optimizing for a single metric like containment can degrade overall customer or employee experience.
Immediate Priorities (First 90 Days):
- Conduct an audit of all existing AI agent deployments: Identify current use cases, data access patterns, and levels of human oversight.
- Initiate the development of an enterprise-wide AI usage policy: Prioritize data privacy, security, and ethical guidelines.
- Define pilot programs with clear, measurable KPIs: Select specific, high-impact use cases to establish baseline metrics for FCR, CES, or conversion rates.
- Perform a stakeholder training needs assessment: Identify critical skill gaps for employees interacting with AI agents.
What ‘good’ looks like: A telecommunications company has AI agents handling 40% of Tier 1 customer inquiries, achieving a 75% FCR rate, with human agents seamlessly escalating complex issues via predefined workflows. This is supported by a clear policy on data usage and regular training for agents, resulting in a 10% improvement in both CSAT and employee satisfaction scores over six months.
Summary
The rapid adoption of AI agents presents significant opportunities for enterprise efficiency and customer experience enhancement. However, the Liferay 2026 Agentic AI Adoption and Governance Report clearly demonstrates that this speed is largely unmatched by the necessary governance and measurement structures. To truly capitalize on AI agent capabilities, senior leaders must proactively establish clear AI usage policies, implement robust data governance, define precise human-in-the-loop protocols, and commit to comprehensive employee training. By prioritizing these foundational elements, enterprises can move beyond mere adoption to achieve sustainable, measurable value from their AI agent investments, transforming potential risks into reliable, impactful operational gains









