The Governance Gap: 72% Run AI Agents in Production, Most Without a Net
Here is the number that should be keeping operations leaders up at night. Roughly 72% of enterprises now run agentic AI in production, and a majority of them have no governance framework underneath it. Deployment has raced ahead of control. The agents are live, touching real systems and real customers, and in most companies nobody can say with confidence what they are allowed to do, what they are actually doing, or how to stop them in a hurry.
This is a different problem from the two governance topics that usually get the attention. It is not shadow AI, the unsanctioned tools employees use without IT knowing. These agents are sanctioned, chosen, paid for. And it is not purely an EU AI Act question, although the Act raises the stakes. It is operational governance of the agents you deliberately put into production, and it is the gap almost nobody priced in when they rushed to deploy in 2025 and early 2026.
What governance actually means, operationally
Governance is one of those words that dissolves into compliance theatre if you let it. So let us be concrete. Operational governance of a production agent is five things, and you either have them or you do not.
The governance gap: deployment has outrun control. Five operational components most production agents are missing.
Observability
Can you see what the agent is doing, in real time, without asking an engineer to pull logs. Every decision, every action, every escalation, on a surface a non-technical owner can read. Most production agents fail this immediately. They run, they act, and the only record is a log file nobody watches. An agent you cannot see is an agent you cannot govern, and the dashboard is not a nice-to-have, it is the precondition for everything else.
A kill switch
Can a named person stop the agent, now, without a deployment. When an agent starts misbehaving, the time between noticing and stopping is the blast radius. If stopping requires a code change and a release, that window is hours, and an agent acting wrongly for hours is an incident. A real kill switch is one button, one authorised human, immediate effect. It is astonishing how many production deployments do not have one.
An audit trail
Can you reconstruct, after the fact, exactly what the agent did and why. Every action timestamped, attributed, traceable to the input that triggered it. This is the artefact regulators will ask for, and it is also the artefact you need to debug your own incident. Audit-trail-by-default, written at the moment of action, not reconstructed afterwards from fragments.
Scope review
Does someone check, on a schedule, what the agent can do against what it needs to do. Permissions creep. Each new capability looks reasonable in isolation, and six months in the agent can touch systems its original purpose never justified. The only defence is a recurring review that revokes aggressively. Without it, scope only ever grows, and the day it matters is the day after an incident.
A named accountable human
When the agent gets it wrong, whose problem is it. Not the team. A person. We have made this case before in agents joining the org chart, and it is the keystone of governance because every other component needs an owner. The dashboard needs a watcher, the kill switch needs a hand, the audit trail needs a reader, the scope review needs a reviewer. No name, no governance.
Why the gap opened
The gap is not the result of negligence. It is the result of speed. Deploying an agent in 2026 is genuinely fast, faster than building the operational muscle to govern it. A team can have a useful agent in production in weeks, and the governance layer, the dashboards and the review cadences and the escalation paths, takes longer to build than the agent did and produces no visible feature. So it slips. The agent ships, the governance is a backlog item, and the backlog item is still there when the first incident arrives.
There is also a measurement trap. An ungoverned agent that is working looks identical to a governed one that is working. The difference only shows up under stress, the day the agent does something unexpected, and by then the cost of not having governance is an incident rather than a line item. The gap is invisible right up until it is the only thing anyone can see.
What the gap actually costs
Three costs, in rising order of pain. First, drift. An ungoverned agent slowly diverges from what you wanted, because nobody is watching the slow change, and you find out when a customer or an auditor tells you. Second, the unrecoverable action. Without a kill switch and reversibility, a single confident mistake propagates further than it should before anyone can intervene. Third, the trust collapse. The first visible incident with an ungoverned agent does not just cost the incident, it costs the mandate. Teams route around the agent, leadership freezes the programme, and the company loses a year of progress to recover from a gap that a fortnight of governance work would have closed.
The EU AI Act raises the floor
From 2 August 2026, the high-risk obligations of the EU AI Act are enforceable, and the oversight they require maps almost exactly onto the five components above. This is convenient, in a way. The governance you should build for operational reasons is largely the governance the Act will require for legal ones. We walk through the documentation and classification detail in our compliance guide. For governance purposes, the headline is simple. The regulatory deadline and the operational best practice have converged on the same answer, which means the work is no longer optional and no longer a pure cost.
The Greek-market angle
Closing the governance gap is faster in a smaller organisation, for the same structural reason most things are. The named accountable human is obvious in a flat firm and ambiguous in a matrix. The scope review fits in an existing weekly meeting rather than requiring a new committee. The kill switch authority does not need three sign-offs. Greek enterprises that deployed agents in the last year can retrofit governance in weeks, where a multinational would need a quarter, because the owners of each component are close enough to coordinate without ceremony. The gap is real here too, but it is cheaper to close.
The 30-day governance retrofit
For a company with agents already in production and no governance underneath, the path is short and worth running now rather than after the incident. Week one, instrument. Stand up an observability surface so every agent action is visible to a non-technical owner. Week two, contain. Add a kill switch and confirm every consequential action is reversible or gated. Week three, attribute. Turn on audit-trail-by-default and name the accountable human for each agent. Week four, review. Run the first scope review, revoke what is not needed, and put the review on a recurring calendar. Thirty days converts an ungoverned deployment into a governed one, and the difference is the difference between a programme that survives its first incident and one that does not.
We build the governance layer into every agent we deploy, because an agent without it is a liability wearing the costume of an asset. The agents we ship (AI Customer Support, AI Contract-to-Cash, Enterprise AI Search, AI-Powered CRM and the rest of the product family) arrive with observability, a kill switch, audit-trail-by-default, scheduled scope review, and a named accountable human, on day one. If you have agents in production and a governance gap underneath them, get in touch at inbusiness.gr before the gap introduces itself.