Leadership1 publisher3 min readPublished
Three In Four Plan Agentic AI, One In Five Can Govern It
Wellington Management has put a number on the oversight gap in private companies. The decision it forces this quarter is how much authority an agent gets, and who signs off on it.
The Board Room · Leadership desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction
What happened
- Wellington Management's Private Investments Value Creation Team, in a post on corpgov.law.harvard.edu authored by Hillary Flynn, Drew Morales, Courtney Hugger and Caroline Conway, states that nearly three in four companies plan to deploy agentic AI within two years despite only one in five having a mature governance model for autonomous agents.
- The stated intent-to-deploy share exceeds the mature-governance share by roughly 55 percentage points, a ratio of about 3.75 to 1.
- If every company with a mature oversight model is also among those planning agentic deployment, at least 55 percent of companies plan to deploy agentic AI without a mature governance model.
- The three-in-four and one-in-five statistic in the post is supported by a footnote marker [1], and the underlying survey is not named in the text of the passage.
- The post states that the risk with agentic AI moves beyond producing a wrong answer to taking a wrong action.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
Wellington Management's Private Investments Value Creation team, writing on the Harvard Law School Forum on Corporate Governance, reports that nearly three in four companies plan to deploy agentic AI within two years while only one in five have a mature governance model for autonomous agents [2]. That is a spread of roughly 55 percentage points, meaning intent to deploy runs close to four times ahead of demonstrated capacity to supervise [3].
Read against itself, the arithmetic says at least 55 out of every 100 companies are heading into autonomous deployment without a mature oversight model [4]. The figure is carried in the post under a footnote, and the underlying survey is not named in the passage, so treat it as directional rather than audited [5].
What makes the gap consequential is a change in failure mode. Wellington's framing is that the risk with agentic AI moves beyond producing a wrong answer to taking a wrong action [6]. As systems access information, interact with applications and execute multi-step workflows, failures become harder to predict, detect or reverse [7]. The exposure rises when those tools are wired into sensitive data, customer-facing channels, payment systems or other core processes [8]. The team lists the resulting risk domains as operational, legal, cybersecurity, customer and reputational [9].
The cited example is deliberately unglamorous. A US auto dealership's chatbot was manipulated into agreeing to sell a new vehicle for one US dollar after a user tested the system's limits [10]. Wellington notes it was not a fully autonomous agent, which is the useful part: a bounded tool was still pushed outside its intended scope because guardrails and escalation controls were weak [11]. An agent with permissions to transact would have converted that conversation into a commitment.
The evidence from Wellington's own portfolio points the same way. Drawing on an annual AI adoption survey and a peer forum of portfolio technology leaders, the team found the biggest barriers to value creation are organisational rather than technical, and that the companies reporting the strongest progress pair AI investment with employee training, clear governance and defined expectations for use [1]. Adoption itself is already routine, with leading use cases in content generation, coding assistance, knowledge retrieval, analytics and customer support [12]. Separately, the team flags shadow AI, where employees adopt unsanctioned tools that sit outside established security, privacy and governance controls [13], and warns that data, privacy and intellectual property problems are magnified when tools are deployed before controls over data access, retention and use exist [14].
None of that is a model-selection problem. It is a question of what an agent is permitted to do without a human in the loop, which systems it can touch, and what triggers escalation.
What to watch: whether boards start recording authority limits in writing rather than delegating them to whoever configures the tool, and whether the one-in-five maturity figure moves when the same survey runs again. Wellington's post also promises coverage of the regulatory landscape, adoption best practices and company resources [15], and the regulatory direction will determine whether these limits stay discretionary.