Leadership1 publisher3 min readPublished
Agent governance maturity trails deployment plans by 53 points in Deloitte's figures
Kousik Rajendran cites the split in a Forbes post to argue that agents break linear change management, because the model behind an unchanged API can shift without a release. His fix is a five-stage loop.
The Board Room · Leadership desk

What happened
- Deloitte found that 74% of companies plan to deploy agentic AI within two years while only 21% report a mature governance model for AI agents, according to figures cited in a Forbes Tech Council post.
- Kousik Rajendran, co-founder and CEO of Aivar Innovations, wrote that an agent's API can stay the same while the behavior of the system changes underneath it.
- He sets out a five-stage change management model called TRACE, for Trust, Route, Adopt, Calibrate and Evolve, built as repeated loops instead of a one-way process.
- He describes trust failing in both directions, with staff pushing sensitive financial, HR or classified information into AI systems while other users rule out use cases an agent could handle.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- constraint If behavior can change while the interface does not, approval dated to a deployment stops certifying the system a company is running. The control then has to move to a repeated audit cadence that costs staff time every cycle instead of once.
- decision Classifying work by consequence turns oversight into a per-transaction design question. The choice in front of a process owner is where the value threshold sits, and each threshold creates a second path to build and maintain.
- exposure A human named in an escalation path who skims and approves carries the accountability for the agent's decision without exercising the review. The organization is left holding a control that exists only on the org chart.
- precedent A vendor-authored framework built on an undated, self-reported maturity statistic is the form this argument will keep arriving in. Buyers who want the causal claim tested will have to commission that evidence themselves.
Subtract one figure from the other and the distance is 53 percentage points; as a ratio, stated intent runs about three and a half times ahead of stated readiness [16]. Those numbers come from a Forbes Tech Council post by Kousik Rajendran, co-founder and chief executive of Aivar Innovations. The post does not state the Deloitte survey's date, its sample, or the test a company had to pass to count as mature [2][17].
The claim underneath the numbers can be tested on its own. In traditional software, Rajendran wrote, you develop code for a particular problem and deploy it. It is deterministic and relatively static, so the way it solves the problem does not change until you release a new version [18]. Agents break that sequence. "The API might remain the same while the behavior of the system changes underneath it," he wrote [4].
The gap Rajendran names is that the thing being governed does not hold still between reviews. He puts the three reasons prototypes stall short of production as measurable ROI, trust and velocity [15].
Route, the second stage of his TRACE model, is the part with an operational test [5]. Invoice reconciliation is his example. A small-value transaction can move through a faster path with significant agent augmentation, while a high-value transaction or one with substantial compliance implications goes down a path with more validation and human review [11]. Work gets classified by complexity and consequence, so that human oversight becomes more intensive as potential impact increases [12]. A single workflow then has two or three paths to build and maintain.
Both directions of trust failure are governance problems in his account. Over-trust already shows up as sensitive financial, HR or other classified information being pushed into AI systems without enough thought about the implications [6]. Where a human sits in an agent's escalation path, he asks whether that person is thoroughly reading the recommendation or simply skimming the lines and approving it notionally [7]. Under-trust sounds like a leader or employee deciding "The agent cannot work for this use case," when it actually could [8].
Ownership is where the sequence starts, with a sponsor who owns the workflow: a CFO, CIO, line-of-business leader or process owner [9]. The commercial screen comes before any decision about how the agent should behave. It covers ROI, unit economics, whether the case makes sense commercially, and whether it is technically feasible given the limitations agents still have [10]. Adoption begins during the build, with process stakeholders involved throughout and validation running past the traditional UAT phase [13]. The failure he is arguing against is the familiar one: organizations subscribe to powerful AI tools and relatively few people use them to their full extent [14].
What to watch
- Publication of the underlying Deloitte survey with its date, sample and maturity criteria. That would show whether the 21% is a control measurement or a self-report.
- Whether model providers start offering version pinning or advance notice of behavior changes. Either would restore a release-shaped control point.
- Whether enterprise agent contracts begin specifying routing thresholds by transaction value.