Security1 distinct publisher3 min readUpdated
Deloitte's readiness survey names data foundations, agent governance and integration cost as the brakes on agentic AI. None of those is a model problem, and two are security's problem.
The Watch · Security desk

Compiled by The WatchSomething wrong?How this is made
Deloitte's latest agentic AI research puts the brake on adoption in three places, and none of them is model capability: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration [1]. Only 16% of surveyed leaders say their organizations' business processes are ready for agentic AI, with 5% describing them as highly prepared [2].
The ordering matters for anyone who owns controls. Two of the three named constraints, the data foundation and agent governance, are the substrate that security assurance is built on, which means the survey is describing a governance deficit and calling it an operating-model gap. Fewer than half of leaders say their organizations are prepared for agentic AI across most areas of the business, with workforce readiness and business processes ranking as the weakest [3]. Only one in five say they are prepared to redesign business processes to operate autonomously with AI agents [4], leaving roughly 80% who are not [5].
Deployment is not waiting for the redesign. Deloitte reports that many organizations are introducing agents into existing workflows rather than rebuilding processes from the ground up, a layered approach that offers a quicker path to short-term payback and experience with the technology [6]. The same respondents attribute their lack of readiness to poorly documented processes, fragmented data and systems, entrenched ways of working, and limited AI expertise among executives and employees [7]. Bolting an autonomous, multistep actor onto an undocumented process running on fragmented systems is how you end up unable to answer, after the fact, what the agent was entitled to touch.
Experience does not close the gap as much as you would hope. Among organizations that have deployed AI agents at scale, 46% report that their business processes are prepared [8], which is 30 points better than the overall figure but still a majority of the most advanced adopters saying no [9].
The schedule is the part worth pinning to a wall. About 31% of surveyed organizations expect at least half of their business processes to be redesigned or rebuilt around AI agents within two years, rising to 74% over four years [10]. That 43-point jump sits in years three and four [11], while 43% of leaders expect a lot to extreme job disruption within the next 12 to 18 months [12]. The disruption arrives before the redesign does.
The oversight layer that leaders are counting on is thinly funded. Leaders expect agents to work across functions on complex, multistep tasks with people primarily providing oversight, directing agents, reviewing output, validating quality and deciding when human judgment is required [13]. About 71% report providing baseline AI-agent literacy training and 65% are targeting upskilling toward roles expected to change [14], but half of leaders say their organizations are not investing enough in the workforce changes needed to support agent adoption [15]. Human-in-the-loop is a control. Staffed by people who have had a literacy module and no process documentation, it is a control on paper.
Laura Shact, Deloitte's U.S. TMT AI growth leader, said limited, layered-on approaches "may create the sense of getting ahead with quick wins, but in reality, they may not be enough" [16]. The published summary does not disclose sample size, respondent geography or fielding dates, so treat the percentages as directional [17].
What to watch: whether agent inventories, identity and entitlement models, and revocation paths land before the year-three redesign wave, or after it. Watch also whether the half who admit underinvestment in workforce readiness fund the oversight roles they are assigning controls to, because on this survey's own timeline the accountability lands in 12 to 18 months [12] and the process work lands in three to four years [10].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Deloitte's research identifies three main challenges limiting wider adoption of AI agents: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration.
Only 16% of surveyed leaders say their organizations' processes are ready for agentic AI, with just 5% describing them as highly prepared.
Fewer than half of surveyed leaders say their organizations are prepared for agentic AI across most areas of the business; workforce readiness and business processes rank as the weakest areas.
Only one in five surveyed leaders say their organizations are prepared to redesign business processes to operate autonomously with AI agents.
Many organizations are introducing AI agents into existing workflows instead of redesigning processes from the ground up; Deloitte notes this layered approach may offer a quicker path to short-term payback while building experience and credibility with the technology.
Executives and AI and data science leaders attribute the lack of readiness to poorly documented processes, fragmented data and systems, entrenched ways of working, and limited AI expertise among executives and employees.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single-source vendor survey, methodology undisclosed
All figures trace to one secondary summary of one consultancy's readiness survey. The percentages are internally consistent and the derived arithmetic checks out, but sample size, respondent geography and fielding dates are absent, there is no second publisher or primary report in the cluster, and every reading is self-reported rather than instrumented.
Deployments exist, process readiness thin
The survey does disclose real usage: a subset of organizations has deployed agents at scale, 71% run baseline literacy training and 65% run targeted upskilling. But readiness for agent-shaped operations is thin - 16% overall, 46% even among at-scale deployers, one in five ready to redesign processes - and no named deployment, seat count or workload volume is given anywhere in the cluster.
Deflationary framing, inflated forward numbers
The article's own posture is corrective - it leads with unreadiness rather than capability - which limits overstatement. The residual gap sits in the forward-looking numbers: 74% of organizations expecting half their processes rebuilt around agents in four years, and 43% expecting heavy job disruption in 12 to 18 months, are expectations with no adoption or methodology support behind them, and the Clarity framing that governance and integration gaps become security's problem is not asserted by the source.
Consultancy research promoting transformation work
The originating research is Deloitte's own, and the only named voice is a Deloitte AI growth leader whose quote argues that quick, layered-on fixes are insufficient and that organizations must invest in work and organization design, leadership and workforce enablement - precisely the advisory engagement a consultancy sells. The publisher adds no counterweight, disclosure or independent sourcing.
Directionally credible, weakly verified
The direction of the story - readiness lagging agent ambition, with data, governance and integration as the binding constraints - is coherent and consistent across every figure supplied. Confidence is capped by one publisher, one interested sponsor, no disclosed methodology, and entirely self-reported measures with no independent deployment evidence.
security
OpenAI's Computer History writes a plaintext log of the workday. Decide before staff opt in.1 distinct publisher
leadership
A $3.48m evidence base, six bad citations, and a denial that did not survive the metadata1 distinct publisher
security
The customer is genuine and the payment is authorized: 55% of banks say scams dominate fraud1 distinct publisher
invest
Half a book in two memory names: what Situational Awareness's 67% month actually shows1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 13, 2026