Security1 publisher3 min readPublished
Deloitte: 16% say processes are ready for agents. Security inherits the other 84%.
Deloitte's readiness survey names data foundations, agent governance and integration cost as the brakes on agentic AI. None of those is a model problem, and two are security's problem.
The Watch · Security desk
Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

What happened
- Deloitte's research identifies three main challenges limiting wider adoption of AI agents: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration.
- Only 16% of surveyed leaders say their organizations' processes are ready for agentic AI, with just 5% describing them as highly prepared.
- Fewer than half of surveyed leaders say their organizations are prepared for agentic AI across most areas of the business; workforce readiness and business processes rank as the weakest areas.
- Only one in five surveyed leaders say their organizations are prepared to redesign business processes to operate autonomously with AI agents.
- About 80% of surveyed leaders are therefore not prepared to redesign business processes to operate autonomously with AI agents.
Compiled by The WatchSomething wrong?How this is made
Why it matters
Deloitte's latest agentic AI research puts the brake on adoption in three places, and none of them is model capability: the lack of a unified and accessible data foundation, limited trust in and governance of AI agents, and the cost and complexity of integration [1]. Only 16% of surveyed leaders say their organizations' business processes are ready for agentic AI, with 5% describing them as highly prepared [2].
The ordering matters for anyone who owns controls. Two of the three named constraints, the data foundation and agent governance, are the substrate that security assurance is built on, which means the survey is describing a governance deficit and calling it an operating-model gap. Fewer than half of leaders say their organizations are prepared for agentic AI across most areas of the business, with workforce readiness and business processes ranking as the weakest [3]. Only one in five say they are prepared to redesign business processes to operate autonomously with AI agents [4], leaving roughly 80% who are not [5].
Deployment is not waiting for the redesign. Deloitte reports that many organizations are introducing agents into existing workflows rather than rebuilding processes from the ground up, a layered approach that offers a quicker path to short-term payback and experience with the technology [6]. The same respondents attribute their lack of readiness to poorly documented processes, fragmented data and systems, entrenched ways of working, and limited AI expertise among executives and employees [7]. Bolting an autonomous, multistep actor onto an undocumented process running on fragmented systems is how you end up unable to answer, after the fact, what the agent was entitled to touch.
Experience does not close the gap as much as you would hope. Among organizations that have deployed AI agents at scale, 46% report that their business processes are prepared [8], which is 30 points better than the overall figure but still a majority of the most advanced adopters saying no [9].
The schedule is the part worth pinning to a wall. About 31% of surveyed organizations expect at least half of their business processes to be redesigned or rebuilt around AI agents within two years, rising to 74% over four years [10]. That 43-point jump sits in years three and four [11], while 43% of leaders expect a lot to extreme job disruption within the next 12 to 18 months [12]. The disruption arrives before the redesign does.
The oversight layer that leaders are counting on is thinly funded. Leaders expect agents to work across functions on complex, multistep tasks with people primarily providing oversight, directing agents, reviewing output, validating quality and deciding when human judgment is required [13]. About 71% report providing baseline AI-agent literacy training and 65% are targeting upskilling toward roles expected to change [14], but half of leaders say their organizations are not investing enough in the workforce changes needed to support agent adoption [15]. Human-in-the-loop is a control. Staffed by people who have had a literacy module and no process documentation, it is a control on paper.
Laura Shact, Deloitte's U.S. TMT AI growth leader, said limited, layered-on approaches "may create the sense of getting ahead with quick wins, but in reality, they may not be enough" [16]. The published summary does not disclose sample size, respondent geography or fielding dates, so treat the percentages as directional [17].
What to watch: whether agent inventories, identity and entitlement models, and revocation paths land before the year-three redesign wave, or after it. Watch also whether the half who admit underinvestment in workforce readiness fund the oversight roles they are assigning controls to, because on this survey's own timeline the accountability lands in 12 to 18 months [12] and the process work lands in three to four years [10].