Leadership1 publisher3 min readPublished
Fifty-three points separate planning for agentic AI from governing it
Deloitte's figures, as cited by a Persistent Systems executive, compare a two-year expectation with a capability held today, which makes the gap less a verdict on neglect than a measure of the governance build now due.
The Board Room · Leadership desk

What happened
- Deloitte's 2026 State of AI in the Enterprise report, cited in a Forbes Tech Council post, finds 74% of organizations expect to be using agentic AI within two years.
- McKinsey's 2026 report, also cited in the piece, has nearly two-thirds of respondents naming security and risk as the top barrier to fully scaling agentic AI.
- In a biotechnology engagement Gharpure describes, more than 50 candidate use cases were narrowed to high-accuracy ones and throughput rose 30% with humans placed at major decision points.
Compiled by The Board RoomSomething wrong?How this is made
Why it matters
- contradiction The 74% and the 21% do not describe the same moment, so the 53-point gap reads as the size of a two-year build rather than proof that most enterprises are running agents ungoverned today.
- decision A three-lane sort makes the approval budget a portfolio rather than a single board policy, because each workflow carries its own review cost and its own rollback requirement.
- constraint If oversight tiering has to be set at design stage, sequencing precedes tooling: a program that ships first inherits a retrofit it had priced as a patch.
Start with the arithmetic the two Deloitte figures make available. Seventy-four percent of organizations expect to be using agentic AI within two years [2]; 21% say they currently hold a mature governance model defining which decisions an agent can make alone and which require human approval [3]. That is 53 percentage points of daylight [4], with expected adopters outnumbering the governed by roughly three and a half to one [5]. The horizons differ, though, and that changes how the number should be read: one measures an expectation two years out, the other a capability in place now [2][3]. The governance work implied by the 74% has a two-year clock on it, and most of it has not started. Gharpure's claim is that the second number lags for a structural reason: autonomy gets treated as one policy settled once at the top, when it is five questions asked for every task an agent touches - criticality, predictability, governance and accountability, business maturity, and data quality [1][6]. Answer them and the task sorts into one of three lanes: execute alone where risk is low and predictability high; act with a professional reviewing the exceptions rather than every case where both are moderate; recommend only, with a human deciding, where risk is high and predictability low [7]. The debate that never resolves defaults instead to keeping a human in the loop everywhere, for now [12]. That default looks like caution and bills like headcount. Reversibility sits in that list. It is not its own axis. It is folded into the accountability question, as whether every action can be explained and every decision undone if it is wrong [6], and it returns in the operational readiness test as whether a human can quickly roll back an unexpected action [11]. For a middle-lane task that is the load-bearing question, because it decides whether a wrong call is an incident or a correction, and a task that is cheap to reverse can tolerate less pre-approval than its criticality score alone would suggest. The sequencing argument is the part with a cost attached. Gharpure's position is that governance bolted on after go-live, as a patch once something breaks, is where programs undermine themselves, and that the tiering belongs in the design: the highest level of human interface from the outset for processes touching financial or confidential data, moderate oversight for customer support [9]. His illustration is a biotechnology firm where more than 50 identified use cases were narrowed to those automatable with high accuracy, humans were embedded at the major decision points rather than spread evenly across every step, and throughput rose 30% with high error containment [10]. That figure comes from his own firm's engagement and carries no independent verification [1], so it supports the design principle better than it prices it. Five questions and three lanes describe any competent risk register, and task-level triage is old consulting furniture. The piece does not claim the axes are novel; the claim is about how often they get applied [1]. The corroboration that carries weight is McKinsey's, cited in the same article: nearly two-thirds of respondents name security and risk concerns as the top barrier to fully scaling agentic AI, ahead of regulatory uncertainty and technical limitations [8]. Were the binding constraint the technology or the rulebook, a per-task method would be beside the point. This quarter's version of the work is small: a list of the tasks agents already touch, a lane assigned to each, and a named rollback path for anything in the middle lane.
What to watch
- Whether Deloitte's own wording supports the 74/21 comparison when read directly rather than as quoted in a council post.
- Whether the 21% mature-governance share moves in the next annual cut of Deloitte's survey, which would show whether the build is happening or being deferred.
- Whether security and risk stays ahead of regulatory uncertainty as the top scaling barrier in later McKinsey survey rounds.