Enterprise AI Agents Are Reaching Production — But Governance and Security Aren't Ready
Something is out of sync in enterprise AI. Companies are pouring billions into building and deploying autonomous AI agents — systems that can reason, plan, and act across business processes without constant human oversight. Databricks just raised $5 billion at a $190 billion valuation to expand its agent platform. Zenity closed a $125 million Series C for agent runtime security. Xpander, a startup founded by former AWS principal engineers, scored $7.5 million in seed funding for its agent infrastructure. The money is moving fast.
But the organizations deploying these agents are, by their own admission, not ready to manage them. Gartner predicts that by 2027, 40% of enterprises will demote or decommission autonomous AI agents — not because the technology failed, but because governance failed. Fortune 500 companies are projected to operate more than 150,000 agents each by 2028, yet only 13% of firms feel prepared to manage that scale. The gap between deployment speed and governance readiness is widening, and the consequences are already showing up in production incidents that nobody planned for.
This is the story of what happens when a technology moves from the lab to the business faster than the rules can follow.
The Infrastructure Rush: Billions Flowing Into Agent Platforms
The funding numbers tell a clear story. Databricks’ $5 billion round, announced on August 13, is the largest in the company’s history and values the firm at $190 billion — up from $62 billion just 18 months ago (PYMNTS, August 13). CEO Ali Ghodsi said plainly: “Enterprises want AI agents working across their business and Databricks offers the foundation they need.” The capital will fund three products specifically designed for agent workloads: Lakebase, a serverless Postgres database built for AI agents; Genie, an AI coworker; and Unity AI Gateway, which provides multi-AI governance and cost controls. Databricks also reported surpassing a $7 billion revenue run-rate with 80% year-over-year growth in Q2.
Meanwhile, Xpander’s $7.5 million seed round (Pulse2, August 17) takes a different angle: infrastructure that lets enterprises build and deploy agents as portable workloads across existing cloud environments. Their flagship agent, Omni, scored 90.9% on the GAIA benchmark — a test designed to measure complex reasoning and tool use. Founded by three former AWS principal engineers who spent years helping large enterprises migrate to cloud infrastructure, Xpander’s thesis is straightforward: becoming AI-native requires more than adding individual copilots. It requires infrastructure that lets agents operate securely and consistently across existing systems.
The pattern is clear across every major tech company and startup raising capital for agent infrastructure. The market has decided that AI agents are not a niche experiment — they are becoming core business infrastructure. And the infrastructure layer is scaling rapidly to support that shift, with more funding rounds expected before the year ends.
The Governance Gap: 40% Will Be Decommissioned
Here is where the story gets uncomfortable. While infrastructure investment accelerates, the ability to govern, monitor, and secure these agents is falling behind. Gartner’s prediction is blunt: by 2027, 40% of enterprises will demote or decommission autonomous AI agents due to governance gaps that are only identified after production incidents occur. Not before. After.
The numbers paint the picture. Fortune 500 companies are projected to operate more than 150,000 agents each by 2028 (HPCWire, June 18). But only 13% of firms feel prepared to manage that scale. That is not a technology problem — it is an operational and governance problem. The agents work. The organizations deploying them do not have the systems, policies, or people to keep them under control.
Yuval Fernbach, VP and CTO of JFrog AI Security, described the core issue as “binary governance” — the tendency to treat AI agents as either fully locked down or fully trusted, with nothing in between (Techzine, August 14). This worked when AI was limited to simple chatbots and static assistants. But autonomous agents that can read databases, send emails, approve transactions, and interact with external APIs require a fundamentally different governance model. Traditional compliance frameworks — designed for human workflows and predictable software — do not map well to agents that can adapt their behavior based on context.
This plays out predictably. Enterprises deploy agents into production with governance policies that were designed for a different era, one where software did what it was told and nothing more. Incidents follow. The 40% decommission rate Gartner projects is not a future risk — it is the logical consequence of deploying autonomous systems without autonomous governance.
Security Fragmentation: Agents Everywhere, Oversight Nowhere
The security challenge compounds the governance problem. Enterprise AI agents do not run in one place. They span cloud platforms, internal systems, and external endpoints. Every new agent deployment adds another surface that needs monitoring, enforcement, and access control. NeuralTrust, which raised $20 million in seed funding — the largest cybersecurity seed round raised by an EU company to date — describes this as “security fragmentation” that grows harder to manage with every new deployment (HPCWire, June 18).
The problem is structural. Agents are not static applications with well-defined boundaries. They interact with multiple systems, make decisions based on context, and can trigger cascading actions across an organization’s infrastructure. A single agent that reads customer data, drafts a response, and sends it through an email system touches three different security domains. Multiply that by thousands of agents across a large enterprise, and the attack surface becomes enormous.
NeuralTrust’s platform is designed to provide a unified enforcement layer that spans all of these environments — identifying agents, securing their interactions, and scaling governance across the entire agent fleet. The $20 million seed round, led by Alstin Capital with participation from VentureFriends, Seaya, Kibo Ventures, and others, reflects how seriously investors are taking this problem. The European Innovation Council and Spain’s State Research Agency also backed the company with public funding.
The message from the market is unmistakable: the security tooling that worked for traditional enterprise software does not scale to agent-based architectures. New approaches purpose-built for autonomous systems are needed, and they need to be in place well before the agent count reaches the levels Gartner is projecting.
What Is Working: Runtime Governance and Agent-Aware Security
A new category of governance and security tools has emerged, purpose-built for the realities of autonomous AI agents. Zenity, which raised a $125 million Series C in August 2026 (SecurityBoulevard, August 17), provides agent runtime security for Microsoft Foundry. The company offers AI Security Posture Management (AISPM) and AI Detection and Response (AIDR) for real-time threat detection. Gartner named Zenity a Cool Vendor in Agentic AI Trust, Risk and Security Management in 2025, and the company’s valuation places it well into the top tier of AI security vendors.
Fiddler, the AI observability specialist founded by Krishna Gade (who led Facebook News Feed ranking), has repositioned itself as the “AI control plane” for enterprise agent workloads. After raising a $32 million Series C led by Insight Partners in January 2026, Fiddler now covers continuous evaluation, monitoring, enforceable policy, and auditable governance for first-party and third-party agents. The company ships proprietary trust models designed to give enterprises visibility into how agents behave in production.
The governance landscape is splitting into three tiers, according to SecurityBoulevard’s comparison guide. Enterprises needing a governance program of record for regulatory compliance — EU AI Act, ISO 42001, NIST AI RMF — lean toward platforms like Credo AI, Holistic AI, or IBM watsonx.governance. Those needing runtime enforcement on agent behavior and Copilot policy controls turn to Zenity, Pillar Security, or Harmonic Security. And those building governance on connected telemetry across every AI interaction look to platforms like Fiddler and NeuralTrust.
What these tools share is a departure from the binary model. They treat agents as entities that need continuous monitoring, dynamic policy enforcement, and real-time visibility — not one-time approval gates. This is the governance model that matches how agents actually work.
The Path Forward: What Enterprises Need to Do
The window for getting agent governance right is closing fast. Organizations that are already deploying agents at scale need to act on three fronts.
First, build a comprehensive agent inventory. You cannot govern what you cannot see. Most enterprises do not have a complete picture of how many agents are running, where they are deployed, what data they access, and what actions they can take. The 13% readiness figure from Gartner suggests that the vast majority of enterprises are flying blind on agent visibility.
Second, adopt tiered governance. Not every agent poses the same risk. A customer-facing agent that can initiate financial transactions requires a fundamentally different governance model than an internal research assistant that reads public data. Enterprises need to classify agents by risk level and apply governance controls proportionally — runtime enforcement for high-risk agents, monitoring and audit trails for medium-risk, and lighter-touch policies for low-risk deployments.
Third, invest in runtime governance infrastructure. The era of deploying agents with basic access controls and hoping for the best is over. Agent runtime security — continuous monitoring of agent behavior, real-time policy enforcement, anomaly detection, and automated response capabilities — is no longer optional. Zenity, NeuralTrust, Fiddler, and similar platforms exist because the market has recognized that this is a distinct category, not a feature bolted onto existing security tools.
The Bottom Line: The Governance Gap Is the Real Risk
Enterprise AI agents are not a question of if — they are a question of how fast. The funding tells the story: $5 billion from Databricks, $125 million from Zenity, $20 million from NeuralTrust, $7.5 million from Xpander. The market is betting that agents will become core business infrastructure. The infrastructure to support that bet is being built.
But the governance gap is the real risk. Gartner’s 40% decommission prediction is not about technology failure. It is about organizations that deployed agents without the systems to manage them safely. The enterprises that get governance right will scale their agent fleets with confidence. The ones that do not will be the 40% that pulled the plug after an incident they never anticipated.
Money is flowing. Agents are deploying. Governance either catches up, or the gap becomes a crisis that sets the entire enterprise AI industry back by years.
Related Articles

98% of Enterprise Leaders Would Trust AI Agents in Production — If the Guardrails Exist
