# Do you know what your AI is doing right now?

> Source: <https://www.fastcompany.com/91588800/do-you-know-what-your-ai-is-doing-right-now>
> Published: 2026-08-13 12:00:00+00:00

Here’s the uncomfortable math of enterprise [AI](https://www.fastcompany.com/section/artificial-intelligence) in 2026. A recent [survey](https://newsroom.cisco.com/c/r/newsroom/en/us/a/y2026/m03/cisco-reimagines-security-for-the-agentic-workforce.html) of major enterprises showed that 85% had AI agent pilots underway. Only 5% had moved those agents into production. That 80-point gap is the defining story of this phase of AI adoption, and it has almost nothing to do with model capability. Today’s AI is the worst it will ever be. It will only improve. Capability is not holding companies back.

What holds them back is a few simple questions that turn out to be nearly unanswerable: What AI do we have deployed, what is it doing, and are we comfortable with everything it is doing?

Most organizations cannot answer that. [Research](https://www.gravitee.io/state-of-ai-agent-security) this year found that only 48% of deployed AI agents are actively monitored or secured, while 82% of executives believe their existing policies protect them from unauthorized agent actions—they have no visibility. That gap between confidence and visibility is where stalled deployments, canceled projects, and incidents live.

The AI landscape is fragmented by design, and it will stay that way. Different vendors are building different tools for different jobs: customer support, software engineering, general knowledge work, and dozens of specialized functions. Each tool has its own capabilities, connectors, and update cadence. What one assistant supports today, another will not. What is true this month is out of date next month.

Many companies have responded with a tool-by-tool approach to AI governance: A review team evaluates each AI product, signs off on a configuration, and approves it for use. However, by the time this process is complete, the tool has released new features. The underlying model has evolved. And employees have already adopted several more AI tools no one has reviewed. [Gartner](https://www.gartner.com/en/newsroom/press-releases/2026-04-28-gartner-identifies-six-steps-to-manage-artificial-intelligence-agent-sprawl) predicts the average Fortune 500 company will be using at least 150,000 AI agents by 2028, up from fewer than 15 in 2025. No review committee can keep pace with that. By the time you understand today’s AI landscape, it’s already changed.

There is another problem hiding within the first, which explains why so many pilots never scale. Consider a salesperson with write access to the CRM. Organizations grant that access because they trust the person. That salesperson could technically delete records or overwrite data in bulk, but everyone understands those permissions will be used responsibly.

Now give an AI agent that same person’s credentials to act on their behalf. The permissions are identical. The comfort is not. And no volume of instructions fixes it, because an instruction to an AI system is a request, not a control. You can tell an agent, in exhaustive detail, everything it must never do, but asking is not enforcing. The same credentials that are safe in human hands become an open question in an agent’s hands. Most enterprises have no way to tell the two apart.

The organizations that successfully put AI into production have made a subtle but important shift. Instead of trying to govern every AI tool, they’re governing what those tools can access and connect to.

Every assistant, agent, and copilot eventually must connect to enterprise systems to do meaningful work, whether that’s a CRM, data warehouse, ticketing platform, or codebase. That consistent connection point is key to organizations regaining control. This approach allows them to distinguish between humans and agents using the same credentials. They can define what each is allowed to do. And they can approve an agent to undertake specific tasks, for example, reading records but not deleting them, or drafting content but not sending it. They can log every interaction and enforce clear, consistent guardrails.

That’s the idea behind the emerging AI gateway: a single control point that remains effective no matter which AI tools come next. This allows organizations to avoid choosing between agility and safety. When policy lives at the resource level rather than in each tool, a new AI product is a configuration decision, not a re-architecture. Teams adopt what works this month, and swap it next month. The answer to “what is our AI doing right now” stays in the same place.

Using the best models and the cleanest data are becoming table stakes. The real differentiator for AI success is having a consistent point of control in an environment that’s constantly changing, along with the confidence that comes with it to move AI into production.

*Blake Brannon is chief innovation officer of OneTrust.*
