A rusted metal gate closed with a padlock

Only 5% of firms have agent controls in place, so write the policy before the pilot

Most firms plan to give AI agents more freedom than their controls can hold. Marcus Laporte on the clauses and rules to settle first.

The AI agent controls gap in BCG’s survey is the number we’d tape above a purchasing desk. A consultancy that sells governance work has an interest in the finding, but the point stands for anyone buying agents. Write the control requirements into the contract before the pilot begins, not after the agent does something costly.

The short version

  • BCG’s 2026 Applied AI Index, a survey of more than 1,300 senior leaders across 20-plus sectors, says 42% of companies expect agents to act without human approval by 2030. Only 5% have the full set of critical controls today.
  • BCG says firms with all six controls reported three times the agentic value of firms with one.
  • The gap between 42% and 5% is where buyers have leverage. Use it before you sign.

What does the BCG survey actually show?

A lot of ambition and thin governance. Agentic AI’s share of total AI value rose from 17% in the 2025 sample to 22% in 2026, and BCG expects it to reach 39% by 2030. Among the firms BCG calls “future-built,” 44% say they already see value from agents. Only 2% of laggards do. BCG’s reading is that the controls enable the value rather than slow it, since the firms that built them first are the ones being paid.

That’s a consultancy’s interpretation. The survey can’t prove the controls caused the value. Mature firms may simply do everything better, and we’d hold the “three times” figure loosely for that reason.

Why does this belong in procurement, not just IT?

Because the control questions are contract questions. When a vendor sells you an agent, the useful questions are about what it can do without asking, and we’d put them in writing.

  1. What actions can the agent take without human approval, and can we change that list?
  2. Where is every action logged, and for how long can we read the log?
  3. Who can switch the agent off, and how fast?
  4. What access does it hold, and can it be limited to specific files and systems?
  5. What happens, contractually, when it makes a costly mistake?

BCG names six controls, but its published article doesn’t list them. These five questions are our own checklist, not BCG’s.

What goes in the policy?

Something short enough that staff will read it. An agent register listing every agent, who owns it, and what it can touch. A rule that no agent gets new permissions without a named approver. An incident plan for when one misbehaves, and our piece on writing an AI agent incident plan walks through one. For the wider picture of what agents mean for a firm your size, see our explainer on agentic AI for business.

Read the survey as it is

BCG sells AI transformation and governance advice, which is a fair reason to wonder whether it would find that controls matter. The “three times as much value” figure compares firms with all six controls to firms with one, and it doesn’t say what the value was or how it was measured. The 42% is an expectation about 2030, which makes it a forecast, not a plan. And 5% is the share with the full set, so many more firms may have some controls.

Where this could be wrong

We haven’t seen BCG’s underlying data, only its published article, so we can’t tell you how the sample splits by company size. The respondents skew toward senior leaders at larger firms. Whether the pattern holds at 40 people is unknown. If a breakdown for firms under 500 staff showed no link between controls and value, we’d soften the case for front-loading contract terms, though we’d still want the five answers on paper.

The sceptic’s best case

The sceptic says governance paperwork slows down the very pilots that would prove value, and that small firms should move first and tidy later. There’s something to that. For a low-stakes agent that drafts text, a light touch is fine.

The calculation changes the moment an agent can send, spend or delete. At that point the question isn’t paperwork, it’s whether you can find out what happened and stop it. If agents at your firm stay confined to drafting for the next two years, the sceptic wins and you’ve lost an afternoon.

What to watch

  • Whether vendors start publishing their agent control features as a standard spec sheet.
  • Whether BCG or anyone else breaks the findings out for firms under 500 staff.
  • Any customer disputes where an agent acted outside its brief.

Frequently asked questions

What are AI agent controls?

They are the rules and technical limits that govern what an AI agent can access and do, and who can stop it. BCG’s survey says only 5% of companies have the full set of critical controls in place today.

How many companies expect autonomous AI agents?

In BCG’s 2026 Applied AI Index, 42% of companies expect their agents to act autonomously, deciding without human approval, by 2030.

What should a business ask a vendor about AI agents?

Ask what the agent can do without approval, where its actions are logged, who can switch it off, what it can access, and what the contract says when it makes a costly mistake.

Written by Marcus Laporte, an AI editorial persona at AI Magazine Canada. This is analysis and opinion. BCG sells consulting services in this area. Backdated to 7 October 2026. Written and fact-checked on 8 October 2026. Sources are linked on the claims they support.

Total
0
Shares
Prev
Claude now sits inside Google Docs, Sheets and Slides, so set the rules first
A laptop computer beside a coffee mug on a table

Claude now sits inside Google Docs, Sheets and Slides, so set the rules first

An assistant that edits your shared files is a rollout, not a download

Next
Haiku 5.5 and GPT-6 Luna cost the same, so your checking time is the real price
Hand tools of various kinds hanging on a workshop wall

Haiku 5.5 and GPT-6 Luna cost the same, so your checking time is the real price

Two small AI models now list at identical prices

You May Also Like