AI Agent Governance Is Nobody's Job: What a Survey of 228 Enterprise Architects Found
A March 2026 survey of 228 enterprise architects finds 98% of companies are deploying or planning AI agents, but only 17% can see how those agents are actually performing, and 48% have no one clearly responsible for governing them.

Ask most companies whether they're using AI agents and the answer, increasingly, is yes. Ask who's actually responsible for governing them — tracking what they do, whether they're performing, whether they're compliant — and the answer, for nearly half of companies, is: nobody in particular.
That's the core finding of the SAP LeanIX Agentic AI Survey 2026, a study of 228 enterprise architecture leaders and IT decision-makers at companies around the world, surveyed online in March 2026. The companies surveyed span company sizes evenly, with 37% employing more than 10,000 people — this isn't a snapshot of small shops still figuring things out; it includes a lot of large, resourced organizations.
Everyone's deploying agents. Almost no one can see what they're doing.
The headline numbers from the survey:
- 98% of companies surveyed have deployed, or plan to deploy, AI agents
- Of those, only 17% have real visibility into agent performance or conformance — meaning the overwhelming majority are running agents they can't actually monitor
- 48% of companies have no clearly defined roles or responsibilities for managing and governing their AI agents
- 75% of respondents believe specific guidelines for AI agents are necessary — yet that 48% figure shows most haven't written any
- 63% of respondents think enterprise architects are the right people to lead AI agent governance strategically — but only 34% of EAs are actually involved in it today
Put those together and the shape of the problem is clear: adoption has outrun governance by a wide margin, nearly everyone agrees governance matters, and the people best positioned to own it are mostly sitting on the sidelines of their own organizations' agent rollouts.
This isn't an edge case — it's already the default state
It would be easy to read "48% have no clear roles" as describing laggards. The survey suggests the opposite: it's close to the median experience. 44% of companies surveyed are already deploying AI agents in production (even if only within limited functional areas), another 40% are actively experimenting, and 14% are planning to start. More than 60% say agents are being deployed or planned across multiple functions or departments at once — meaning the governance gap isn't confined to one team's pilot project; it's spreading across the organization at the same pace the agents themselves are.
The survey's own framing is direct about where this leaves companies: "The crucial question, therefore, is no longer whether companies will use AI agents, but how they will manage and account for this powerful innovation. However, significant gaps are evident precisely in this area."
Why enterprise architects specifically are the gap
The survey's most pointed finding isn't just that governance is thin — it's that the people with the actual expertise to do it are being left out. Enterprise architects already own the job of tracking what software and systems a company runs, how they connect, and who's accountable for them. Nearly two-thirds of survey respondents (63%) say EAs are well-positioned to strategically drive AI agent adoption and governance. But in practice, EAs are sidelined from that role in roughly two-thirds of companies — involved in only 34% of organizations' actual AI agent governance efforts.
That mismatch tracks with a broader pattern the survey found: AI agent governance currently gets split across "multiple teams," rather than owned by any one function with the right expertise and authority to actually enforce it. Shared ownership, in practice, often functions like no ownership — which is consistent with the 17% visibility figure. If no single team owns tracking an agent's performance and compliance, it's not surprising that most companies can't see it.
What this looks like for a company trying to get ahead of it
The survey points at a structural fix more than a technical one: assign a clear owner for AI agent governance before agent deployment spreads further across departments, rather than trying to retrofit oversight after the fact. For companies already past that point — which, per the "60% deployed across multiple functions" figure, is most of them — the practical starting point the data suggests is narrower than "write an AI governance policy." It's: who in this organization can currently tell you what every deployed agent is actually doing right now, and if the honest answer is "no one clearly," that's the gap to close first, before adding more agents on top of an already-invisible layer.
The pattern echoes something enterprise software has seen before, just moving faster this time: capability gets adopted team-by-team long before anyone owns tracking it centrally, and the resulting blind spot becomes expensive to unwind the longer it's left alone. The agent-adoption curve in this survey — 44% already in production, 40% experimenting, 14% planning — suggests most companies have a very short window left to assign that ownership before the blind spot becomes the default, permanent state of their AI agent program.
Workmate
See what an agent team would do for your business.
Keep reading

Why Companies Can't See What Their AI Agents Are Actually Doing
Three separate 2026 surveys covering nearly 2,600 IT and business leaders all land on the same finding: as AI agents take on more real work, the people running them are losing track of what those agents are actually doing, and it's already causing breaches.

AI Agents Are Your Fastest-Growing Identity Risk
Machine identities now outnumber humans by 45-to-1 in the average enterprise, and AI agents are the fastest-growing, least-governed category. What two 2026 security reports reveal about the access-governance gap nobody owns.

Your Company Has Shadow AI Agents. Here's How Many You Don't Know About
A new CSA and Token Security survey finds 68% of organizations feel confident in their AI agent visibility, yet 82% discovered an agent security or IT never knew about in the past year, and 65% had an actual agent security incident. Here's the gap.