What the Research Says
Forrester's new report, The State of Agentic AI, 2026, puts a hard number on something most teams have sensed all year. Roughly three-quarters of enterprise leaders say they're adopting agentic AI, but very few have it running in real production beyond glorified chatbots and true multi-agent systems operating at scale are rarer still.
Forrester's own metaphor captures the gap: agentic AI is a runaway train, and most enterprises are the heavy load being dragged behind it.
Scaling doesn't fail because of how many agents you deploy, it fails because of task complexity nobody is actually managing.
What's Actually Changed Since Last Year
Not ambition maturity. Agents can now run unsupervised for hours, days, even months, from long-running coding agents to multi-day research agents. That makes an agent behave less like a tool and more like a distributed system, which means it needs orchestration, identity management, and shared context that most enterprise IT stacks were never built to provide.
Key Data Points From the Report
- ROI uncertainty keeps most agentic AI stuck in pilot purgatory.
- Governance gaps widen fast once agents begin invoking tools and taking action autonomously.
- Nearly half of security decision-makers now name agentic AI as an active concern.
- The reasons cited: immature non-human identity management, agents impersonating each other or escalating privileges, and agent populations growing faster than security teams can track.
The "Trust Tax"
Every autonomous action an agent takes has to be logged and defensible to an auditor. Building that instrumentation layer properly is expensive expensive enough that even well-resourced organizations haven't captured the ROI they expected.
Forrester's Recommended Roadmap
- Invest in orchestration before adding more agents.
- Redesign the workflow around autonomy don't bolt an agent onto a process still paced for humans.
- Treat every agent as a governed identity: own credentials, least-privilege access, full logging, and one named owner accountable for its lifecycle.
Zymr's POV
This is exactly the pattern we've been navigating with clients over the past year. Forrester's "chase versus catch" framing matches what we see in nearly every engagement.
Where We See This Play Out
- Interest in agentic AI is universal; production maturity is not.
- Teams get stuck debating SaaS agent vs. systems-integrator build vs. custom build before they've defined the problem clearly enough to choose.
- The governance and observability layer is consistently under-priced. Teams budget for the model and the integration work, but rarely for the instrumentation an auditor will actually demand later.
Our Take on the "Trust Tax"
We'd call this the single most underestimated cost line in agentic AI budgets today. It's not optional it's the layer that determines whether an agent deployment survives its first serious audit.
Our Take on Security and Governance
You can't govern autonomous systems with a quarterly policy review. Identity and access controls need to be enforced as code, running continuously alongside the agent itself not written into a document and hoped for.
Where We Agree Most With Forrester
Our practical guidance to clients comes down to four moves:
- Build orchestration and identity infrastructure before scaling agent count.
- Redesign the workflow itself around autonomy, rather than retrofitting automation onto a human-paced process.
- Give every agent a named owner. An agent without one is unmanaged, no matter how well it performs in a demo.
- Start with bounded scope and real approval gates expand autonomy in stages, only as controls prove themselves.
Bottom Line
The technology has outpaced enterprise readiness, and closing that gap is an operational and governance problem, not a technical one. The organizations pulling ahead aren't deploying the most agents they're the ones building the control infrastructure first, then scaling deliberately.