Wants the agents working, this year.
The budget exists. The board has asked about it twice. This is the easiest yes in the building, and it is the only one the project ever gets.
Agents are cheap. Nothing that killed the last three years of enterprise pilots was a model problem. They died because the work coming out of them was unsignable: no control over what got touched, no cap on what got spent, no record anyone would put their name against.
None of the figures below are ours. Three independent readings of the same enterprise, taken by people with nothing to sell you on this page. Read together they describe one condition, and it is not a capability gap.
of agentic AI projects will be canceled by the end of 2027
Cancellation is not the same as failure. Most cancelled projects worked. Somebody looked at what it would take to run one against real systems, real money and a real audit, and could not write the memo that authorised it.
of enterprises have a mature agentic-AI governance model; four in five do not
Four in five have the mandate and not the structure. That gap is where the cancelled projects in the figure above go, and closing it is a build problem before it is a policy problem.
machine identities for every human identity: the surface nothing governs by default
Every access model an enterprise owns was designed around people: joiners, movers, leavers, a quarterly review. Machine actors already outnumber people eighty-two to one, and almost none of them sit inside that model.
A survey result is an abstraction until you put it on a grid. One hundred enterprises, every one of them with agents already bought, a board asking about them and a budget behind the answer. Light the ones whose governance is mature enough to answer for the work.
21 of every 100 enterprises
hold a mature agentic-AI governance model · Deloitte
The twenty-one are not the ones with the better models. Everybody had the same models, from the same handful of providers, inside the same eighteen months. What separates them is that somebody could answer five questions in writing before the work went live: what it can touch, what it can spend, who approves, what ships, and what got logged.
The rest have the mandate and not the structure, and they find that out in a meeting rather than in a benchmark. That meeting is the next section.
None of this is mysterious once you sit in the room where the decision actually gets made. The mandate is genuine and well funded. So are the objections, and every one of them is correct.
Wants the agents working, this year.
The budget exists. The board has asked about it twice. This is the easiest yes in the building, and it is the only one the project ever gets.
Nothing controls what an agent touches.
A prompt is not a permission. If the only thing between a model and a production repository is an instruction not to go there, the control being signed off is a paragraph of text that other text can argue with. No security officer signs that, and none should.
Agent spend is unbounded by default.
Spend is metered per token and reported the next morning. A run that goes wrong keeps costing money until a person notices it, and the bill is the first place anyone finds out. There is no ceiling to write into a budget line, only a number to read afterwards.
There is no forensic record of any of it.
Application logs are not an audit trail. They record that something happened, not who authorised it, under which limit, against which version of the rules. Asked to reconstruct a single decision from six months ago, nobody can. That answer is a no before it is a finding.
The standard answer to all three refusals is a document. An AI usage policy, a set of written guardrails, a review board, a training module with a completion certificate. Each one sits beside the work instead of inside it, and each one is, in the end, a request.
Written rules govern people because a person can be held responsible for breaking one. That mechanism is missing here. A rule that exists only on paper has to be obeyed voluntarily by something that cannot be sanctioned, cannot be fired, and will not remember the training.
Read the three refusals again against that sentence. The security control becomes a path list checked against the diff, so out-of-bounds work never becomes a pull request at all. The spend ceiling becomes a cap checked before the model is called, and a ledger written in micro-dollars while the run happens. The audit record becomes a by-product of a chain of command in which nothing approves its own work and a named person signs every merge it holds in probation.
None of that is a claim about how well the agents behave. It is a statement about what the architecture will and will not let through, which is the only kind of statement the three refusers can sign. It installs in your own infrastructure, which is how the same argument answers the question sitting underneath all five: the code and the data never leave.
This essay is the diagnosis. The library is where the structural answer is worked out in detail, one decision at a time.
Defined seats, hard gates on what any AI can touch and spend, and a human signature on every merge until you graduate it. It runs in your own infrastructure.