Only 11% of Executives Feel Ready for AI Agent Deployment, IBM Survey Finds

An IBM survey of 2,000 C-suite executives found just 11% feel prepared for AI agent rollout, raising questions about authority, visibility, and control.

An IBM survey of 2,000 C-level technology executives found that only 11% felt fully prepared for AI agent deployment in the year ahead. Two-thirds of CIOs and CTOs said they were accountable for AI systems they did not fully control, and 70% said teams were deploying technology faster than IT could track. The findings point to a widening control gap as AI use spreads across business functions.

Madhuri Chandoor, founder of PromptHalo, frames that gap as a question of capability versus authority. PromptHalo positions itself as AI security and trust infrastructure that inspects why a given action is being performed, not only what is being performed, so organizations can judge whether an action reflects user intent, assigned permissions, and surrounding context.

What the IBM study measured

IBM’s 2026 study polled 2,000 C-level technology executives about their readiness for AI agent deployment over the following year. The headline result, that 11% felt fully prepared, sat alongside two structural concerns:

  • Accountability without control: roughly two-thirds of CIOs and CTOs reported being accountable for AI systems they did not fully control.
  • Visibility lag: 70% said teams were deploying technology faster than IT could track.

IBM framed the results as evidence of a growing control gap as AI adoption scales inside enterprises.

Why capability and authority are different things

Chandoor draws a line between what an agent can do and what it is authorized to do. In her reading, earlier chatbots operated within predetermined questions and answers. Large language models now draw on broader company information and tools, which expands the exposed risk surface and raises questions about how incoming requests can influence a system.

She uses a database task to illustrate the stakes. An infrastructure-managing AI agent asked to improve application performance might add or remove an index or change table structures autonomously in a production environment. That action could affect live transactions, customer data, or dependent processes outside the agent’s immediate analysis.

"A technical conclusion can appear reasonable within a narrow focus," Chandoor says. "The context, the situation, and the downstream impact still need to be considered before an action proceeds."

How a refund request can slip past a single-action limit

Chandoor’s refund example shows why review at the level of individual actions can miss coordinated risk. In her scenario, an agent is permitted to issue refunds up to $50 without human review. A user then requests ten $50 refunds instead of one $500 refund, which would trigger review.

Each transaction can look permissible on its own. The sequence suggests an effort to stay below the threshold. From her perspective, reviewing broader session context and behavior helps identify when escalation for human review is appropriate.

Behavioral profiling for agents, borrowed from fraud monitoring

Chandoor spent two decades in financial services, and she maps that background onto agent oversight. Fraud monitoring reviews activity across transactions and accounts. She argues organizations should build behavioral profiles for autonomous agents alongside standard identity and access permissions.

Under her model, teams review:

  • The resources an agent accesses
  • The tools it uses
  • Changes in activity over time
  • Actions inconsistent with assigned role or session circumstances

The intent is to flag requests that are repeated, unusually broad, or inconsistent with the purpose originally assigned to the agent.

What to document before agents go into production

Chandoor recommends treating authorization as a design-time and run-time question, not a one-time check. Her checklist for teams rolling out agents includes:

  • Resources the agent may access
  • Conditions that apply to that access
  • Possible downstream effects of particular actions
  • Observability gates that review activity, especially for repeated, broad, or off-pattern requests

Those checkpoints, she argues, contain the impact of a misfire and surface what additional controls are required to secure the underlying systems.

The operating principle: trust, but verify

Chandoor describes her position as support for responsible AI adoption rather than a slowdown. She favors agentic automation for analysis and workflows, paired with extra verification when the impact touches critical decisions and actions.

"Trust, but verify," she says. "Businesses should adopt AI responsibly and verify its behavior throughout the process. Establishing clear accountability ownership across the organizations for AI applications security is essential to operationalise these guardrails."

The wider aim, in her view, is to give security and accountability the same weight as the push to innovate with AI agents.

FAQ

What did the IBM AI readiness survey find?

A 2026 IBM survey of 2,000 C-level technology executives found that only 11% felt fully prepared for AI agent deployment in the following year. About two-thirds of CIOs and CTOs said they were accountable for AI systems they did not fully control, and 70% said teams were deploying technology faster than IT could track.

What is the difference between AI agent capability and authority?

Capability is what an AI agent can technically do with the tools and data it can reach. Authority is what it is permitted to do under assigned permissions and current context. PromptHalo’s founder Madhuri Chandoor argues that reviewing only what an agent is doing misses cases where a single action is technically reasonable but its downstream impact falls outside the agent’s intended scope.

How can organizations monitor AI agents for risky behavior?

Chandoor recommends building behavioral profiles for agents alongside standard identity and access permissions, mirroring fraud monitoring in financial services. Teams should document the resources an agent may access, the conditions on that access, the downstream effects of specific actions, and observability gates that flag repeated, unusually broad, or off-pattern requests for human review.


This article summarizes reporting from thenextweb.com. See our editorial disclaimer for how our articles are produced.

🤖
Is your business visible to AI assistants?

Run a free scan to see your AI Visibility Score, SEO rating, and local citation accuracy.

Check Your Score →