
AI Agent Adoption Hits a Trust Ceiling
86% of enterprises have deployed AI agents, but only 34% trust their actions. Governance, liability and execution evidence are now the scaling constraint.
Executive Signal: Enterprise AI Agent Adoption Is Outrunning Trust
July 20 produced the clearest evidence yet that enterprise AI agent adoption is moving faster than organizational trust.
A Boomi-commissioned Forrester Consulting study found that 86% of surveyed organizations had moved beyond AI agent pilots, but only 34% trusted the actions their agents were taking. BCG argued that regulated industries need shared agent architecture and governance before agents become embedded across workflows. HSBC and the Emerging Payments Association Asia began formal work on identity, authorization and liability in agentic payments. CoSAI expanded its security agenda around agent credentials, Model Context Protocol security and secure agent design. SAP placed agent discovery, approval and governance inside its enterprise AI platform.
The previous editions showed identity and runtime control becoming security boundaries. July 20 shows the commercial consequence of failing to build them.
Tesseris signal: Agent deployment is no longer the principal constraint. The market now needs evidence that each agent is known, authorized, secure, auditable and accountable for its outcome.
Deployment is no longer the bottleneck. Accountability is.
Key Signals Across Enterprise AI Agents, Payments and Governance
- Adoption gap: Enterprise AI agent deployment has crossed into production faster than trust and governance have matured.
- Trust ceiling: Only a minority of surveyed organizations say they trust agent actions, even as most are moving beyond pilots.
- Regulated workflows: Banking, healthcare and other regulated sectors need common platforms for identity, permissions, guardrails and audit.
- Payment liability: Agent-initiated payments are forcing banks and payment networks to define authorization, fraud and loss allocation.
- Security posture: Agent identity, credentials, MCP connections, telemetry and runtime isolation are becoming security infrastructure.
- Verification layer: Agent hubs and governance badges are useful, but portable evidence is required when agents cross platform boundaries.
Why July 20 Matters for the Agent Economy
The AI agent market is entering a new phase.
In the first phase, organizations asked whether agents could complete useful work. In the second phase, they asked whether agents could be integrated into enterprise systems. The July 20 evidence set shows the third phase beginning: organizations now need to prove that autonomous work is legitimate, bounded, secure and attributable.
This distinction matters because adoption numbers can hide fragility. A company can deploy hundreds of agents and still lack confidence in what those agents are allowed to do, whether their tool calls remain inside scope, whether the runtime is secure, who is liable for failed actions and whether the final outcome can be independently verified.
The Agent Economy therefore scales only when deployment, governance and accountability move together.
1. Boomi and Forrester Identify a Widening Enterprise AI Agent Trust Gap
Source: Boomi commissioned Forrester study on enterprise AI agent adoption
Forrester Consulting surveyed 409 senior technology decision makers across North America, Europe and Asia Pacific on behalf of Boomi.
The study found that 86% of participating organizations had moved beyond the AI agent pilot stage, while only 34% said they trusted the actions their agents were taking.
Organizations in the lowest quartile for governance, integration and operational readiness were classified as experiencing agentic chaos. Among that group, 77% were moving agents into production despite control gaps. The study estimated an average of USD 2.1 million in additional costs from compliance failures, customer loss, downtime and rework.
Organizations with stronger agent controls reported substantially greater confidence in agent decisions.
Market signal: Enterprise adoption has crossed the trust threshold.
Organizations are no longer waiting for complete governance before deploying agents. They are accepting operational exposure first and attempting to add controls afterward.
Tesseris read: Organizational confidence is not a reliable trust metric.
Trust should be based on evidence connecting the agent identity, represented principal, active mandate, data and tools used, actions performed, verified outcome and responsible party.
An organization should not need to trust an agent blindly. It should be able to verify why the action deserves trust.
2. BCG Says Regulated Industries Need a Common Agent Platform Before Scale
Source: BCG on building enterprise AI agents in regulated industries
BCG argued that companies in regulated sectors need a shared enterprise agent platform rather than separate agent deployments created independently by different business units.
The proposed platform should standardize orchestration, model access, evaluation, guardrails, memory, knowledge management, security and monitoring. BCG also identified identity, access and entitlements as architectural decisions that should be established before agents become embedded across business workflows.
This is particularly important in banking, healthcare and other regulated industries where an agent action may create audit, compliance or legal exposure.
Market signal: Governance is becoming an architectural layer rather than a compliance overlay.
Organizations that defer identity, permissions and audit design until after deployment will accumulate incompatible agents, fragmented controls and incomplete evidence.
Tesseris read: A shared platform can control agents inside one organization.
It does not automatically preserve accountability when an agent invokes an external service, delegates to another agent or operates across platforms. The complete workflow must retain the original authority, every agent and tool invoked, the scope passed at each stage, evidence returned by each participant and the final accountable outcome.
Central governance manages the platform. A continuous delegation record governs the complete workflow.
3. HSBC and EPAA Move Agentic Payment Liability Into Formal Industry Work
Source: EPAA and HSBC AI and Agentic Payments Working Group announcement
The Emerging Payments Association Asia launched an AI and Agentic Payments Working Group with HSBC as a founding member.
The initiative brings together banks, payment networks, financial technology companies and technology platforms to develop common approaches for agent identity, authentication, authorization, liability and fraud across Asia Pacific.
The working group is addressing unresolved questions: who is responsible when an agent exceeds its mandate, how agents should be identified across borders, how fraud systems should distinguish valid machine-speed activity from a compromised account and how disputes should be resolved when software initiated the payment.
Its recommendations are expected to feed into engagement with ASEAN and APEC governments and central banks.
Market signal: Agentic payments have become a liability problem, not only a payment transport problem.
The ability to move money is advancing faster than the rules determining who authorized the transaction and who absorbs the loss when it fails.
Tesseris read: Every agent-initiated payment should carry a verifiable transaction context.
That context should include agent identity, represented customer or organization, payment mandate, amount and merchant limits, validity period, required service outcome, execution evidence, challenge and refund conditions, and final settlement status.
A payment credential proves access to funds. A signed mandate proves the right to use them for a specific purpose.
4. CoSAI Expands the Security Agenda From Models to Agent Systems
Source: CoSAI Year 2 agenda for agentic security
The Coalition for Secure AI outlined expanded work on security for autonomous agent systems.
Its program now includes agent identity and access management, Model Context Protocol security, secure agent development, agent credential standards, zero trust controls, telemetry, incident response and shared responsibility.
CoSAI said traditional security frameworks were not designed for agents that plan, delegate and execute across multiple systems. Its upcoming work includes updated Model Context Protocol guidance, zero trust guidance for AI systems and an artifact integrity maturity model for AI supply chain provenance.
Market signal: Agent security is becoming a system discipline.
The security target now includes the agent, credentials, tools, memory, communication protocols, software artifacts and execution environment.
Tesseris read: Security posture should become part of an agent's persistent trust record.
That record should identify active software version, known vulnerabilities, credential status, approved tools and connections, runtime isolation, security attestations, revocation state and relevant incidents.
A capability claim should not remain trusted after the agent's security posture has materially changed.
Capability verification without continuous security status creates stale trust.
5. SAP Turns Enterprise Agent Governance Into a Central Control Layer
Source: SAP AI Agent Hub and autonomous enterprise governance
SAP detailed its expanding autonomous enterprise stack, including Joule Work, the SAP Autonomous Suite, Joule Studio and the SAP AI Agent Hub.
The AI Agent Hub is designed to discover AI agents, models and Model Context Protocol servers across SAP, Microsoft, Google, AWS and ServiceNow environments. It also supports governance assessments and verification badges that can influence which agents and services are approved for runtime use.
SAP plans to extend the hub into runtime observability, identity and access control, process analysis and workforce impact mapping. The broader platform is moving agents into finance, supply chain, procurement, customer operations and software development workflows.
Market signal: Enterprise vendors are centralizing discovery, approval and governance across agent fleets.
The control plane is becoming as important as the individual agent because it determines which systems are visible, permitted and monitored.
Tesseris read: A platform-issued verification badge is useful within that platform's governance boundary.
Cross-platform commerce requires evidence that can be understood independently of the platform that issued it. A portable trust record should identify who verified the agent, which capability was tested, under which conditions, which software version was assessed, when the result expires and whether the result has been challenged or revoked.
Discovery becomes trustworthy only when verification remains portable and auditable.
Tesseris Trust Ceiling Framework for Enterprise AI Agents
The July 20 evidence identifies five constraints now limiting enterprise agent scale.
1. Identity
Organizations must know which software actor performed each action.
2. Authority
Every action must remain inside a specific mandate granted by a responsible principal.
3. Runtime Security
The agent, tools, credentials and execution environment must remain approved and uncompromised.
4. Outcome Evidence
A trace of activity must be converted into proof that the intended obligation was completed.
5. Liability and Settlement
The responsible party, dispute path and financial consequence must be defined before execution.
Adding more agents without these controls raises deployment numbers without raising accountable economic capacity.
Strategic Read: The Next Agent Infrastructure Category Is Trust
Enterprise AI agent adoption is no longer waiting for trust infrastructure.
Organizations are moving agents into production while confidence, governance and liability remain unresolved. That creates a temporary market in which deployment appears successful because agents are active, even when their authority and outcomes cannot be fully reconstructed.
The next infrastructure category will not be another agent builder.
It will be the system that connects persistent identity, delegated authority, runtime security, execution evidence and final accountability across platforms.
The Agent Economy scales when organizations no longer have to choose between autonomy and trust.
Market Conclusion: Accountability Is the New Bottleneck
The market has moved from proving that agents can be deployed to proving that agents can be trusted.
That shift changes where enterprise budgets, standards work and platform competition will concentrate. Builders will still need orchestration, memory, tools and model access. But the durable value layer will be the system that proves who acted, under whose mandate, against which policy, inside which runtime and with what verified result.
Deployment metrics show activity. Trust infrastructure shows accountable economic capacity.
What to Watch Next in Enterprise AI Agent Trust
- Whether enterprise agent studies begin measuring verified outcomes rather than deployment counts.
- Whether payment standards define portable agent mandates and liability rules.
- Whether security frameworks connect agent identity to runtime posture and revocation.
- Whether enterprise agent hubs accept independent verification evidence across platforms.
- Whether regulated industries require execution receipts before agents can operate in high-risk workflows.
Frequently Asked Questions About Enterprise AI Agent Trust
Does the 86% figure mean most enterprises have fully autonomous agents in production?
No. The figure comes from a Boomi-commissioned Forrester Consulting survey of 409 senior technology decision makers. It indicates movement beyond pilots among surveyed organizations, but it does not establish that every deployment is mature, autonomous or operating at large scale.
Why do organizations deploy agents they do not fully trust?
Organizations face pressure to capture productivity and competitive benefits quickly. Deployment can occur before integration, governance, identity and evidence systems are complete, especially when different business units adopt agents independently.
What is required to trust an agent-initiated payment?
A trustworthy payment should connect the agent identity, represented principal, explicit mandate, transaction limits, merchant, execution evidence, dispute process and final settlement decision.
What is an enterprise AI agent trust ceiling?
An enterprise AI agent trust ceiling is the point where organizations can deploy more agents but cannot safely expand their authority because identity, policy, runtime security, liability and outcome verification are incomplete.
Why does execution evidence matter for AI agents?
Execution evidence turns an agent's activity into an accountable record. It helps determine what the agent was asked to do, what authority it used, which actions occurred, whether the outcome was completed and who is responsible if the result fails.
Research Note
This bulletin synthesizes five sources associated with July 20, 2026.
The Boomi research was commissioned by Boomi and conducted by Forrester Consulting. Its findings represent the surveyed sample rather than every enterprise. The BCG article presents an advisory architecture for regulated industries. The EPAA and HSBC initiative is a working group whose standards and policy recommendations remain under development. The CoSAI article summarizes coalition work and planned security guidance. SAP performance figures and product benefits are vendor-reported estimates unless independently verified.
Reported facts are separated from Tesseris analysis and strategic interpretation.
Final Take: Adoption Numbers Are Not Trust
Enterprise AI agent adoption is accelerating, but trust remains the constraint that determines scale.
The winning infrastructure will not only help organizations deploy agents. It will prove that each agent action was authorized, secure, attributable, outcome-linked and economically accountable.



