The main thing slowing agentic AI down is not the technology or the skills to use it. It is governance: who is accountable, what is recorded, and how anyone can show later what an agent did and why. Businesses that answer those questions before they deploy move faster than those that treat governance as a final review.
The numbers
Omdia's research, based on polls of MSPs and IT decision-makers in 2025, put governance and compliance at the top of the list of barriers to implementing agentic AI, named by 47% of respondents. Technical expertise gaps were named by 16%, value realization and adoption by 14%, and data and security management by 14%.
Smaller businesses say the same thing in their own words. In the Upwork Research Institute's 2026 survey of SMB leaders, data security and compliance was the top barrier to AI agents at 27%, ahead of uncertainty about return on investment at 24%.
Why governance is harder with agents
A chatbot answers questions. An agent acts: it updates records, sends documents, triggers payments. That changes the questions a business has to answer:
- Who is accountable when an agent gets something wrong?
- Which decisions can an agent make alone, and which need a person?
- What exactly did the agent see, decide and do, and with which model version?
- How would we show a regulator, auditor or client what happened?
Most organizations have good answers for their people and their systems. They do not yet have them for software that makes decisions.
Regulators are setting expectations
In insurance, the direction is clear. The NAIC adopted its model bulletin on insurers' use of AI systems in December 2023, and about half of US states have since adopted it. The bulletin expects insurers to have a written AI program covering governance, risk management, internal controls and oversight of third-party vendors. It applies to insurers rather than agencies, but those expectations flow down to anyone supporting insurer processes.
Outside insurance, the NIST AI Risk Management Framework is the most widely used voluntary US reference for structuring AI governance.
What good governance looks like in practice
Governance does not need to be a committee. For agent work it comes down to four things done every time:
- Named accountability. A person owns each process and each type of decision.
- Routing rules. Low-confidence items go to trained people. Licensed and financial decisions go to named approvers.
- A complete record. Inputs, steps, model versions and human approvals for every outcome, stored so later edits are detectable.
- Review. Someone looks at exceptions, errors and trends regularly, and has the authority to change the process.
When those four are built into the process, the conversation with legal, compliance and auditors gets much shorter.
How we built for it
We designed Agentic MSP around this barrier rather than around the technology. Every outcome has a record in the Evidence File. Low-confidence work goes to our exception desk, and your team signs off anything that needs a license or moves money. See how to build an audit trail for AI agents if you are doing this yourself.