Enterprises Face AI Agent Control Gap as Executive Preparedness Lags, IBM Study Finds
PromptHalo founder Madhuri Chandoor advocates for behavioral profiling and contextual authorization to secure autonomous AI workflows in corporate networks.

As enterprise adoption of autonomous artificial intelligence software accelerates, a significant majority of corporate technology executives report that their organizations remain unprepared to manage the operational risks associated with AI agent deployments. According to an IBM survey of 2,000 C-level technology leaders, a growing governance void is opening up between the pace at which employees implement automated tools and the ability of internal IT departments to monitor them effectively.
The IBM study revealed that only 11% of surveyed executives feel fully prepared for the rollout of AI agents expected over the next 12 months. Furthermore, two-thirds of chief information officers and chief technology officers admitted to holding organizational accountability for AI deployments over which they exercise no direct operational oversight. Additionally, 70% of respondents noted that internal teams are adopting new software tools faster than corporate IT departments can track. The findings highlight a widening control gap as autonomous systems gain broader enterprise access, as first reported by The Next Web.
Addressing this control deficit requires distinguishing between an agent's technical capability and its operational authority, according to Madhuri Chandoor, founder of AI security and trust infrastructure provider PromptHalo. Rather than relying solely on traditional access controls that confirm whether an agent possesses credentials to execute an action, PromptHalo inspects the rationale and environmental context behind specific requests. The approach aims to evaluate user intent, assigned permissions, and surrounding circumstances before an automated agent executes tasks.
To demonstrate the risks of context-blind execution, Chandoor pointed to an autonomous infrastructure management agent tasked with optimizing database performance. While the system might logically deduce that modifying table structures or adding database indexes would accelerate query speeds, taking those actions autonomously in a live production environment could disrupt active customer transactions, compromise data, or break dependent software processes. "A technical conclusion can appear reasonable within a narrow focus," Chandoor says. "The context, the situation, and the downstream impact still need to be considered before an action proceeds."
The shift from early conversational chatbots—which operated within predetermined question-and-answer trees—to modern large language models connected to external tools has expanded corporate attack surfaces. Chandoor illustrated how intent can be obscured across multiple interactions using a refund processing scenario. If an automated agent is capped at issuing $50 refunds without human review, a user might submit ten consecutive $50 requests to circumvent a $500 threshold requiring manual authorization. While each transaction appears permissible individually, evaluating the full session sequence reveals a clear attempt to bypass policy controls.
Drawing from two decades of experience in the financial services sector, Chandoor advocated for implementing agent behavioral profiling systems structured similarly to financial fraud monitoring networks. Under this framework, enterprise security teams establish behavioral baseline profiles alongside traditional identity and access management permissions. Organizations monitor the internal resources an agent accesses, its tool usage patterns, activity changes over time, and actions that diverge from its designated job role or session context.
To contain potential operational risks, Chandoor recommends evaluating authorization requirements during both the initial architecture phase and active operation of AI systems. Organizations should document which digital resources an agent can access, define explicit environmental conditions, and map out potential downstream effects. Implementing observability checkpoints enables security systems to inspect activity and intervene when requests become unusually broad, repeated, or inconsistent with the agent's assigned mandate.
Ultimately, Chandoor frames these security controls as essential infrastructure for responsible software automation rather than impediments to technical innovation. "Trust, but verify," she says, emphasizing that leadership must establish clear ownership over AI security governance across departments. "Businesses should adopt AI responsibly and verify its behavior throughout the process," she says. "Establishing clear accountability ownership across the organizations for AI applications security is essential to operationalise these guardrails."
Sources
Written by
The Company Wire
Inside the companies building what’s next. Reporting on startups, technology, funding and the people shaping them.



