AI Governance8 min read

Gartner Says $234 Billion in Software Spend Is at Risk From Agent AI. The Real Problem Is No One Can Prove Governance Is Working

Gartner says $234 billion in software spend is at risk from agent AI. Fewer than one in five organisations can prove their governance controls work.

Shane CoetserBy Shane Coetser
AI Governance Assurance: Why Fewer Than One in Five Organisations Can Prove Their Controls Work

Gartner has put a specific number on the agent AI governance gap: 234 billion US dollars in enterprise software spending is at risk because of it. Arctera's State of AI Governance 2026 report supplies the detail that actually explains the number. Fewer than one in five organisations using AI can prove that their governance controls are functioning as intended. Not that they lack a policy. That they cannot demonstrate the policy does anything.

That distinction is the entire story here, and it is being missed by most of the coverage repeating the headline figure without asking what it actually implies.

The Difference Between Having Governance and Proving Governance

A use case register exists in plenty of organisations that would still fail if asked to demonstrate, with evidence, that the risk assessments in that register reflect what the AI systems are actually doing today. A policy document describing how AI decisions should be reviewed is not the same as a record showing that review actually happened, on which systems, and with what outcome.

This is where most AI governance programmes quietly stop. Building the policy is treated as the finish line. Building the ongoing evidence trail that proves the policy is being followed, which is considerably harder and less visible work, rarely gets the same attention.

Why This Gap Is Specifically Worse for Agentic AI Than for Earlier AI Systems

A chatbot generates an output a human can review after the fact. An agent takes an action, and by the time anyone reviews it, the action has already happened. Proving governance for agentic systems requires evidence of what decisions were made and why, not just evidence that the final output looked reasonable. That is a fundamentally harder audit trail to build, and it is exactly the trail 78 percent of organisations say they expect to need more of as communications and other risks increase with agent AI adoption.

Gartner's projection that 40 percent of enterprise applications will carry embedded agents by the end of 2026, up from under 5 percent in 2025, means this assurance gap is scaling at the same pace as adoption, not lagging safely behind it.

What "$234 Billion at Risk" Actually Means in Practice

That figure is not an abstract estimate of theoretical exposure. It represents enterprise software spending committed on the assumption that agent AI deployments would deliver value safely, spending that is now genuinely at risk precisely because the organisations making it cannot demonstrate the governance controls underpinning that assumption are actually working. If an incident, an audit or a regulator ever tests that assumption, the gap between having a policy and being able to prove it functions is exactly where the exposure sits.

In practice, this is where boards are increasingly likely to ask the harder follow up question. Not whether AI governance exists, but whether anyone could produce evidence of it functioning if asked tomorrow.

What Governance Assurance Actually Looks Like

Real assurance looks less like a policy document and more like an audit trail. Independent testing of controls, not just a description of what the controls are supposed to do. Regular sampling of actual agent decisions checked against stated policy, not an assumption that policy compliance is automatic. And documentation built in a form a board, an auditor or a regulator could actually review as evidence, rather than a governance framework that exists mainly as an internal reference document nobody outside the AI team ever reads.

Building the Evidence Trail Before Someone Asks for It

The organisations least exposed to the risk behind Gartner's figure are not necessarily the ones with the most sophisticated governance policy. They are the ones that can already produce evidence, on short notice, that their policy reflects what is actually happening inside their AI systems. Building that evidence trail before a regulator, an auditor or a board asks for it is considerably easier than trying to reconstruct it after the fact.

What This Means for Your Organisation

What we see across the organisations we work with is that the gap between governance existing and governance being provable is almost always where an otherwise well-intentioned programme breaks down. Building the register and the policy is the easy half. Building the ongoing evidence that both are actually being followed is the half that determines whether an organisation can answer a hard question convincingly when one is eventually asked.

Key Takeaways

  • Gartner estimates $234 billion in enterprise software spending is at risk due to gaps in agent AI governance.
  • Arctera's State of AI Governance 2026 report finds fewer than one in five organisations can prove their governance controls are functioning, distinct from simply having a policy in place.
  • Agentic AI makes this gap worse than earlier AI systems because proving governance requires evidence of actions taken, not just review of generated outputs after the fact.
  • Genuine governance assurance requires independent testing of controls, regular sampling of agent decisions against policy and documentation built for external review, not internal reference alone.
  • Organisations that can already produce evidence of functioning governance controls are far better positioned than those that would need to reconstruct that evidence after an incident or audit.

How Trusenta Can Help

Compliance Management builds the evidence tracking and audit trail this post describes, so governance controls can be demonstrated, not just described.

AI Governance links each AI system and agent to its risk assessment and monitoring record, the foundation any assurance process needs.

Risk Management tracks control testing and treatment outcomes over time, turning a static policy into an ongoing evidence base.

Conclusion

The headline number from Gartner is attention grabbing, but the more useful figure is the one from Arctera underneath it: fewer than one in five organisations can actually prove their AI governance works. Policies are not hard to write. Evidence that a policy is followed, tested and functioning is considerably harder to produce, and it is precisely the thing most exposed organisations will not have when someone finally asks for it.

Shane Coetser

Written by

Shane Coetser

With over 30 years of experience delivering real technology outcomes, he combines strategic insight with deep technical expertise across enterprise, cloud and AI. At Trusenta, he helps organisations move beyond AI hype to accountable, sustainable impact.

Connect on LinkedIn

Ready to transform your AI strategy?

Partner with Australia's AI strategy and governance specialists. From adoption roadmaps to ISO 42001 audit readiness.