McKinsey State of AI 2026: Agents Scale, Trust Lags
McKinsey's 2026 survey finds enterprises scaling AI agents from 27% to 40% of firms, with a third skipping software purchases to build in-house — but governance trails.
Enterprises are moving from experimenting with AI agents to running them in production — but they are deploying autonomy faster than they are building the discipline to govern it. That is the central finding of McKinsey’s State of AI 2026 survey, the consultancy’s annual global read on how organizations are adopting artificial intelligence. This year’s edition is framed explicitly around the shift into what McKinsey calls the agentic era, and it paints a picture of uneven, accelerating adoption shadowed by a widening governance gap.
Agent adoption is climbing fast — for large firms
The headline number is the jump in agent deployment. The share of organizations scaling AI agents in one or more business functions rose from 27% to 40% over the survey period. Broaden the lens and the funnel gets wider still: 62% of organizations report at least experimenting with agents, and 23% say they are scaling agentic systems somewhere in the business.
But the growth is concentrated. Adoption among smaller organizations stayed essentially flat at 22%, opening a gap between large enterprises with the resources to build and govern agent fleets and smaller firms still stuck at the pilot stage. McKinsey also cautions against reading “scaling in one function” as blanket transformation: in any single business function, no more than 10% of organizations report scaling agents. The enterprise-wide agentic company remains rare; what is spreading is targeted deployment in a few high-value areas.
Those areas are consistent. Respondents most often report scaling agents in IT, knowledge management, and software engineering — functions where the work is text- and code-heavy, the outputs are verifiable, and the return on automation is easiest to measure.
Agents are starting to reshape tech budgets
One finding cuts deeper than adoption rates. Nearly a third of organizations report deciding against buying at least one software product or feature because they could now build it in-house using agentic coding tools. That is an early but potentially significant signal that AI is beginning to redraw the classic build-versus-buy calculation that has underpinned the software industry for decades.
If the trend holds, it pressures the middle of the SaaS market most acutely: point solutions and single-feature products that a capable engineering team, armed with coding assistants, can now replicate internally in days rather than quarters. The economics that made it cheaper to buy than build are shifting as the cost of building collapses.
The governance gap
For all the deployment momentum, McKinsey’s companion AI Trust Maturity work flags a sobering counterpoint: only about a third of organizations report maturity levels of three or higher (on the survey’s scale) in strategy, governance, and agentic AI governance specifically. In plain terms, most companies putting agents into production have not built the corresponding controls — the guardrails, monitoring, escalation paths, and accountability structures — that autonomous systems demand.
This is the report’s core tension. An agent that can act across workflows, call tools, move data, and make decisions on a user’s behalf carries a fundamentally different risk profile than a chatbot that only answers questions. It needs scoped permissions, audit trails, and a clear owner. Yet the survey suggests the rush to capture agent productivity is outpacing the far less glamorous work of governing it — a gap that tends to stay invisible until something goes wrong.
Why this matters for the broader stack
The findings validate where much of the industry’s product energy has gone. The move toward agents has driven a wave of infrastructure work: standards for how agents identify themselves and interoperate, like the enterprise agent standards now emerging; authentication and access control for agent-to-tool connections, such as managed MCP authorization; and architectural questions about how agents remember context across long-running tasks. McKinsey’s data explains the urgency: the customers are real, the deployments are scaling, and the governance layer is where the market is most underbuilt.
It also lands against a backdrop of intensifying capability. Vendors are shipping models tuned explicitly for agentic, long-horizon work — Anthropic’s recent Fable 5.1 and Mythos 5.1 releases cut cache-read costs sharply to make persistent, tool-heavy workloads cheaper to run at scale. As the cost of running agents falls, the adoption curve McKinsey charts is likely to steepen, and the governance gap is likely to widen before it closes.
What it means
McKinsey’s survey confirms that the enterprise AI conversation has moved past “should we use it” to “how do we run it safely.” The 27%-to-40% jump is the clearest quantitative evidence yet that agents have crossed from pilot to production in a meaningful share of large organizations. This is no longer a demo-stage technology.
The winners are large enterprises with the engineering depth to build and govern agents, the model and infrastructure vendors selling into that demand, and the emerging category of tools that address the trust gap — observability, evaluation, permissioning, and governance platforms built specifically for autonomous systems. The losers are the SaaS vendors whose products are easiest to replace with an in-house agent, and smaller organizations at risk of falling further behind as the adoption gap compounds.
What to watch next: whether the governance layer catches up to deployment. Expect a surge of investment in agent oversight tooling, and expect the first high-profile agent failures — a bad autonomous action at scale — to accelerate it. The organizations that pair aggressive deployment with equally aggressive governance will pull ahead; the ones that treat governance as an afterthought are, per McKinsey’s own data, currently the majority.
Tagged
Keep reading
Chisato · · 6 min read ARD: Big Tech's Agent Standard vs Anthropic's MCP
ARD vs MCP: Big Tech's new agent-discovery standard takes aim at Anthropic's protocol. What ARD does, who backs it, and how the two actually differ.
Chisato · · 6 min read OpenAI Agents API: Codex Harness Now in Public Beta
OpenAI opened its Agents API in public beta on Sept 10, putting the managed Codex harness behind one API call. What it does, how sandboxes work, and pricing.
Chisato · · 5 min read Anthropic Enterprise Frontier Safeguards Explained
Anthropic unveiled Enterprise Frontier Safeguards, pairing zero data retention with misuse monitoring whose logs stay in the customer's own cloud. Here's what changes.