← All posts AI Governance

Your AI Agent Doesn't Just Say Wrong Things — It Does Wrong Things

Quick answer

McKinsey's 2026 trust report found only 30% of firms have proper AI governance for agentic systems. This article explains what changes when AI agents can take actions, not just answer questions, and what UK SMEs should put in place before letting agents near live systems.

McKinsey's latest trust report found only 30% of firms have proper AI governance for agentic systems. Here's what changes when AI agents can take actions, not just answer questions.

By Matty Hatton·3 August 2026·4 min read
3 August 2026 AI Agents AI Governance

I've been talking to a few UK SMEs lately who are all excited about AI agents. They've seen the demos. An agent that reads your inbox, drafts replies, updates the CRM, raises purchase orders. Sounds brilliant, doesn't it?

And it is brilliant — when it works. But here's the thing nobody tells you: a chatbot that gives a wrong answer is a support ticket. An AI agent that takes a wrong action against your live ERP is a proper incident.

That distinction matters more than you'd think.

What McKinsey found

McKinsey published their "State of AI Trust in 2026: Shifting to the Agentic Era" report in March. They surveyed around 500 organisations that have direct responsibility for AI governance, risk management, or investment decisions. The findings are eye-opening.

The report framed the shift perfectly: "In the age of agentic AI, organisations can no longer concern themselves only with AI systems saying the wrong thing; they must also contend with systems doing the wrong thing, such as taking unintended actions, misusing tools, or operating beyond appropriate guardrails."

That's not a hypothetical risk. Their survey found that 74% of respondents identified inaccuracy as a highly relevant risk, and 72% flagged cybersecurity. Nearly two-thirds said security and risk concerns are the top barrier to fully scaling agentic AI — way ahead of regulatory uncertainty or technical limitations.

And here's the kicker: only about 30% of organisations have reached higher maturity levels in AI strategy, governance, and agentic controls. That means 70% of firms playing with AI agents right now don't have proper guardrails in place.

Why this matters for UK SMEs

I see this all the time. A managing director sees a slick demo of an AI agent updating records and placing orders automatically. They think, "Sorted — that'll save us three admin heads." So they let someone wire it up to the live system.

Then the agent misreads a supplier name, creates a duplicate record in the ERP, sends the wrong product code to procurement, and nobody notices for two weeks because everyone trusted the automation.

That's not a technology failure. That's a governance failure. The agent did exactly what it was told — it just didn't have the right boundaries.

McKinsey's data backs this up. Only 23% of organisations are scaling agentic AI consistently. The other 77% are either experimenting or stuck. And Deloitte found that 56% of CEOs admit their AI investment hasn't produced revenue growth or cost savings in the past year.

What to actually do about it

You don't need a 200-page governance framework. You need three things, done properly:

  • Start read-only. Let your AI agents read data and make suggestions first. Don't give them write access to your ERP, CRM, or finance system until you've watched them for a while and trust the output. Read-only is your friend.
  • Put hard limits on what actions agents can take. Even when you do let them write back, restrict it. An agent that can only update a description field is manageable. An agent that can delete records or send emails to customers without sign-off is a ticking time bomb.
  • Fix your data first. Agents are only as good as the data they're reading. If your master data is a mess — duplicate suppliers, inconsistent part numbers, missing addresses — your agent will confidently make wrong decisions at speed. Sort the foundations, then layer the AI on top.

This isn't about being scared of AI. It's about being sensible. The firms getting real value from AI agents aren't the ones who moved fastest. They're the ones who put the right boundaries in place first, then let the agents loose within those boundaries.

If you're thinking about putting AI agents into your live systems and you're not sure your data or governance is ready, that's the first conversation to have. Before something goes wrong, not after.

References & Further Reading

  1. McKinsey, State of AI Trust in 2026: Shifting to the Agentic Era (March 2026)
  2. Deloitte, CEO Survey: AI Investment Returns (2026)
  3. Gartner, 40% of Agentic AI Projects Will Be Cancelled by 2027
  4. Anthropic, Building Effective AI Agents

Thinking about AI agents for your business?

I help UK SMEs get their data foundations right before layering AI on top. Governance, data quality, the lot. Because an agent built on dodgy data is worse than no agent at all.

Let's have a chat

Matty Hatton is the founder of Digital Adaption, an ERP and data consultancy based on the Wirral. He has spent 15 years delivering ERP transformations for manufacturers, including leading the data migration on a £4.5m consolidation of four legacy systems onto a single Infor LN cloud instance for a 220-user group. He holds an MSc in Digital Transformation and IT Strategy from Manchester Metropolitan University and is Microsoft PL-200 certified.

LinkedIn | Get in touch

Start with a 30-minute data risk call
Got a version of this problem?

Start with a 30-minute data risk call.