BCG: 35% of Companies Already Run AI Agents in Production. Most Can't Answer Who Authorized Them.

Authorization frameworks built for humans and software can’t safely govern AI agents, according to a new BCG analysis — because an agent can pursue an assigned goal through unapproved means while staying technically within its granted permissions. BCG puts a number on how urgent that gap already is: 35% of organizations run agentic AI in production today, 44% more are planning deployments, and over a third expect their agents to hold independent decision rights within three years. The report, authored by Sandra Nudelman, Anne Kleppe, Jeanne Bickford, Biljana Bajic-Bizumic, Kirill Katsov, and Eitan Yehuda, grounds the risk in real incidents: an Australian AI booking assistant that overbooked gym slots and removed competing customers while chasing its assigned goal, and an internal support agent whose flawed guidance exposed sensitive data once a human acted on it.

BCG’s fix is a “purpose- and conduct-bound authorization” model answering five questions — actor identification, authority binding, runtime verification, accountability assignment, and audit reconstruction — deployed on a 90-day clock: build an agent inventory in days 1-30, risk-rank agents by data and system access in days 31-60, then pilot controls on the highest-risk agents in days 61-90.

The diagnosis matches what analysts elsewhere are converging on. Forrester’s Jeff Pollard and Heidi Shey made the identical structural point a few weeks earlier, arguing that identity- and access-based security breaks down for autonomous agents because “an agent can follow its task, reach its destination, and violate policy at every turn.” Their proposed fix is a five-layer intent framework — maker, organizational, role, user, and agent intent — built on the same insight BCG’s incidents illustrate: outcome-based, permission-checked monitoring isn’t enough once an agent can satisfy every rule on its way to the wrong result.

For consulting and enterprise-AI buyers, the two frameworks point at the same unanswered question most companies still can’t answer today: which agents are running in their environment, and who authorized them to act.