‘If the foundation’s not functioning well, and you layer AI on top of it, you are not making things any better’
Artificial intelligence (AI) agent errors are already causing control failures, unintended actions and customer-facing problems, according to a recent survey that tracks what happens once agents are authorized to act in an environment that’s not designed for them.
Overall, 34% of organizations had acted on an inaccurate agent decision or output, reports Optro. Among organizations deploying agents:
-
30% had seen an agent take an unintended action
-
25% had experienced a control failure involving an agent
-
24% reported customer-facing impact
-
20% had two agents conflict
The errors largely trace to flawed data and workflows that were never redesigned for agents. Respondents named data quality and availability as the top missing prerequisite, at 36%, and 43% had added agents to existing workflows without changing them, Optro found.
“Enterprise AI agents are now embedded directly into workflows with real business, compliance, and regulatory consequences,” says Guru Sethupathy, general manager of AI governance at Optro.
Optro surveyed 417 governance, risk and compliance (GRC) and audit leaders at organizations with 250 or more employees in North America and Europe. Canadians made up 25% of respondents.
The hidden cost of AI agent errors
The errors happen as agents now hold real authority, according to the report:
-
38% of organizations let agents approve or reject transactions or requests
-
34% let them modify controls or policies
-
and 27% let them change user permissions or access rights
And the problems often surface late: among organizations with an agentic AI initiative that failed to deliver, 28% discovered the failure only after it had caused downstream impact.
The errors also create work. Some 46% of respondents said staff spend more time reviewing, validating or correcting AI outputs, and 47% reported new AI-related responsibilities. That echoes a previous survey on costly AI errors made by workers, where most managers reported extra time spent redoing AI-affected work.
How do flawed agent decisions slip through?
Failure to redesign work before using AI is causing the problem, according to the report.
“If the foundation’s not functioning well, and it’s still kind of broken, and you layer AI on top of it, you are not making things any better,” says an unnamed information security leader at a retail organization cited by Optro.
Also, human checks often lack substance. While 98% of respondents said reviewers can stop or override an agent, only 64% of organizations Optro classes as “moving fast” said reviewers have enough time to evaluate agent actions properly.
“I think we have to use that judiciously... once you get fatigued as a consequence of too much authorization and approving clicks, people just click without thinking about it. The control efficacy is lost forever once you get to that point,” said an information security risk leader at a consumer goods organization.
What should employers do about AI agent errors?
Regulators are watching. Three-quarters of GRC leaders said regulators or external auditors already ask about AI agent use.
Canadian employers have seen similar warnings in an Ontario audit that exposed gaps in public service AI governance and a previous report on governing autonomous AI agents.
Optro recommends:
-
designing workflows around the roles of people and agents
-
defining where human judgment is required and giving reviewers time and context to use it
-
and measuring whether agents produce the intended business outcome rather than speed and cost alone
Here are other things employers can do to address this issue, according to different sources:
|
# |
Action item |
What employers and HR should do |
Supporting data |
Source |
|
1 |
Keep an inventory of every agent and its permissions |
Register each agent with a named owner, a defined scope and access rights limited to its task. Review the inventory regularly so unsanctioned agents touching employee data are found and shut down. |
Info-Tech’s report holds that AI agents cannot be governed like traditional software or human staff because they act autonomously across systems. Separately, Strata Identity 2026 data show that 15% of employees run unauthorized “shadow agents”. |
Info-Tech Research Group, Govern Enterprise AI Agents While Preserving Innovation, and Strata Identity, both as reported by HRD Canada |
|
2 |
Train reviewers to check outputs, not just use tools |
Build AI literacy training that teaches staff how to spot and question flawed outputs. Give reviewers enough time and context to evaluate agent actions so approvals don’t become rubber stamps. |
Among Canadian respondents, 55% have relied on AI outputs at work without evaluating the information, and less than a quarter (24%) of Canadian respondents say they have received training in AI. |
KPMG International and University of Melbourne, Trust, attitudes and use of AI: A global study 2025 – Canadian insights |
|
3 |
Put verification rules in writing |
Adopt a written policy that says when AI output must be verified, by whom, and who owns the final result. Clear rules also protect employees who might otherwise carry the blame for an AI error. |
65% of workers who use AI on the job do not always verify an AI answer before acting on it, and only 22 percent of respondents said their employer has a written policy requiring AI output to be verified before it goes into work product. |
Kolmogorov Law, survey of 500 U.S. workers, 2026, via PR Newswire |
|
4 |
Deploy agents only where value is clear and controls are in place |
Set measurable business outcomes for each agent, not just speed and cost targets. Pause or retire agents that cannot show results or that lack adequate risk controls. |
Over 40% of agentic AI projects will be canceled by the end of 2027, due to escalating costs, unclear business value or inadequate risk controls, and Gartner recommends agentic AI only be pursued where it delivers clear value or ROI. |
Gartner, press release, June 25, 2025 |