
Nobody Decided to Trust the Agent

Companies spent $2.5 trillion making AI powerful and almost nothing knowing when it breaks. That gap is not a budget line. It is a decision nobody made.
TL;DR
Enterprises are projected to spend about $2.5 trillion on AI in 2026 and roughly one dollar on trust and safety for every $735 of capability. Most leaders who report confidence in their AI readiness have already had to roll an agent back. The common cause is not weak models or thin budgets. It is that the choice to let an AI system act on its own is rarely made deliberately: trust accrues by default, ownership stays unclear, and the failure surfaces in front of a customer. What follows is the 2026 data and the one question worth asking about every agent in production.
How the Trust Crept In
The last couple of years I keep ending up in the same conversation, across seven scaling product organizations now, and it always opens the same way. A team pulls up a demo. The agent takes a real customer case, a gnarly one, and handles it clean. Somebody in the room, usually the most senior person there, leans back and says some version of we are ahead of the curve on this. Everybody wants that to be true. So it becomes true. The agent ships.
Nobody in that room decided to trust it. That is the part that took me a while to see. There was no moment where a person said out loud, we are handing this kind of judgment to a machine, here is what we accept in exchange, here is who owns it when it goes wrong. The trust just crept in. Week one the agent handled the easy tickets. Week six it was quietly deciding refunds. Week twenty it was making calls no one in that first room would have signed off on, and nobody could tell you when that line got crossed, because it was never a line. It was a slope. The first time I watched an agent start approving refunds on its own, I'm like, wait, who set that scope, and the room went quiet, because the honest answer was no one did. It grew.
Noise Is Cheap. Judgment Is Not.
The AI deployment-trust gap is the distance between how much autonomy an AI system has been granted in practice and how deliberately anyone decided to grant it. Here is the frame I keep coming back to, and it is the whole thing. A machine is built to do the noise. It answers, it drafts, it routes, it resolves, at a volume and speed no person can touch. That is not a knock. That is the point. That is what you are paying for. Judgment is the other thing. Judgment is knowing whether the answer is actually right. Whether this is the case you let it close on its own, or the one you pull into a room. When to stop. Judgment is scarce, it does not scale, and it is supposed to stay with a person. Right?
What broke in 2026 is that the machine got so fluent at the noise that the fluency started standing in for judgment nobody applied. The agent sounds certain. It is fast. It is right often enough that checking it starts to feel like friction. So the checking quietly stops, and the judgment that was supposed to live with a person leaks into a system that cannot do judgment at all, only a very convincing imitation of it. It never says I don't know. It never flags the one case that should have scared you. It just keeps going, competent and tireless, and competent and tireless is exactly what makes it dangerous. I used to think the real risk in all this was the models, that they would hallucinate or drift or get jailbroken. That is real, but it is not the thing. The thing is that we let confident output stand in for a decision, and then acted surprised that the decision was never actually made.
One Dollar of Safety for Every $735
Look at where the money went, because the money already tells you nobody decided. Gartner expects the world to spend about $2.5 trillion on AI this year. Against that, TELUS Digital's GenAI safety benchmark, reported by CX Today, puts total enterprise spending on AI trust, risk, and safety at $3.43 billion. That works out to about one dollar of safety for every $735 of capability. No executive team sat down and chose a 735-to-1 ratio. Nobody would defend that number out loud in a board meeting. It exists because it is the sum of a few hundred small yeses, each of which felt like progress, none of which was the actual decision.

Confidence Is the Tell
Then there is the confidence, and the confidence is the tell. In Sinch's research on AI in production, ninety percent of leaders said they were confident in their organization's AI readiness. Of those confident leaders, seventy-five percent had already been forced to roll back or shut down an agent. Even inside the group that rated their own guardrails fully mature, eighty-one percent had pulled something back. The researchers said it plainly, that confidence had essentially no correlation with governance outcomes.
Sit with that for a second. The feeling of being ready and the fact of being ready have come apart completely. That is not what it feels like when you have actually decided something and built it to hold, where the confidence and the outcome move together. When confidence floats that far free of results, it means it is attached to nothing. People are sure about a call that was never made. And I understand how you get there. Nobody in the room is lying. They have no instrument that would tell them otherwise, so the absence of bad news reads as good news, right up until it doesn't.
The Missing Middle
Gartner names the mechanism about as well as anyone. It projects that forty percent of enterprises will demote or decommission their AI agents by 2027, and its analysts put the cause on binary thinking. Teams treat an agent as either locked all the way down or trusted all the way up, with nothing in between. Under pressure to show a return, most of them quietly pick trusted and call it enablement. The missing middle, the part where a person decides how much judgment this system actually gets, what it is allowed to do alone, and the condition under which you take it back, is exactly the part that got skipped. Not because it is hard to grasp. Because skipping it felt faster, and the noise was good enough that skipping it did not hurt for a while.

It Fails in Public
Here is what makes the AI version meaner than the usual one. When you skip that middle and the thing fails, it does not fail quietly on an internal dashboard where you can still catch it. It fails in a customer interaction, at machine speed, in front of the exact person you least wanted to see it. Eighty-six percent of organizations in the TELUS benchmark had already had an AI-related security incident. That is not a projection about next year. That is the current weather. The failure does not surface in your monitoring first. It surfaces in someone's inbox, or their account balance, or a screenshot that is already moving, and by the time it reaches you it is outside the building and it has your name on it.
That is the cost that never shows up in the AI line of the budget. Not the compute. The credibility. The judgment you are actually paid to hold, sitting inside a system that was never built to hold it, waiting to be wrong in public.
No Tool Fixes a Decision Nobody Made
The reflex, once this lands, is to go buy governance. A maturity model. A framework. A dashboard with a lot of green on it. I get the pull, because it turns a decision you never made into a purchase you can make this quarter. But no tool fixes a decision nobody made. You can wire an agent with monitoring end to end and still not be able to say who owns it, what you traded to run it, or what would make you switch it off. If those answers do not exist, the monitoring is just a better seat for watching the thing fail. Next quarter you roll it back, file it under bad luck, and the same slope starts again with the next agent.
The Question Worth Sitting With
So I am not going to hand you a governance checklist, because the checklist is not the missing piece. The missing piece is smaller and harder to sit with. Somewhere in your product right now there is a system making calls on its own, and the honest questions are these. Did anyone actually decide to trust it that far, or did we drift there. Can you name the person who owns it when it is wrong. And if it did something wrong in front of a customer right now, how long before you would know.
If the answers are no, not really, and a while, then the problem was never the model. The machine did exactly what it is built to do. It did the noise, and it did it beautifully, at a scale no team could match. The judgment was ours to keep. Somewhere along the way we let the noise stand in for it, and we called that being ahead of the curve. If you want to see where your own decisions sit before an agent forces the question, the Decision Durability Scorecard is a short read, from Fragile to Self-Healing.
Key takeaways
Worldwide AI spending is projected at about $2.5 trillion in 2026, while enterprise spending on AI trust and safety is roughly one dollar for every $735 of capability.
Confidence in AI readiness does not predict outcomes. A majority of leaders who report confidence have already rolled back or shut down an agent.
The common failure is undecided trust rather than weak models. Autonomy is often granted by default, with no named owner, no explicit trade-off, and no condition for turning the system off.
Governance tooling does not resolve an ungoverned decision. Monitoring an agent does not establish who owns it or what would trigger switching it off.
A practical readiness test is detection and ownership: how quickly a customer-facing error would be caught, and who would own the response.
Frequently asked questions about AI agent trust
What is the AI deployment-trust gap?
The AI deployment-trust gap is the distance between how much autonomy an AI system has been granted in practice and how deliberately that trust was decided. It commonly widens as an agent takes on more over time without a formal decision, a named owner, or a defined scope. The result is a system acting with authority no one explicitly assigned.
How much are companies spending on AI versus AI safety in 2026?
Gartner projects worldwide AI spending of about $2.5 trillion in 2026. TELUS Digital's GenAI safety benchmark puts enterprise spending on AI trust, risk, and safety at roughly $3.43 billion, which is about one dollar of safety for every $735 of capability.
Why do AI agents get rolled back even at confident, well-resourced companies?
Sinch's production research found ninety percent of leaders felt confident in their AI readiness, yet seventy-five percent of them had already rolled back or shut down an agent, and eighty-one percent of those with fully mature guardrails had done the same. Confidence tracked almost nothing about real outcomes, which usually indicates that the decision to trust the system was never made deliberately.
What does Gartner say causes AI agent failures?
Gartner projects forty percent of enterprises will demote or decommission agents by 2027 and identifies binary governance, treating an agent as either locked down or fully trusted, as the root cause. The missing middle is a deliberate decision about scope, ownership, and the conditions for turning the system off.
Does buying AI governance tooling prevent agent failures?
Tooling and monitoring improve visibility but do not establish who owns an agent, what was traded to run it, or what would trigger switching it off. Without those decisions, a well-instrumented agent still operates on undecided trust. Governance is a decision before it is a product.
What is the most useful question to ask about an AI agent in production?
If the agent did something wrong in a customer interaction right now, how long before anyone would know, and who owns the response. An inability to answer indicates the system is operating on trust that was never formally granted.
I help product leaders at complex product organizations unblock execution when their decision architecture starts breaking down, so that they can ship the roadmap they committed to without another quarter of explanation.
If this sounds familiar, you're not alone.
The work is not about moving faster. It is about preserving judgment as systems scale.
If you are navigating this right now, book a Relevance Check. We will walk through what you can move first.
No pitch. Just the read.
Clinton Pracher | CP Product Advisory

