Gartner forecasts that over 40% of agentic AI projects will be canceled by the end of 2027 because of escalating costs, unclear business value, or inadequate risk controls. So how do we put together an Agentic Roadmap?
The Gartner forecast needs to be unpacked, not met with knee-jerk reactions that cancel a bunch of projects. Business value, of course, is the number one evaluation criterion. If there is no value, there is no point in agent washing for the sake of agent washing.
Of the remaining two concerns Gartner identified, cost is a significant factor, and I will address that in another brief. For this brief, let’s assume that cost can be reviewed and reduced if an agent offers high business value.
Classification Of Agentic Risks
Let’s consider risk controls now. Agentic risk control does not mean we have to stall all agentic deployment until we put in place excruciatingly burdensome controls to mitigate risks posed by agents running around the company doing things.
Consider the following two things when reviewing agentic risk. Credential theft from an agent can turn it into an insider threat. Or an agent’s actions can cause financial, legal, or reputational damage to the company.
Governance for securing agents is fairly understood. If AI agents use broad, static, long-lived credentials for cross-environment access to databases, APIs, and SaaS tools, attackers will target credential theft. This turns a hijacked agent into an insider threat. So governance starts with compartmentalizing credentials per agent and securing access to agents.
Governance to lower the damage from an agent’s action should consider what Jeff Bezos wrote in Amazon’s 2015 letter to shareholders about decisions. He wrote that most decisions are two-way doors — walk through, see something you don’t like, walk back out, and no real damage is done. Spending weeks deliberating over those doesn’t make sense. A handful of decisions are one-way doors. No walking back, so they earn the full weight of judgment. You can take a similar approach here. Identify if the risk is a two-way or one-way door. All one-way door risks need a human in the loop before final action. The two-way risks are those in which the agent can take autonomous action.
A Roadmapping Framework
Ask your team to map all agentic projects into the simple grid shown below. You can quickly discern which projects to cancel, which to move forward with, and under what conditions.
What’s at Stake
Of the 40% of agent deployments Gartner expects to stop by 2027, many will be because nobody decided in advance which mistakes/risks were two-way doors and which weren’t, and found out the hard way which was which. Deploying agents that deliver great business value has benefits, so don’t slow your agentic deployment. Instead, conduct a disciplined review, as discussed above, and finalize your agentic roadmap.


