Enterprise adoption is moving faster than enterprise confidence. A new Forrester Consulting study commissioned by Boomi found that 86% of surveyed organizations had moved beyond the AI-agent pilot stage, yet only 34% of leaders trusted the actions their agents were taking. The gap is not solved by buying a smarter model. It is closed by improving the data, context, permissions, and measurement system around the agent.
The trust gap is bigger than the pilot gap
The Boomi study surveyed 409 director-level and above technology decision-makers across North America, Europe, and Asia-Pacific. Fifty-eight percent said their organizations were moving from pilot to production, and another 28% reported agents already in production. Only about one-third, however, said they trusted agent actions and decisions.
Those figures should not be treated as a universal adoption census. Survey definitions and samples differ: Stanford’s 2026 AI Index reports broad organizational AI adoption at 88% while noting that agent deployment remains early across many business functions. The consistent message is more useful than any single percentage—experimentation and adoption are advancing faster than operating confidence.
Why agent trust starts with governed data
Agents do more than retrieve information. They interpret context, join facts across systems, choose a next step, and sometimes take action. If a customer status is stale, two dashboards define the same metric differently, or a policy document lacks an effective date, the agent can make a coherent decision from an incoherent foundation.
Trust therefore begins upstream: known owners, authoritative sources, quality rules, freshness expectations, lineage, retention, and access controls. The agent should know which source wins when records conflict and what to do when required evidence is missing. In high-risk workflows, the safest answer may be to pause and escalate.
A semantic layer becomes safety infrastructure
Human analysts often carry business meaning in their heads: what counts as an active member, which date closes a reporting period, why one status overrides another, or when a metric excludes an exception. Agents need that meaning expressed through governed definitions, metadata, rules, and examples.
This is where analytics teams become central to agentic AI. A shared semantic layer reduces the chance that an agent invents a join or misreads a measure. Identity-aware access prevents it from retrieving data the user could not see directly. Versioned definitions and lineage make the agent’s decision explainable after the fact.
The scorecard analytics teams should own
A useful trust scorecard measures more than final-answer accuracy. It should track source freshness, retrieval precision, unsupported-claim rate, tool-selection accuracy, parameter errors, policy violations, human overrides, rework, escalation quality, and the business outcome produced. Each failure should be classified as a model, instruction, tool, data, permission, or workflow problem.
That classification prevents every miss from becoming a prompt rewrite. NIST’s AI Risk Management Framework organizes the work around governing, mapping, measuring, and managing risk. Applied to agents, that means clear ownership, pre-deployment tests, monitored production behavior, and an improvement loop grounded in real exceptions. Trust is not a feeling added at launch; it is an operating result built from evidence.
02