International Organisation

Putting agentic AI systems to work: What practitioners reveal about deployment and governance

Disclaimer: The opinions expressed and arguments employed herein are solely those of the authors and do not necessarily reflect the official views of the OECD, the GPAI or their member countries.

Somewhere in a codebase, AI agents are continuously scanning for security flaws, rewriting buggy code, and supporting incident response actions. Somewhere in a government department, another AI agent is sorting incoming correspondence, determining which legal provisions apply to a query, help make planning and permitting processes more efficient.

These are real-world examples of how organisations are already putting agentic AI to work. Agentic AI generally refers to systems composed of multiple co-ordinated AI agents that can break down tasks, collaborate, and pursue complex objectives autonomously over extended periods with limited human oversight. They are attracting growing attention as organisations explore how these systems can unlock new opportunities for innovation and productivity.

But how are different organisations using agentic AI in practice? What are these early applications revealing about the distinctive capabilities of these new AI systems? And what governance approaches are they adopting to manage these systems responsibly? To explore these questions, we spoke with practitioners in 25 organisations across 11 countries, including frontier developers, enterprise deployers, public sector organisations and academic institutions to examine practical implementations as well as perceived benefits and challenges of agentic AI systems.

The resulting OECD working paper, Agentic AI in organisations: Early insights from practitioner interviews examines how agentic AI systems are being developed and deployed in real-world contexts. Building on The Agentic AI Landscape and Its Conceptual Foundations, which examined how AI agents and agentic AI are defined across the literature, the paper offers an illustrative snapshot of how organisations are currently deploying agentic AI systems in practice and what they are learning in the process.

Here are some of the lessons emerging from those conversations.

Deployment of agentic AI is expanding, while autonomy remains carefully managed

Agentic AI is rapidly moving beyond pilot-stage projects and becoming integrated into organisational workflows. Figure 1 shows AI model usage generated by agentic systems has grown rapidly and now accounts for an increasing share of overall activity. Adoption spans organisations of different sizes and sectors. Interviewees reported its use in enterprise productivity, software development, cybersecurity, infrastructure and network capacity planning, scientific discovery, and public administration.

At the same time, none of the participating organisations reported deploying agentic AI with unrestricted autonomy. In the near-term, deployment is concentrated where tasks are structured enough, outcomes can be validated and the costs of errors are bounded or reversible. Many organisations use checkpoints, allowing AI agents to carry out tasks autonomously up to predefined points where human review or approval is required before proceeding, particularly for high-impact or irreversible actions. A key challenge remains determining where autonomy can safely be introduced and where human confirmation remains essential.

Adoption is uneven, and the maturity of agentic AI deployments varies considerably across organisations. Differences in technical readiness, risk tolerance and organisational priorities all shape how deeply agentic AI is integrated into operations.

Figure 1

Agentic AI introduces governance challenges as AI systems move from recommendation to action

Some of the challenges associated with agentic AI are familiar from generative AI, and specifically large language models (LLMs), but they can be amplified when systems are designed to act on outputs rather than simply support human decisions. Agentic AI systems may behave differently across contexts and from one “run” to another, and remain susceptible to hallucinations, incorrect tool use and other unintended actions. These difficulties become more pronounced in multi-agent and cross-organisational settings, where interactions among agents, enterprise systems and external tools increase complexity, reduce predictability and make failures harder to identify and trace to their source with resulting challenges for accountability.

Governance responses are emerging, and organisations are keen to learn from one another

Rather than starting from scratch, many organisations are addressing challenges associated with agentic AI largely within existing AI governance frameworks, including the OECD AI Principles, the NIST AI Risk Management Framework, ISO/IEC 42001, and where applicable, the EU AI Act.

Organisations are also finding that no single safeguard is sufficient. Instead, they are adopting layered approaches that combine calibrated human oversight, domain expertise embedded in system design, and technical controls such as sandbox testing, least-privilege access, continuous monitoring and registries of approved agents.

At the same time, several governance challenges remain unresolved:

  • System-level evaluation and assurance: There is currently no widely accepted standard for evaluating agent behaviour across extended action sequences, such as planning quality, the ordering of tool calls and determining when agents should seek human input.  
  • Traceability and accountability: Traceability can become more difficult in multi-step, multi-agent workflows. Assigning responsibility is also more complex when agents operate across organisational boundaries. Existing identity and access management frameworks were designed primarily for human users and may not adequately address agent-based interactions. 
  • Cybersecurity: As demonstrated by the recent incident involving OpenAI agents and the Hugging Face platform, agentic AI systems introduce new attack surfaces and risks, such as multi-agent collusion, agent hijacking, credential theft, and data leakage.

Many interviewees also argued that the mode of governance itself may need to evolve, shifting from static controls towards more dynamic and distributed oversight throughout the AI system lifecycle. Interviews surfaced the need to monitor and assess not only the outcomes, but also the intermediary agent actions towards achieving a goal.

Given these challenges, peer learning emerged as a recurring theme. Almost all participants underlined the importance of sustained dialogue on the implications of agentic AI and expressed strong interest in sharing implementation experiences and learning from peers as they navigate agentic deployments.

Toward safe, secure and trustworthy agentic AI systems

The experiences shared by these practitioners ground the agentic AI discussion in operational experience, offering a snapshot of how organisations are already deploying these systems and governing them in practice. Expanding the evidence base through broader sectoral and geographic coverage would help deepen understanding of emerging trends, challenges and good practice. Further work would also be important to understand the implications for  businesses, employees, and society more broadly, as well as evolving questions around governance, accountability and interoperability as systems become increasingly capable. As organisations continue to expand what agentic AI is trusted to do, governance approaches will need to evolve in tandem to enable the deployment of safe, secure and trustworthy AI systems.


Read the full report: https://www.oecd.org/en/publications/agentic-ai-in-organisations_1257a26f-en.html



Disclaimer: The Organisation cannot be held responsible for possible violations of copyright resulting from the posting of any written material on this website/blog.