TLDRocket
Sign in

AI agents are spreading fast. Their rules are still catching up.

The New Stack Amanda Caswell Covered by 5 sources

AI agents are already in most of these big companies, but only a few people think the rules are clear. That gap matters because agents can touch real systems and data, not just write text.

Based on reporting by The New Stack, Amanda Caswell — read the original for the full story.

Summary, retelling and take written by AI under human oversight; images are AI-generated illustrations. How we work · Report an error

AI agents are moving into enterprises faster than the playbook around them. In an IDC survey released Tuesday, 86% of respondents said they already use agents embedded in applications, but only 12% said the risks tied to sovereign AI are widely understood inside their organizations.

That matters because these systems are no longer just chatbots with a nicer name. They can reach into company data, call tools, and act inside other applications. Cohere, which commissioned the survey, says the real headache is observability and guardrails: who can see what, who can touch sensitive data, and who can tell what an agent actually did.

IDC’s sample was built from 508 IT and business decision-makers at organizations with more than $1 billion in annual revenue across the U.S., Canada, the U.K. and Germany. They came from healthcare, financial services, the public sector, energy, manufacturing, and telecommunications. Nearly everyone in the group used generative AI. But only 13% said sovereign AI concepts were widely or very widely understood across their organizations, and one in three said they had trouble explaining sovereign AI in their own words.

Cohere’s answer is to push control down into the stack. The company says its full platform, including its models, retrieval-augmented generation and North’s agents and tool use, can run on customer infrastructure with no external connection, including air-gapped and classified environments. Licensing is offline, updates arrive as signed packages, and the customer decides what gets in and when.

That control comes with more work. In the survey, infrastructure was the biggest barrier to sovereign AI readiness at 17%, with cost and budget at 10% and skills and talent at 9%. And the responsibility is already landing somewhere: 420 of the 508 organizations said someone is accountable for sovereign AI, but only 8% said that role was well-defined, and just 0.4% said it was fully formalized and governed.

My take — AI-written commentary, not fact-checked reporting

Enterprise AI is still being sold like a magic trick while the boring bits — access, audit trails, deployment control — do the real work. That’s why sovereign AI keeps showing up in these conversations: not because it sounds elegant, but because lock-in with a friendly logo is still lock-in. The industry keeps shipping agents first and paperwork later, which is a fine way to create a future compliance headache with a nicer UI.

Read more about this at: The New Stack

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads all relevant sources, removes duplicate coverage, and summarises the day in two minutes. Follow companies and topics for alerts, or get the briefing in Slack. Free, no spam, unsubscribe anytime.