Sixty-nine percent of organizations are planning to implement agentic AI use, according to anMIT/Google Cloud report. Despite this, there still compliance and regulation concerns, as well as challenges with the data AI is trained on.
Dave Schubmehlis a research vice president at IDC. He specializes in AI and automation research, covering predictive, prescriptive, generative and agentic AI. He was previously VP of product strategy at Janya. In this interview, Schubmehl sat down with No Jitter to discuss agentic AI in the enterprise.
No Jitter: What does “decision debt” mean in operational terms?
Schubmehl:Decision debt refers to the accumulation of ungoverned or poorly governed decisions made by autonomous agents, resulting in a compounding risk surface as agent populations scale, analogous to technical debt, but for decision-making authority and accountability.
No Jitter: Where do organizations most often underestimate agentic risk?
Schubmehl:Organizations most often underestimate agentic risk in the governance of non-human identities (NHIs), where agents dynamically acquire permissions, spawn subagents, and act autonomously, leading to a significant gap between perceived and actual policy enforcement, especially as agent populations outpace governance controls.
No Jitter: How should organizations test agents for risks before production?
Schubmehl:Organizations should conduct pre-deployment testing that includes red teaming for prompt injection and adversarial attacks, baseline and stress testing across connected environments, validation of reversible controls (kill, clamp, rollback), and the requirement of audit trail completeness and real-time monitoring instrumentation before agents go live.
No Jitter: What signals should companies look for to prevent issues with agentic AI?
Schubmehl:Key signals include anomalous agent behavior, unexplained permission escalations, cost or token consumption spikes, drift in model or agent performance, incomplete or missing audit logs, and breakdowns in human-in-the-loop or escalation mechanisms—each of which indicates potential governance, security, or operational failures that require immediate attention.
