What strategic decisions matter when scaling agentic AI?

Build governance, portability, and cost control into AI
Home  // . //  //  What strategic decisions matter when scaling agentic AI?

Companies face several dilemmas as they try to strategically scale agentic AI and avoid higher costs and complications in the future. Some of the biggest dilemmas involve how much of the new agentic AI platform they should build, how much can be bought without getting locked into vendor proprietary systems, and how to deploy funding without buying too far ahead. The answers can make the difference between success and failure.

First, enterprises must remember that the model itself is rarely the culprit. The problem is more likely to be IT's approach to agentic. Too often enterprises treat incorporation of agentic as a procurement challenge, reducing its complexities to a master agreement and seat count. To scale successfully, agentic must be regarded as a transformation program. That forces enterprises to address potential risks and resources early across finance, legal, security, operations, human resources, and risk management, where the decisions with a long half-life sit.

The second issue is linked to how companies build their agentic layer. To scale agentic AI properly, technology leaders must address many questions, including whether key components of an agentic platform are present and whether they will be assembled in the proper order with sufficient internal corporate sponsorship. These questions are not always addressed or understood well enough. This is an issue because, in our experience, there is an optimal sequencing of a scale-up that delivers the best result.

Why agentic AI governance is lagging adoption

In July 2026, Oliver Wyman surveyed 70 CEOs and executive committee members and 130 CIOs and CTOs at large enterprises across Europe and North America. The findings revealed that many do not have a 360-degree view of their agentic AI programs or sufficient control over costs. For instance, only 10% of tech leaders could produce, on demand, the owner, scope, cost, and approver for every production agent. Among CIOs and CTOs running agents at scale, 54% had exceeded their AI budget ahead of plan. Bottom line: Platforms are being built faster than the accountability around them.

Dealing with vendors can be one of the trickier and stickier parts. For tech leaders, the most important decision is not which supplier to choose but, rather, which components of the agentic platform should be dependent on specific vendors and which need to stay portable.

Time horizons and information asymmetry impact that decision. A frontier model rebases roughly every six months, while an enterprise IT commitment remains active for three to five years. Suppliers can renegotiate what they deliver more frequently than ever, and will probably do it. IT departments need to factor in those likely changes and plan for them.

The four layers of an agentic AI platform

A working platform has four nested layers. First, the model is the statistical engine, blind to individual corporate policies, customers, and vocabulary. Second, the context is what you feed it per request. Third, the harness turns a model into an agent through memory, versioned skills, vetted tool access, an execution environment, and observability. Finally, the mesh makes a population governable through a registry, identity governance, shared observability, and cost accounting.

Since 2024, the center of gravity has lived in the harness, and upgrading the model rarely repairs what a weak harness breaks. Two constraints sit above the engineering: 6% of CIOs report governed, agent-ready data across most domains, and 58% hold only some attributes of their production agents.

Exhibi 1: Anatomy of an agentic platform — model, context, harness, mesh
Source: The Oliver Wyman 2026 Parallel Surveys on CEOs and Tech Leaders on Agentic AI and IT

How to avoid common mistakes when scaling agentic AI

The most expensive error an organization can make is starting with a mesh-first build — in other words, buying a governance platform before a single agent exists. The enterprise is stuck with a framework and nothing to govern.

Another significant and frequent mistake is harness sprawl, which is the case when every business unit builds its own execution environment, and no one holds a view of the entire landscape until the first incident or regulator letter. The best approach would be to build one harness around a workflow with measurable payback, expand to a small portfolio, then add the mesh once the agent population turns governance into a problem.

Six out of 10 of the CIOs and CTOs we surveyed at companies that had reached scale followed this sequence, while 27% bought governance before agents existed, and 8% let each team build its own. Yet only 21% have appointed a head of AI governance with cross-functional authority. Another danger is under-scoping a project. Getting early buy-in from CFOs and COOs can help ensure the scope reflects broader business requirements.

Three disciplines decide whether agentic AI can scale

Three disciplines are critical to operating agentic AI successfully at scale: deciding where workloads should run, governing agents as non-human identities, and planning for their eventual removal.

First, IT must decide where each agentic job should run, one job at a time. A premium can be paid for early access to the most advanced AI models, or a standard commercial service or open models on your own infrastructure can be used. Each decision represents a trade-off on power, costs, reliability, or continuity.

The reality is that outside providers reprice and deprecate on their own schedules, not necessarily based on their customers’ needs. But running models on your own only pays off with a large, steady volume.

Second, treat every production agent as a privileged non-human identity, giving each authentication credentials, a behavioral baseline, and a quarantine switch. Twenty-four percent of CIOs and CTOs capture the ratio of non-human to human identities, one-quarter reconstruct changes made by agents from a tamper-evident record, and 83% rely on human review of consequential outputs, which can end up capping scale.

Finally, organizations must budget for removal. Only 8% run a removal cadence with a named budget and owner. Without removal, scaffolding built for last year's model becomes this year's constraint.

Answering 10 questions can show whether an AI program is governable

A practical way to assess whether an agentic AI program is governable is to test it against 10 fundamental questions. Together, they examine whether an organization has clear accountability, appropriate controls, visibility into costs and value, a deliberate supplier strategy, and a plan for the workforce implications of agentic AI. The same questions should be asked at every approval gate as agents move from development to deployment and scale. Leaders should be able to answer:

  1. Who answers when an agent acts?
  2. How is each agent identified, audited, and revoked within minutes if needed?
  3. What can an agent see, and how does that boundary hold?
  4. What are the costs in steady state, and who owns that number?
  5. How is value measured against a baseline taken before deployment?
  6. What is the supplier strategy across the model and agentic platform?
  7. Which design decisions will need to be reversible?
  8. What is proprietary, and what is replaceable?
  9. Who owns the workforce transition?
  10. Who is most impacted by decisions made and should then have the biggest say?

Why agent memory creates vendor lock-in

As CIOs and CTOs choose vendors, they must keep in mind the level of dependency they are creating, especially when dealing with key elements like the operating model, context and data, memory, harness, and infrastructure. Prompts and evaluations tuned to one model can make migration an expensive and time-consuming engineering exercise, not just a pricing negotiation. Thus, it is important to avoid delegating too many key operations essential for the enterprise and IT function, or IT functions could find themselves locked into a vendor.

Embeddings also do not necessarily transfer between suppliers, and a fine-tune expires with its version. A strong framework abstraction imposes patterns your application code marries — and divorce can be expensive.

But this lock-in problem is particularly acute when it comes to memory, which is among the least discussed yet most consequential forms. While static context can be rebuilt from sources, the record of what an agent has done, learned, and been corrected on cannot. Twelve months of interaction history inside a supplier's managed memory is a non-portable book of business on someone else's ledger — and one that can take many engineering hours to reproduce.

Among programs at scale, 23% store most or all of that record in a neutral schema, and half estimate a model switch at 21 to 60 engineer-days. At board level, 46% of CEOs place supplier concentration on the risk register, while 53% discuss it without registering it.

Six questions to assess agentic AI vendor risk

There are some real possibilities CIOs and CTOs must consider when establishing relationships with suppliers, including whether a supplier will reprice services or retire a version.
Because these dependencies can be difficult to unwind, CIOs and CTOs should test the portability and financial implications of vendor decisions before committing. Six questions can help expose the trade-offs and dependency risks:

  1. How many engineer-days would a move off a primary model take, and when did IT last test one?
  2. If the organization changed its embeddings supplier tomorrow, what would have to be re-indexed, at what cost, and over what timeline?
  3. Is the organization’s harness decoupled from its model supplier?
  4. Has the organization adopted an open protocol for the agent-tool interface, with a version and a live connector count?
  5. If a supplier raised prices by 50%, what is the P&L impact, and which options are already exercisable?
  6. What share of agent-interaction memory can be read and replayed outside the current supplier's stack?
Exhibit 2: Manage vendor lock-in on two fronts
The harness protects your proprietary know-how, the LLM model controls the cost

How operating models drive value from agentic AI

Asked where advantage will hold as frontier models converge and prices fall, nearly three-quarters of CEOs point to reengineered processes and the operating model. Sixty-four percent suggested proprietary data and customer context. Only 4% expect it from privileged access to a leading model or vendor.

When it came to biggest fears, 30% named a security breach or loss of control, another 27% chose a high-profile failure or incident, 14% checked spending heavily with no return, and 4% picked faster competitors. Only 3% are very confident they could stand behind what an autonomous system did on their behalf.

The companies that create lasting advantage from agentic AI will be those that combine the right architecture with clear governance, portability, and operating-model discipline. As models converge, the differentiator will be less about access to technology and more about how effectively organizations embed it into the way they work.