McKinsey AI 2026 Trust Report on AI Agents

Everyone Is Deploying Agents. Almost No One Can Govern Them: Inside McKinsey’s 2026 AI Trust Report

TL;DR — McKinsey’s 2026 AI Trust Maturity Survey, published March 25, 2026, surveyed roughly 500 organizations and found a widening gap between what companies are deploying and what they can actually control. Average responsible-AI (RAI) maturity rose to 2.3 out of 4, up from 2.0 in 2025 — real progress. But only about 30% of organizations reach maturity level 3 or higher on the three dimensions that matter most for autonomous systems: strategy, governance, and the brand-new category of agentic AI governance. The technical capabilities that build AI are advancing roughly twice as fast as the oversight structures that govern it. Nearly two-thirds of respondents name security and risk concerns — not regulation or technical limits — as the top barrier to scaling agentic AI. Incident rates are flat at about 8%, but roughly 60% of organizations that had an incident are unhappy with how they responded. The core reframing McKinsey offers is the most useful sentence in the report: in the gen-AI era the risk was AI saying the wrong thing, which a human could catch before acting on it; in the agentic era the risk is AI doing the wrong thing, where the action has already happened. This guide walks through what the report actually found, why the saying-to-doing shift resets the governance problem, and the six moves McKinsey’s own data ties to higher maturity and realized value.

McKinsey surveyed ~500 organizations on AI trust. The gap between what companies deploy and what they can control is the whole story.

What the Report Is and Why It’s Credible

McKinsey’s 2026 AI Trust Maturity Survey was conducted between December 2025 and January 2026, gathering responses from approximately 500 organizations across industries and regions. Critically, the respondents weren’t random — they held direct responsibility or expertise in AI governance, risk management, or AI investment decisions. This is a survey of the people who actually own the problem, not a general business-sentiment poll.

Responses were scored against the McKinsey AI Trust Maturity Model, which assesses five dimensions of responsible AI: strategy, risk management, data and technology, governance, and — new this year — agentic AI governance and controls. That fifth dimension is the tell. McKinsey added an entire new category to its framework specifically because governing autonomous systems has become a distinct discipline from governing generative ones. Each dimension is scored across four maturity levels, from foundational practices to a comprehensive, proactive program.

The authors — Gabriel Morgan Asaftei, Roger Roberts, Abby Sticha, and Cécile Prinsen — sit across McKinsey’s New York, Bay Area, and London offices in the firm’s Digital and AI Trust practices. This is a flagship piece of research from the consultancy that most enterprise boards read, which is exactly why it’s worth engaging with critically rather than just citing.

The headline finding is deceptively simple: maturity is improving, but the parts of maturity that keep autonomous systems safe are the parts lagging furthest behind.


The Shift That Changes Everything: From Saying to Doing

The single most important idea in the report isn’t a statistic — it’s a reframing of what AI risk even is. McKinsey draws a clean line between two eras, and understanding it is the prerequisite for understanding why the governance gap is so dangerous right now.

McKinsey’s core framing: the risk moved from what AI says to what AI does — and the human safety net that made gen AI governable doesn’t exist by default for agents

The gen-AI era: the risk was what AI said. A model hallucinated a fact, produced biased output, or made a wrong recommendation. These failures are real, but they share a crucial property: they’re containable because a human reads the output before acting on it. The analyst who gets a hallucinated citation catches it before it reaches the client deck. The safety net is built into the workflow — a person stands between the AI’s output and any real-world consequence.

The agentic era: the risk is what AI does. In McKinsey’s words, organizations “can no longer concern themselves only with AI systems saying the wrong thing; they must also contend with systems doing the wrong thing, such as taking unintended actions, misusing tools, or operating beyond appropriate guardrails.” An agent doesn’t recommend issuing the refund — it issues the refund. It doesn’t suggest sending the email — it sends it. It doesn’t propose modifying the database record — it modifies it, then calls three downstream systems that act on the change.

Why this resets the governance problem entirely. The human-in-the-loop review that made generative AI governable is not present by default in agentic systems — that’s the entire point of agents. They act autonomously. When you remove the human from between the output and the consequence, every weakness in your controls becomes an operational exposure rather than a caught mistake. A poorly governed chatbot embarrasses you. A poorly governed agent transacts on your behalf.

This is why the report’s central tension matters so much. Companies are deploying systems whose failure mode is action, using governance structures designed for systems whose failure mode was speech. The tools haven’t caught up to the autonomy.


The Maturity Gap: Capabilities Race Ahead, Oversight Falls Behind

The clearest data point in the report is that the dimensions of AI maturity that build capability are roughly twice as mature as the dimensions that govern it.

Average RAI maturity rose to 2.3, but the dimensions that govern autonomy trail the ones that build it.

The average RAI maturity score rose to 2.3 in 2026, up from 2.0 in 2025. On a four-level scale, that’s genuine, measurable progress — organizations are getting better at responsible AI overall.

But the average hides the problem. Only about one-third of organizations reach maturity level 3 or higher in strategy, governance, and agentic AI governance. Meanwhile, data and technology and risk management — the dimensions concerned with building and running AI — score materially higher. McKinsey’s own framing: “while technical and risk management capabilities are advancing, organizational alignment and oversight structures are struggling to keep pace.”

Two patterns compound this:

The gap is globally consistent. McKinsey found that governance and agentic controls lag behind data and technology across all regions. Asia-Pacific leads overall maturity, and technology/media/telecom and financial services lead among industries — but even the leaders show the same shape: the build-it dimensions ahead of the govern-it dimensions. This isn’t a laggard problem; it’s a structural one.

Agentic governance is the newest and least mature dimension. Because McKinsey only added it this year, most organizations are starting close to zero. They’re deploying agents faster than they’re building the specific discipline required to govern them — reusing generative-AI controls for a fundamentally different risk profile.

The strategic read for tech leaders: if your organization has invested heavily in MLOps, model monitoring, and data infrastructure but treats governance as a policy document rather than an operational capability, you are the median organization in this survey. The capability to build agentic systems has outrun the capability to control them almost everywhere.


The Awareness-Action Gap: Companies Know the Risks They Aren’t Managing

One of the report’s most uncomfortable findings is that across nearly every risk category, awareness of a risk substantially outpaces active mitigation of it. Organizations can name the threats. They haven’t built the controls.

Across almost every risk category, awareness outpaces active mitigation — dangerously so for agents.

The numbers that define the gap:

74% cite inaccuracy and 72% cite cybersecurity as highly relevant risks. These remain the top two concerns even as newer agentic risks emerge — the foundational model risks didn’t disappear when agents arrived; they got a larger attack surface layered on top. (The cybersecurity concern is well-founded: research like Cornell’s WARP attack has shown how little it takes to poison the web content that AI agents retrieve and act on.)

Active mitigation lags awareness across almost every category, most sharply for intellectual-property infringement and personal privacy. McKinsey is direct: “risk awareness is outpacing the implementation of controls, processes, and tooling needed to manage it effectively.” Knowing a risk exists and having a control that catches it are different things, and most organizations are living in the gap between them.

The incident numbers tell the subtlest and most important story. The share of organizations reporting AI-related incidents held steady at roughly 8% — flat since 2025. On its face, that sounds reassuring: incidents aren’t rising. But look at the second number. Almost 60% of organizations that experienced an incident hold satisfactory-or-negative views of their own response. Incidents aren’t becoming more frequent, but organizations are becoming less confident they can handle them.

This is the honest nuance the headline coverage will miss, and it’s the most revealing finding in the report. A flat incident rate with declining response confidence means system complexity is growing faster than response capability. The organizations aren’t getting hit more often — they’re getting less sure they can manage the hit when it comes. For agentic systems, where an incident might be an agent taking a cascade of wrong actions across connected tools before anyone notices, that erosion of confidence is the warning signal that matters. The problem isn’t the frequency. It’s the preparedness.


Where the Value Is: What the Report Says About ROI

The report makes an argument tech leaders can take to a CFO: responsible AI investment is associated with realized financial value, not just risk reduction.

The standout finding: organizations investing $25 million or more into RAI initiatives report significantly higher maturity scores and are far more likely to realize material AI benefits — including EBIT impact above 5%. McKinsey’s framing is deliberately pointed: “RAI investment is not a tax on innovation but a key enabler of sustained value creation.”

The logic behind the correlation is the through-line of the whole report. Trust enables two outcomes simultaneously: it lets organizations realize value from AI by supporting sustained adoption and integration into core workflows, and it lets them manage an expanding risk landscape. The companies that can trust their agents deploy them more widely; the companies that can’t keep them stuck in pilots. If security concerns are the number-one barrier to scaling agentic AI — and two-thirds of respondents say they are — then the RAI capabilities that resolve those concerns are precisely what unlock scale.

There’s a natural skepticism worth naming: correlation isn’t causation, and this is a consulting firm whose AI Trust practice benefits directly from companies deciding to invest $25M in AI trust. Both things can be true. The $25M-to-EBIT link is a genuine pattern in the data and it’s a pattern McKinsey is commercially motivated to emphasize. A careful reader treats it as a strong signal about the direction of the relationship — trust capabilities and realized value travel together — without over-reading the precise dollar threshold as a magic number.

The tenth insight reinforces the shift: organizations increasingly view AI trust as a business enabler rather than a compliance exercise. McKinsey notes the perceived influence of some regulatory frameworks has actually declined, suggesting motivation is moving from “avoid fines” to “capture value.” That’s a meaningful change in why companies invest in this at all.


What Separates the Leaders: Six Moves

The most actionable part of the report is what McKinsey’s data ties to higher maturity and realized value. Six moves stand out.

The practices McKinsey’s data associates with higher maturity and realized value.

1. Assign explicit RAI ownership. This is the single biggest differentiator in the data. Organizations with a clearly accountable RAI function — an AI-specific governance role, or internal audit and ethics teams that own it — score an average maturity of 2.6. Those without clear accountability score just 1.8. That’s an enormous gap driven by a decision that costs nothing but organizational will: naming who owns it. Diffuse responsibility produces diffuse results.

2. Fund it like you mean it. The $25M+ investment tier correlates with both higher maturity and EBIT impact above 5%. You don’t have to spend exactly that much, but the direction is clear: underfunded RAI stays foundational, and foundational RAI can’t govern autonomous systems. Treat it as capability investment, not compliance overhead.

3. Close the knowledge gap first. Nearly 60% of respondents cite knowledge and training gaps as the primary barrier to implementing RAI — up from about 50% last year. Notably, executive support has improved while the training gap widened. That means leadership is bought in but the operational muscle isn’t there. The bottleneck has moved from the boardroom to the teams doing the work. Fix the skills before you scale the agents.

4. Govern agents as a distinct discipline. Agentic governance is a separate maturity dimension for a reason. The controls that made a chatbot safe — content filters, output review, human sign-off — don’t automatically make an autonomous agent safe. Agents need action-level controls: permission scoping, tool-use boundaries, transaction limits, audit logging of what the agent did, and kill switches. Reusing gen-AI governance for agents leaves the biggest gap in the report unmanaged.

5. Build response capability, not just awareness. With 60% of organizations unhappy with their incident response, the message is that knowing the risks isn’t enough — you need rehearsed capability. Define the kill switch before you need it. Run incident drills. Rehearse the rollback. Know who gets called when an agent goes wrong at 2 a.m. and what authority they have to stop it. Response capability is built in advance or not at all.

6. Treat trust as an enabler, not a compliance exercise. The organizations capturing value frame AI trust as a core business capability that accelerates adoption, not a checkbox that slows it down. This is a mindset shift with operational consequences: teams that see governance as an innovation enabler build it into the deployment process; teams that see it as compliance bolt it on afterward, where it’s both weaker and more resented.

McKinsey’s bottom line ties it together: AI trust “cannot be bought and installed.” It’s a combination of policies, processes, people, and technology built together over time — which is precisely why the organizations that start early will define who captures long-term value in the agentic era.


What This Means for Developers and Engineering Teams

The report is written for executives, but it has direct implications for the people actually building and shipping agentic systems.

Agentic governance is becoming an engineering requirement, not just a policy concern. The controls McKinsey describes — permission scoping, tool-use boundaries, audit logging, kill switches — are things engineers build, not things committees write. If your team is shipping agents, the governance gap in this report is partly your backlog. Action-level observability (logging what the agent did, not just what it said), retrieval provenance, and the ability to halt a running agent are engineering features that most codebases don’t have yet.

Verification and self-checking move from nice-to-have to core. Boris Cherny’s most durable advice about Claude Code — give the agent a way to verify its own work, worth 2-3x on quality — maps directly onto McKinsey’s governance concern. An agent that checks its own actions before committing them is both higher-quality and more governable. The same discipline that makes agents work well makes them safer.

The knowledge gap is an opportunity. With 60% of organizations citing training gaps as their top barrier, engineers who genuinely understand agentic governance — not just how to build agents, but how to build them safely and observably — are scarce and valuable. This is the same dynamic behind the Forward Deployed Engineer boom and the premium on “harness skill.” The market is short on people who can make autonomous systems trustworthy in production.

Cybersecurity is now inseparable from agent design. With 72% citing cybersecurity as a top risk and agents dramatically expanding the attack surface, secure-by-design is no longer a separate workstream. Every tool an agent can call is a capability an attacker might hijack; every piece of web content an agent retrieves is a potential injection vector. Building agents means building threat models for them.


Frequently Asked Questions

What is McKinsey’s 2026 AI Trust Maturity Survey?

It’s McKinsey’s flagship annual research on responsible AI, published March 25, 2026. It surveyed approximately 500 organizations between December 2025 and January 2026, drawing on respondents with direct responsibility for AI governance, risk management, or AI investment. Responses were scored against McKinsey’s AI Trust Maturity Model across five dimensions: strategy, risk management, data and technology, governance, and a new dimension for agentic AI governance and controls.

What is the main finding of the report?

That AI maturity is improving overall — the average score rose to 2.3 from 2.0 in 2025 — but the dimensions that govern autonomous systems (strategy, governance, and agentic AI governance) lag well behind the dimensions that build them. Only about 30% of organizations reach maturity level 3 or higher on those governance dimensions. Companies are deploying agents faster than they can govern them.

What is the “saying versus doing” shift?

It’s McKinsey’s core framing for how AI risk has changed. In the generative-AI era, the primary risk was AI saying the wrong thing — a hallucination or bad recommendation that a human could catch before acting on it. In the agentic era, the risk is AI doing the wrong thing — taking an unintended action, misusing a tool, or operating past its guardrails — where the action has already happened before anyone reviews it. The human safety net that made gen AI governable doesn’t exist by default for autonomous agents.

What is responsible AI (RAI)?

Responsible AI refers to the policies, processes, people, and technology that make AI systems trustworthy — spanning strategy, risk management, data and technology practices, governance, and now the governance of autonomous agents specifically. McKinsey measures RAI maturity on a four-level scale from foundational practices to a comprehensive, proactive program. The report stresses that RAI “cannot be bought and installed” — it’s built over time.

Why is security the top barrier to scaling agentic AI?

Nearly two-thirds of respondents named security and risk concerns as the top barrier — ahead of regulatory uncertainty or technical limitations. This reflects that organizations are less constrained by their ability to build and experiment with agents than by their confidence they can deploy autonomous systems safely at scale. When an agent can take real actions across connected systems, the consequences of a security failure grow materially, and most organizations don’t yet trust their controls.

What did the report find about AI incidents?

The share of organizations reporting AI-related incidents held steady at roughly 8%, unchanged from 2025. But almost 60% of organizations that had an incident are unhappy with their own response. The important insight is the combination: incidents aren’t becoming more frequent, but confidence in handling them is declining — meaning system complexity is outpacing response capability. Preparedness, not frequency, is the problem.

Does investing in responsible AI actually pay off?

McKinsey found that organizations investing $25 million or more in RAI report significantly higher maturity and are far more likely to realize material AI benefits, including EBIT impact above 5%. The report frames RAI investment as “not a tax on innovation but a key enabler of sustained value creation.” The caveat: this is a correlation, and McKinsey’s AI Trust practice has a commercial interest in the finding — treat it as a strong directional signal rather than a precise formula.

What most differentiates high-maturity organizations?

Explicit accountability. Organizations with a clearly accountable RAI function — an AI-specific governance role or internal audit/ethics ownership — score an average maturity of 2.6, versus just 1.8 for those without clear ownership. Naming who owns responsible AI is the single largest differentiator in the data, and it’s a decision that costs organizational will rather than budget.

What should engineering teams take from this report?

That agentic governance is becoming an engineering requirement. The controls McKinsey describes — permission scoping, tool-use boundaries, action-level audit logging, kill switches, self-verification — are features engineers build. Teams shipping agents should treat observability of what agents do (not just what they say), retrieval provenance, and the ability to halt a running agent as core engineering work. The scarcity of people who can make agents trustworthy in production is also a significant career opportunity.

How does this connect to other AI developments in 2026?

Directly. The cybersecurity concern connects to research like Cornell’s WARP prompt-injection attack, which showed how easily AI agents can be manipulated through the web content they retrieve. The governance-as-engineering theme connects to practices from Claude Code’s development around agent verification. And the knowledge-gap finding connects to the Forward Deployed Engineer boom and the premium on engineers who can deploy AI safely in real environments.


Final Take

McKinsey’s 2026 report lands on a paradox that defines enterprise AI right now: organizations have gotten measurably better at responsible AI, and it still isn’t enough — because the thing they’ve gotten better at (building and running AI) has outpaced the thing they most need (governing what it does autonomously). The average maturity score went up. The dimensions that keep agents safe stayed behind. Both are true, and the gap between them is where the risk lives.

The report’s most valuable contribution isn’t a number — it’s the saying-to-doing reframing. Once you internalize that agentic AI’s failure mode is action rather than speech, the whole governance conversation changes. The controls that worked when a human stood between AI output and consequence don’t work when you’ve deliberately removed the human. Every organization racing to deploy agents is, whether it realizes it or not, dismantling its own safety net and betting that its governance is strong enough to replace it. The data says most of that governance isn’t there yet.

The most honest finding is the quietest one: incident frequency is flat, but confidence in handling incidents is falling. That’s not a story about things going wrong more often. It’s a story about organizations sensing, correctly, that they’re less prepared for the failures that are coming as autonomy scales. That instinct is worth trusting — and acting on before the incident, not after.

For engineering leaders, the practical takeaways are concrete and available now: name an owner, fund the capability, close the skills gap, govern agents as their own discipline, rehearse your incident response before you need it, and treat trust as what unlocks scale rather than what slows it. McKinsey’s line is the right one to end on. AI trust cannot be bought and installed. In the agentic era, it’s the difference between agents you can deploy and agents you can only pilot — and increasingly, that’s the difference between capturing the value of AI and watching competitors do it.


Published 2026 · The AI & Tech Society · digitalstrategy-ai.com

Source: McKinsey & Company, “State of AI trust in 2026: Shifting to the agentic era,” by Gabriel Morgan Asaftei, Roger Roberts, Abby Sticha, and Cécile Prinsen, published March 25, 2026 (mckinsey.com). All statistics — the 2.3 average maturity score, the ~30% level-3 figure for governance dimensions, the two-thirds security barrier, the 74%/72% inaccuracy and cybersecurity figures, the ~8% incident rate, the ~60% response-dissatisfaction figure, the $25M/5% EBIT link, the 60% knowledge-gap figure, and the 2.6-versus-1.8 accountability gap — are drawn directly from McKinsey’s published findings. The 2026 AI Trust Maturity Survey gathered responses from approximately 500 organizations between December 2025 and January 2026. Editorial framing and the connections to agentic engineering practice, the WARP attack, and Forward Deployed Engineering are this publication’s analysis, not McKinsey’s.


Discover more from The Tech Society

Subscribe to get the latest posts sent to your email.

Leave a Reply