Securing 2M+ accounts & $15B+ in assets, protected & secure·B5 Secure™ — per data-element authorization for .NET platforms

Does It Need Judgment, or Just Rules?

Agent selection discipline

Does it need judgment, or just rules?

Enterprises are about to build agents by the tens of thousands and cancel nearly half of them. The teams that survive the shakeout won’t be the ones that deployed fastest — they’ll be the ones that asked one question before every deployment, and enforced the answer at the record.

The numbers

150,000 agents. 40% cancellations. 13% governed.

Gartner now predicts the average global Fortune 500 enterprise will run more than 150,000 AI agents by 2028 — up from fewer than 15 in 2025. The same firm predicts over 40% of agentic AI projects will be canceled by the end of 2027, naming three causes: escalating costs, unclear business value, and inadequate risk controls. And in Gartner’s own survey of IT application leaders, only 13% believe they have the right governance in place for what’s coming.

Read those together and the story isn’t “AI is failing.” Model capability doesn’t appear on Gartner’s cancellation-cause list at all. Every named failure mode is a discipline problem — and one of the three is precisely the problem B5 Secure exists to solve. When Gartner prescribes its six steps for managing agent sprawl, two of them read like our datasheet: define agent identity, permissions, and lifecycle with least-privilege access, and monitor and remediate agent behavior, correcting agents that exceed their intended scope.

Sources: Gartner press releases — “Six Steps to Manage AI Agent Sprawl” (April 2026) and “Over 40% of Agentic AI Projects Will Be Canceled by End of 2027” (June 2025). The framing question in this article’s title comes from Liz Centoni‘s commentary on that data.

The question

Ask it before the build, not after the budget review.

Agents are the right tool when the work is genuinely multistep, high-variance, and context-heavy — when the next action depends on understanding a situation, not on evaluating a condition. Most enterprise workflows are not that. Password resets, standard entitlement checks, rigid onboarding flows, threshold approvals: these are deterministic. They need clean automation, explicit rules, and someone with the conviction to say no to the agent pitch.

The distinction matters more than it did a year ago, because the cost of getting it wrong changed shape. AI that responds fails by producing a bad answer. AI that acts fails by producing a bad cascade — automated actions propagating across systems at machine speed before anyone notices. Every unnecessary agent in the estate is blast radius you volunteered for.

Rules, not an agent
Entitlement checks · access approvals · threshold-based routing · password and credential flows · standard onboarding · anything where the correct answer is computable from the inputs. Deterministic work belongs in a deterministic authorization engine — explicit rules, fail-closed, complete audit trail.
An agent — with enforcement
Multistep investigation · cross-system synthesis · drafting under judgment · high-variance customer work. Justified — and only ever deployed with its own identity, delegated authority narrower than its principal, and per-action, data-element authorization.
The three layers

Inventory tells you what exists. Assurance tells you what to trust. Enforcement decides what actually happens.

When an agent is justified, governance has three layers, and they are not interchangeable:

Inventory. Does the organization know the agent exists, who owns it, why it exists, and whether it still produces measurable value? Gartner’s sprawl guidance starts here for a reason — the customer who “stopped counting his agents” is already past the point where any other control can help. A registry is necessary. It is also the weakest of the three layers, because a registry never stopped a request.

Assurance. Has the agent been evaluated, continuously monitored, and tested against defined trust, safety, and compliance criteria? Assurance answers whether the agent should be trusted with the authority it holds.

Enforcement. When the agent acts — this request, this operation, this record, right now — does anything decide whether it’s allowed? This is the layer that exists at runtime, where the damage happens, and it is the layer most estates are missing entirely. B5 Secure enforces it in-process: the agent holds its own identity, always acts for an identified principal, and every tool call and data operation is authorized inside the AND-gate — permitted only when the agent’s delegated scope and the principal’s entitlement both allow it, per data element, fail-closed, with every decision logged. A manipulated agent doesn’t get a cascade; it gets a wall of denials and a suspension.

Inventory without enforcement is a well-documented incident. Enforcement is what turns Gartner’s “inadequate risk controls” from your cancellation cause into your survival criterion.

The first agent to retire

Start with the one doing entitlement checks.

If you want one concrete action from this article: find the agent (or the agent proposal) performing routine entitlement and access checks, and retire it. Authorization is the canonical example of work that must be deterministic — the correct answer is computable, the tolerance for creativity is zero, and the audit requirement is absolute. A probabilistic model in that seat is a liability with a demo. That work belongs in a purpose-built authorization engine: explicit grants, per-operation and data-element decisions, fail-closed behavior, and a decision ledger an examiner can read. That engine is what B5 Secure is — and the agents you keep get governed by the same one, at the same records, under the agent authority model.

Agent count is about to become a vanity metric. Governed, measurable, enforced outcomes are what survive the 2027 budget reviews. Go deeper in the Never Trust whitepaper and the seven field-proven authorization patterns — Pattern 5 is the agent authority model in engineering detail.

Before your agents number 150,000: enforce at the record.

Thirty minutes with a B5 engineer: your agent roadmap, the AND-gate, and a data-element denial you can watch happen — the risk control Gartner says the canceled 40% won’t have.

Scroll to Top