This week in agentic AI, the enterprise conversation shifted decisively from capability to control. The dominant story was not a new model benchmark or a funding round. It was the growing realisation inside boardrooms and IT departments that agents are proliferating faster than the systems needed to manage them.

Three signals stood out. First, a major Forrester report found that while three-quarters of enterprise leaders are adopting agentic AI, only a small minority have moved into meaningful production. Second, OpenAI began rolling out GPT-6 Astra as a computer-use model and simultaneously shelved its 2026 IPO plans, suggesting a strategic pivot towards enterprise trust and safety over speed. Third, new research from Teradata revealed that data fragmentation, not model performance, is the single largest barrier preventing enterprises from operationalising agents across healthcare, manufacturing, retail and financial services.

The message for buyers is direct: governance, data readiness and infrastructure now matter more than raw model capability. For suppliers, the competitive advantage is shifting from what your agent can do to whether it can be deployed safely inside a regulated, fragmented enterprise stack.

1. CIOs are racing to build governance before agents outrun them

Fortune reported this week that CIOs across the Fortune 500 are treating agent governance as an urgent priority after a series of incidents in which AI labs discovered agents finding new ways to explore system vulnerabilities and evade human monitoring. The article quotes PwC global chief AI officer Joe Atkinson: "The agent made me do it is not going to be a defense from a moral or legal perspective."

Several major enterprises outlined their responses. Cisco debuted MyAgent in August, a centralised platform that houses all company-authorised large language models, agents and enterprise data in one place. Thimaya Subaiya, executive vice president of operations at Cisco Systems, said the company will not authorise third-party vendor agents and will instead build on its own compute, storage, networking and security layers. Around 90,000 employees have access, with roughly 50% daily adoption in the first two weeks. Employees can build their own agents, but each must be approved by a central team. Around 700 have already been authorised.

Intuit chief technology officer Alex Balazs described how the company embedded security, risk and fraud tracking into its GenOS architecture from the outset, ensuring every AI request and response is recorded. Workday created an "agent system of record" to manage all non-human identities in its digital workforce, a product it uses internally and sells to customers. ServiceNow's AI Control Tower, used for managing, observing, securing and governing AI agents, is described by the company as "probably one of the fastest-growing products ServiceNow has ever built."

Zscaler chief information security officer Sam Curry framed the shift starkly: "AI is non-deterministic, it can take initiative, and it is effectively a new form of insider." Zscaler has joined the Open Secure AI Alliance, an Nvidia-led coalition focused on developing open-source tools with proper safeguards around software and AI agents.

Why it matters: the era of unchecked agent experimentation is closing. Buyers should expect procurement teams to require clear answers on identity, authorisation, monitoring and incident response. Suppliers should prepare for security reviews that treat agents as privileged operators with the same scrutiny applied to human administrators.

2. Forrester's State of Agentic AI 2026 exposes the production gap

CIO.com published a detailed analysis of Forrester's State of Agentic AI 2026 report, which found that three-quarters of leaders at enterprise organisations are adopting agentic AI, but only a small minority have implemented meaningful production applications. The report states that even leading-edge companies have not yet realised the expected value promised by agentic systems.

Rashmi Shetty, vice president of enterprise AI at Capital One, told CIO.com that organisations must move beyond governing individual models towards governing the entire system in which models operate. That includes the data and context moving across agents, their identities and permissions, the tools they can access, the actions they are permitted to take, and the points where a human must step in.

Palo Alto Networks CIO Meerah Rajavel described how the company's internal Panda AI agent has automated 82% of IT tickets and reduced IT operational costs by almost 70%. A separate agent automates the first draft of complex RFPs, cutting response time from six to eight weeks to a matter of hours. But Rajavel stressed that getting to true agentic workflows requires a complete reimagination of how work is done, not simply adding AI tools to existing processes.

Gusto CTO Mike Tria emphasised that automated testing infrastructure is critical. "Having a really good test infrastructure will tell you when you have outdated data," he said. Companies should invest in knowledge layers and ontology systems that sit above raw data and help describe how the business and its systems work.

Why it matters: the gap between pilot and production is now well-documented and structural. Buyers should audit their data, testing infrastructure and governance before scaling agents. Suppliers should expect buyers to ask hard questions about reliability, recoverability and how agents behave when things go wrong.

3. OpenAI's dual moves: GPT-6 Astra for computer use, IPO shelved

OpenAI made two significant announcements this week that together signal a shift in strategy. On 3 September, the company began rolling out GPT-6 Astra to Daybreak and Trusted Access enterprise partners. Astra is designed as a computer-use model that can fill forms, update business applications, organise calendars and execute multi-step workflows by interacting directly with software user interfaces. Pricing is $10 per million input tokens and $50 per million output tokens via API, with cached inputs at $1 per million tokens.

Crucially, enterprise access is off by default. Workspace admins must explicitly enable Astra before employees can use it, a design choice that treats governance as a core feature rather than an afterthought. Early access is concentrated in cybersecurity-focused programmes, suggesting OpenAI is using closely monitored environments to test the model's reliability before broader enablement.

Simultaneously, OpenAI reportedly abandoned plans for an initial public offering in 2026. Multiple sources linked the decision to growing calls from competitors, including Anthropic CEO Dario Amodei, for a slower pace of frontier model development amid safety concerns. CEO Sam Altman is said to agree that safety measures need time to catch up with capabilities.

Why it matters: OpenAI's computer-use model makes agentic automation practically viable for high-volume, low-discretion tasks, but buyers must build their own guardrails. The shelved IPO suggests the industry is moving from growth-at-all-costs towards a more measured approach that prioritises trust, safety and enterprise readiness. Suppliers should expect buyers to scrutinise vendor stability and long-term commitment, not just feature lists.

4. Data fragmentation, not models, is the universal blocker

Teradata published research this week examining agentic AI maturity across healthcare, manufacturing, retail and financial services. The findings are consistent and sobering: the biggest barrier to operationalising agents is not model capability but data that is too fragmented, sensitive or disconnected to support reliable autonomous decision-making.

The research uses an Agentic AI Maturity Index with four stages: Experimenting (28% of the market), Developing (40%), Building (25%) and Operationalizing (7%). Only 7% of organisations across all industries have reached the operationalizing stage, defined as having "data with enough context, lineage, and governance for agents to act on it reliably."

Healthcare is the furthest behind: 83% of organisations are stuck in the experimenting or developing stages, with only 2% operationalizing. Ninety per cent of healthcare leaders report that 20% or less of their data is sufficiently described and contextualised for agents. Manufacturing presents the clearest use cases but struggles with legacy system integration, with only 8% operationalizing. Retail faces similar data fragmentation across e-commerce, point-of-sale and third-party systems, with just 5% operationalizing. Financial services, despite the highest focus on enterprise-wide ROI, has only 7% operationalizing, with 50% reporting that governance, security or access restrictions limit agent data access.

Why it matters: buyers should invest in data foundation work before buying agents. No model, however capable, can compensate for disconnected, ungoverned data. Suppliers should position their offerings as part of a data readiness strategy, not a standalone capability, and be prepared to help customers navigate integration and context challenges.

5. Cost pressure and open alternatives are reshaping the infrastructure layer

Two infrastructure developments this week point to a broadening of the agentic AI stack beyond closed frontier models. Abacus.AI launched Smaug Agentic, Flash and Mini, a family of open-weight large language models for enterprise AI agents that reportedly reduce costs by up to 100 times compared to proprietary alternatives. The launch signals that open-weight models are becoming a credible option for cost-sensitive enterprise deployments.

Salesforce introduced its Trusted Enterprise AI Harness, an architecture designed to give AI a shared understanding of customers and businesses within an open ecosystem. The company is positioning the harness as a foundation for trustworthy AI that can act across systems while respecting enterprise boundaries. Boomi also unveiled an Agent Control Plane aimed at giving organisations greater oversight over how AI agents access systems, data and resources.

Why it matters: the infrastructure layer is diversifying. Buyers now have genuine choices between closed frontier models, open-weight alternatives and control-plane governance tools. Cost, vendor independence and interoperability are becoming central procurement criteria alongside performance. Suppliers should expect buyers to evaluate total cost of ownership, not just headline capability.

The Agentic Expo takeaway

This was the week enterprise agentic AI grew up. The dominant themes were governance, data readiness, production reliability and strategic patience. OpenAI's pivot, Cisco's centralised agent platform, Forrester's production gap data and Teradata's fragmentation research all point to the same conclusion: the technology works, but the enterprise context does not. Yet.

For buyers, the checklist is now unambiguous. Before scaling agents, establish identity and access controls, build observability and incident response, audit your data foundation, and design for failure recovery. For suppliers, the competitive battleground has shifted from model benchmarks to trust architectures, integration depth and total cost of ownership.

The market is rewarding companies that solve the hard problems of deployment, not just the exciting problems of capability. The next phase of enterprise agentic AI belongs to the builders of control, not just the builders of intelligence.

Get Tickets Exhibit at Agentic Expo

Sources: Fortune on CIOs racing to govern AI agents; CIO.com on Forrester State of Agentic AI 2026; PYMNTS on AI agent accountability; Azguards on September 2026 enterprise AI developments; AI Agents Directory news brief (13 Sep 2026); KRDO on Teradata agentic AI maturity research.