40% of autonomous AI agents could face demotion, a rollback in autonomy and operational scope, by 2027, according to a Gartner prediction.

The Gartner report argues that AI agents face a risk as the gap between what they promise and execute widens, leading to high demotion rates.

The whole premise is that AI governance failures are stemming from poor access management (IAM), the main driver of production incidents. Whilst enterprises invest in a “binary framework” of AI agents, either locked down or fully trusted, this is the “root cause of failure”. Instead, they should take a Proportional Governance Approach which grades AI agents by four autonomy levels, and each level should abide by trust boundaries and identity and access management controls (IAM). 

As AI agents scale up, organisations are ignorantly treating their access management as binary, attack-proof and completely trusted.

“Agents operate at different autonomy levels and across different trust boundaries. When the same controls are applied indiscriminately, organisations encounter two common failure modes: over-restriction of simple agents, which slows delivery and drives shadow development, or under-restriction of more autonomous agents, which increases operational, security and compliance risk.”  

Gartner stresses that IAM models must evolve to treat AI agents as distinct digital identities requiring proportional governance, monitoring their specific “trust boundaries,” scoping data access, enforcing strict user authentication, and logging usage based on the agent’s autonomy level.