AI July 29, 2026 4 min

Agent Governance Has Now Become a Core AI Investment – Not an Afterthought

Governance is no longer an afterthought for agentic AI. According to IDC’s Future Enterprise Resiliency and Spending Survey, Wave 10, enterprises now allocate an average of 16.7% of their total planned AI spending to AI and Agent security and governance, a share on par with investment in other core layers of the AI tech stack. The takeaway for CIOs and vendors: governance has moved from a compliance checkbox to a strategic budget priority.

That institutional shift was visible at WAIC 2026 in Shanghai. On July 16, representatives from 29 countries signed the Agreement on Establishing the World Artificial Intelligence Cooperation Organization and became its founding members. The following day, the conference issued a chair’s statement and two governance action plans, while also proposing a global initiative on trusted Agent connectivity and interoperability. A year after China proposed the creation of WAICO at WAIC 2025, the signing of the agreement represents institutional follow-through worth watching. Its practical impact will depend on how these commitments are translated into common standards, coordination mechanisms and implementation programs.

Why Governance Is the Gatekeeper, Not the Brake

IDC’s October 2025 FutureScape: Worldwide Agentic Artificial Intelligence 2026 Predictions forecasts that by 2030, up to 20% of G1000 organizations will have faced lawsuits, substantial fines, and CIO dismissals due to high-profile disruptions stemming from inadequate controls and governance of AI agents. Far from restricting what Agents can do, governance is what makes deeper integration possible in the first place. Without clear identity and authorization rules, companies won’t grant Agents access to core systems. Without full observability and immutable logs, teams can’t reconstruct what happened after an incident. Without built-in suspension, rollback and human-override controls, businesses can’t contain the damage when an Agent misbehaves. Trust scales with control and not the other way around.

Three Layers of Trust

Enterprise confidence in Agents builds across three interconnected layers:

1. Internal controls — Agent identity, permissions and audit trails

2. Cross-platform interoperability — standardized verification mechanisms

3. Cross-border alignment — regulatory frameworks and capacity-building

As Agents increasingly need to work across organizational and platform boundaries, the second layer matters as much as the first. Shared identity credentials, common connectivity standards, and audit-ready activity trails keep accountability clear even across company lines. Without them, every cross-platform integration means redundant security validation and custom risk assessment — a tax on the whole Agent economy.

Translating Global Governance Rules into Enterprise Agent Design

The three trust layers above aren’t abstract, they dictate real architecture choices. Identity and permissions become credential and account governance. Audit-ready activity trails become tool-invocation logs and accountability records. Risk tiers become access scopes and human-review checkpoints for high-stakes actions — the same logic enterprises already apply to a routine quotation-approval workflow, now extended to Agents.

What This Means for Enterprises and Vendors

This reshapes how enterprises should design and evaluate Agent systems in practice:

  • Assign every Agent a unique identity — with defined authorizing stakeholders and bounded permissions, calibrated to risk. Routine tasks can run autonomously; anything touching sensitive data, capital transactions or production systems needs human-override capability.
  • Build fully observable, rollback-enabled pipelines — with complete audit trails covering every input, tool call and state change.
  • Push vendors for verifiable evaluation results — beyond task completion rates, including how well an Agent respects privilege boundaries, recovers from failure and escalates to humans.
  • Architect for cross-organization collaboration — Agents should present verifiable credentials, and receiving platforms should enforce granular, risk-based access policies.

Need to know how AI governance will impact your business? Explore the latest research, AI Governance: The Trust Layer — Governance Is Not Glamorous, But It Is About AI Trust and 中国智能体开发平台市场份额, 2025 to learn more. Fill out this form to Contact Us.

This blog is an extract of the original blog WAIC2026现场观察| 聚焦可行动AI,探索适配产业的治理规范 by Zhenya Sun, published in WeChat.

Zhenya Sun - Research Manager - IDC

Zhenya Sun is a research manager for the IDC team focused on exploring the application of technology and industrial development of AI and AI agents. He is also responsible for providing clients with consulting services on technologies, products, and markets related to large language models (LLMs) and AI agents, as well as delivering speeches at industry conferences and internal seminars. Before joining IDC, Zhenya served as a project management officer (PMO), responsible for internal and external strategic consulting, AI application research and advisory services, AI project framework standardization, management system construction, and technical training on AI applications. Prior to that, he also led initiatives in product development process optimization and user market analysis. Zhenya holds a Master's Degree in Engineering Management with a specialization in Information Systems Engineering from the University of the Chinese Academy of Sciences.

Subscribe to our blog