If your agentic AI deployment plan treats capability as the gating question ("is the agent capable enough to do the work?"), the 2025 survey data shows you are working on the wrong constraint. 62% of organisations cite security and risk concerns as the top barrier to scaling agentic AI. Capability is not the bottleneck. Risk surface is.
Main obstacles to reaching fully scaled agentic AI, 2025:
The data underneath that 62%:
Technical limitations: 38% cite this as a primary obstacle. Regulatory uncertainty: 38%. Gaps in RAI tooling and control: 36%. Resource or budget constraints: 34%. Unclear or insufficient business value: 32%. Immature vendor or ecosystem landscape: 28%. Organisational resistance: 23%. Lack of executive support: 9%. Other: 2%. None: 1%.
The picture: the obstacles to agentic AI scale are not the obstacles to language model deployment. The 2024-era playbook for AI deployment (secure executive buy-in, build a business case, navigate change management, address technical limitations) addresses the 9% obstacle (executive support), the 23% obstacle (organisational resistance), and the 32% obstacle (business case). It under-allocates to the 62% obstacle (security and risk concerns) and the 36% obstacle (RAI tooling gaps).
For comparison, the same survey asked about obstacles to general responsible AI implementation. The top barriers there were knowledge and training gaps (59%), resource constraints (48%), and regulatory uncertainty (41%). Security and risk concerns did not appear as a dominant obstacle in the general RAI question. They appear as the dominant obstacle specifically when the question is about scaling agentic AI.
The difference is structural. Language model deployment creates output-review failure modes: the model produces wrong or unhelpful output, and human review catches it. Agentic deployment creates action-execution failure modes: the agent takes actions in the world that may have consequences before any human reviews them. The risk surface is fundamentally different.
What does action-execution risk look like in practice? An agent with email access can send messages that commit the organisation. An agent with calendar access can book meetings that consume executive time. An agent with database access can write records that update production data. An agent with code-execution capability can run scripts that modify systems. Each of these capabilities is necessary for the agent to do meaningful work. Each is also a vector for failure modes that did not exist in the previous generation of AI deployment.
The 2026 data, on capability terms, shows the agent capability climb is real. OSWorld jumped from 12 to 66.3% in one year (see Ch 2). GAIA from 20 to 74.5% in nine months. The capability is now genuinely strong enough that the gating question for deployment is not "can the agent do the work?" but "what happens when the agent does the work wrong?"
The security and risk concerns visible in the 62% number are the practical expression of that question. The deployment teams are not sceptical about agent capability. They are sceptical about whether the security and risk infrastructure inside their organisation can absorb the action-execution failure modes that agents introduce.
Three procurement implications follow.
The first: agentic AI procurement evaluation needs a security and risk surface dimension that did not exist in language model procurement evaluation. The evaluation should include, at minimum: authentication and authorisation model (who is the agent acting as, with what permissions?), audit and logging (can every agent action be reviewed?), reversibility (which agent actions can be undone, which cannot?), failure-mode taxonomy (what specific failures has the agent shown in adversarial testing?), and human-in-the-loop boundaries (which actions require human approval before execution?). Vendor selection that does not include these dimensions is selecting on capability while accepting unknown risk exposure.
The second: the RAI tooling gap (36% of organisations cite it as an obstacle) is now a procurement-relevant concern. Vendors that offer integrated RAI tooling (agent observability, action approval workflows, audit infrastructure, incident response integration) close the gap that 36% of organisations are flagging. Vendors that ship only the agent capability and leave the tooling gap for the customer to fill are creating a deployment readiness mismatch that the data shows is one of the top three obstacles to scale.
The third: the regulatory uncertainty (38% of organisations) is a real constraint on agentic deployment, not just on language model deployment. The EU AI Act categorises certain agentic uses as high-risk (depending on the deployment context). ISO/IEC 42001 requires documented governance for AI systems that take actions. NIST AI RMF asks about deployment risk specifically. Agentic AI deployment plans that have not mapped to these frameworks are operating in regulatory uncertainty that the data shows is a third-tier blocker.
The prescription: rebuild agentic AI procurement and deployment frameworks around the security and risk surface as primary criteria, with capability as a sanity check rather than the headline question. Procurement evaluation should require disclosure of authentication and authorisation model, audit infrastructure, reversibility properties, failure modes, and human-in-the-loop boundaries. Deployment infrastructure should include agent observability, action approval workflows, and incident response integration before the deployment goes live. The 2024-era playbook for AI deployment will under-perform for agentic AI because the obstacles it addresses are not the obstacles the survey data shows are blocking scale.
For practitioners, the planning anchor needs to shift. Agentic AI is not a more-capable language model. It is a fundamentally different deployment pattern with a different risk surface. The 62% number in the survey is not noise. It is the structural feature of the agentic AI landscape that will shape procurement and deployment decisions for the next 24–36 months. Plans that build for this reality (security and risk as the primary procurement dimension, not capability) will produce better deployment outcomes than plans that treat agentic AI as a capability extension of language model deployment.
Sources
- Primary: Stanford AI Index 2026, Chapter 3 (Responsible AI) 3.3 — hai.stanford.edu/ai-index/2026
- Survey data: McKinsey & Company "State of AI" Survey, 2025 — agentic AI scaling obstacles
- Regulatory frame: EU AI Act; ISO/IEC 42001:2023; NIST AI RMF
Discussion