Briefing #28. {{current_date_mdy_dashed}}

Welcome to The Boardroom Brief — the intelligence briefing for leaders who run the room.

This week the data is unambiguous: agentic AI has moved from pilot to production at a pace that has caught most governance frameworks flat-footed. 11× growth in production AI models, 76% of enterprises now defaulting to open-source LLMs, and legislative activity up 21% across 75 countries. At the same time, reasoning models are projected to power over 70% of agentic applications by 2029. The organizations treating this as “just another IT project” are already behind. The ones treating it as a board-level strategic and risk issue are the ones building durable advantage.

The pattern is consistent across every major signal this week: the bottleneck is no longer model capability. It is governance, ownership, and the ability to move from experimentation to scaled, auditable deployment without creating unacceptable exposure.

🧠 The Big Idea

Agentic AI didn’t ask for permission — and most boards still haven’t updated the risk register.

The numbers tell the story clearly. Enterprise adoption is no longer creeping; it is compounding. Production models are up 11× year-over-year. Vector database usage has grown 377%. And three-quarters of organizations are choosing open-source foundations rather than closed frontier models. At the same time, the shift to reasoning models and autonomous agents is moving faster than almost any prior technology wave. What used to be a six-month pilot cycle is now measured in weeks.

The governance gap is the real story. Deloitte’s work on board oversight shows that while leaders understand governance, risk, and compliance are essential, the actual mechanisms — named owners, updated risk taxonomies, audit trails for agent decisions, escalation paths when an agent acts outside policy — are still missing in the majority of organizations. The result is predictable: shadow AI, unapproved tool usage, and decisions being made by systems that no one at the executive level can fully explain or defend.

This is not a technology problem. It is an ownership and accountability problem. Boards that continue to delegate AI entirely to the CIO or a “digital transformation” committee are repeating the mistake they made with cybersecurity a decade ago. The difference is that agentic systems move faster, make higher-stakes decisions, and create regulatory exposure that scales with every automated action.

What this means for your organization:

Agentic AI changes the unit of governance. You are no longer governing models or even workflows. You are governing autonomous decision loops that can execute across systems, update their own logic, and interact with third parties. That requires a different level of policy specificity, logging, and human override capability than traditional IT governance was designed for.

Open source dominance changes the risk surface. 76% of enterprises choosing open-source LLMs means the supply chain, the fine-tuning data, the safety alignments, and the update cadence are now your responsibility in a way they weren’t when you bought a closed API. The cost advantage is real; the governance burden just moved inside the walls.

The regulatory multiplier is here. A 21% increase in AI-related legislation across 75 countries in a single year is not background noise. It is the signal that enforcement regimes are forming. The organizations that can demonstrate auditable, policy-aligned agent behavior will have a structural advantage in regulated industries and government contracting.

The question to bring to your next board meeting: Who owns the outcome when an AI agent makes a decision that affects customers, employees, or regulatory compliance — and what is their escalation authority when the agent’s reasoning cannot be fully audited?

Sources: Databricks State of AI Report; Menlo Ventures 2025 Generative AI in the Enterprise; Deloitte State of Generative AI; Ropes & Gray AI Q3 2025 Report

🛠 Tool of the Week

Glean Enterprise — the AI layer that makes agentic work actually governable

Most enterprise AI tools optimize for individual productivity. Glean optimizes for organizational memory and controlled action. It sits on top of your existing systems (Slack, Google Workspace, Salesforce, Confluence, etc.) and creates a governed, searchable, permission-aware layer that agents can safely query and act within.

What makes it relevant right now: as reasoning models and agents proliferate, the biggest risk is not capability — it is context and guardrails. Glean gives you the ability to define what an agent is allowed to see, what it is allowed to do, and creates an audit trail of every decision and data access. That is the difference between “we have agents” and “we can defend how our agents operate.”

Early adopters are using it to move from “AI pilot in one department” to “AI operating system with policy controls” without ripping out existing infrastructure. For boards that need to show auditors and regulators that AI activity is visible and bounded, this class of tool is becoming table stakes.

📊 By the Numbers

11× — Growth in production AI models inside enterprises over the past year. This is not experimental usage. These are models that have moved into revenue-critical or operations-critical workflows. The organizations that scaled this fast either had governance in place before the wave or are now retrofitting it under pressure. (Databricks State of AI Report)

76% — Share of enterprises now defaulting to open-source LLMs rather than closed frontier models. The cost and customization advantages are clear. The governance implications — supply chain, alignment, update velocity, and IP leakage risk — are now internal responsibilities. (Databricks; Menlo Ventures)

21.3% — Increase in AI-related legislative actions across 75 countries in 2024 alone. The regulatory surface is expanding faster than most compliance functions are staffed to handle. Agentic systems multiply the number of decisions that can trigger regulatory scrutiny. (Glean analysis of global legislative tracking)

70%+ — Projected share of agentic AI applications that will be powered by reasoning models by 2029 (from near zero in 2024). The shift from “chat with documents” to “autonomous goal execution” is the defining change of the next 36 months. Most current governance playbooks were written for the previous generation. (Ropes & Gray Global AI Report)

3–6 months — Average time from agent pilot to production deployment in organizations that have moved past experimentation. The window for thoughtful governance design is closing faster than traditional policy cycles can accommodate. (Menlo Ventures 2025 Enterprise AI Report)

🎯 The Move

This week: put AI agent governance on the board calendar with a 90-day ownership mandate.

The data shows the adoption curve has already inflected. The governance curve has not. That gap is now a board-level exposure.

Step 1 — Name a single executive owner for agentic AI outcomes (not just “AI strategy”).
This person needs P&L or operational authority and a direct reporting line to the board or a dedicated AI risk committee. Without named ownership, agent proliferation will continue in the shadows.

Step 2 — Require a one-page “Agent Decision Audit” for any agent that touches customer data, financial systems, or regulated processes.
The document should answer: What decisions can this agent make autonomously? What data can it access? What is the human override mechanism? How is every decision logged and reviewable? If it cannot be answered in one page, the agent should not ship.

Step 3 — Update the enterprise risk register to include “Autonomous AI Decision Risk” as a standalone category with quarterly board review.
Treat it with the same seriousness as cybersecurity or regulatory compliance. The velocity of agentic systems means quarterly is the minimum viable cadence.

Do this in the next 90 days and you will be ahead of the regulatory and competitive curve. Wait six months and you will be explaining to auditors why your agents were operating without guardrails.

📌 Worth Reading

Databricks — State of AI: Enterprise Adoption & Growth Trends
The clearest data set on what is actually happening inside enterprises right now — production models, open source adoption, and the infrastructure that is scaling fastest. Required reading for anyone trying to separate signal from vendor noise.

Deloitte — Oversight of AI in the Boardroom
Directly addresses the governance gap. The research shows leaders know governance matters but the practical mechanisms are still immature. The piece includes a useful framework for what “good” board oversight actually looks like in practice.

Menlo Ventures — 2025: The State of Generative AI in the Enterprise
Strong data on buy-vs-build decisions, product-led growth in AI tooling, and the speed at which agents are moving into production. The “enterprises prefer buying” finding has direct implications for how you should be thinking about your own build-versus-partner strategy.

You’re receiving this because you signed up at theboardroombrief.news

Free Tier: Monthly Issues, up to four briefs

Keep reading