The most striking claim in this story is also the one we trust least, so we start there. A report titled "Scaling AI agents with trustworthy data" says that within two years, 100% of respondents plan to use agentic AI, with 69% expecting to use it widely.1 Agentic AI means software that carries out tasks on a company's behalf instead of only answering questions. The same report says that in organizations it calls 'data laggards', AI access to company data falls to 30% or less.1
Our own measurement of that publication is unflattering. Of 11 claims from it that we checked, 0% held up.1 Read the figures above as the report's assertions, not as established fact. A related headline figure, that companies let agents touch only 45% of their data, does not appear in the material we could verify. We are not repeating it.
Why the question matters
The idea is simple even where the numbers are soft. An AI agent is only as useful as the information it is allowed to use, and only as safe as the checks around it. If the agents arrive faster than the data preparation and oversight, results disappoint. That is the gap this piece examines. It is our framing of the evidence, and the evidence for it is uneven.
A wave of specialists, described in their own words
The businesses selling these agents describe large ambitions, and CB Insights has been publishing their leaders' interviews in its Enterprise AI coverage. These are company claims, not audited results.
Covecta sells to banks. Its Chief Revenue Officer, Ben Thomas, says it deploys "seasoned banker agents" for workforce productivity, workflow automation and portfolio management.2 He says its market is tens of thousands of financial institutions globally, and that it aims to disrupt "not just their software budget but their labor budget as well."3 It currently serves customers in the US and UK.4
Penguin AI also sizes its market by labor, not software. Head of Marketing Glenn Herzberg says US healthcare administration runs about a trillion dollars a year, about a quarter of total health spend. He adds that published estimates put around $570 billion of that in work with no effect on health outcomes.5 Those estimates are unnamed in the interview, so we cannot check them.
Maisa AI's CEO, David Villalon, defines his market as process automation of core tasks at regulated industries. He says those tasks must be auditable, reproducible and hallucination resistant.6 A hallucination is an AI stating something false with confidence. Note what that list of requirements amounts to: the customers most willing to pay are the ones demanding proof that the software can be trusted.
Investors are also backing this category. CB Insights published a further set of executive interviews on 22 and 24 September 2026, with Veridox, Binary World, Shepherd, Arlo and LARX.7 Separately, Latitude, a payments company, raised a $35M Series A on 10 September 2026 for stablecoin-to-local-currency payments.7 That is a payments deal, not an enterprise-AI one, so it shows appetite for fintech more than for the trust problem.
Emily Man, a partner at Primary, described the founders of Casap, another CB Insights subject, as having "experienced the pain points of disputes firsthand at their respective large fintech companies." She said they saw how much internal effort it took to solve those challenges "even with a really strong engineering team."8 The lesson is that the hard part is often the organization around the software, not the software itself.
Big incumbents are buying the guardrails
Established companies are spending on control as much as capability. On 22 July 2026, Manulife and Microsoft announced a five-year agreement. Manulife will adopt Microsoft's Frontier Suite, deploy Microsoft Agent 365, and expand Microsoft 365 Copilot to more than 30,000 employees.9 Manulife's Shamus Weiland called the partnership "a critical enabler of Manulife's continued evolution into a truly AI-driven organization."9 The announcement is titled as being about AI governance.9
A day earlier, Box announced agent guardrails, third-party agent activity oversight, prompt injection detection, and access policies based on agent classification.10 Prompt injection is a trick where hidden instructions in a document steer an AI off course. Tatsutoshi Murata of Nomura Research Institute said that as it advances its use of AI agents, it expects Box "to provide the administrative features needed to safely leverage this new era of AI."11
Both are company press releases. Our reliability check found that 57% of 4,952 claims from their common source held up.9,10 That is better than the MIT Technology Review figure but well short of comfortable. Treat the announcements as evidence of intent to buy oversight. Whether the oversight works is a separate question.
What the Nvidia numbers do and do not show
Nvidia supplies the hardware underneath much of this, and its filings are the firmest evidence we have. Its cost of revenue, essentially what it spends to deliver what it sells, rose from $16.621 billion in fiscal 2024 to $32.639 billion in fiscal 2025 and $62.475 billion in fiscal 2026, checked against SEC filings.12 That is more than a three-and-a-half-fold rise in two years. Our sources give no comparison that would make these sums easier to picture, and we will not invent one.
Cash held over the same fiscal years was $7.28 billion, $8.589 billion and $10.605 billion.13 Quarterly cash is choppier. It was $15.234 billion in the first quarter of fiscal 2026 and $13.237 billion in the first quarter of 2027.13 Cost of revenue in those same quarters rose from $17.394 billion to $20.458 billion.12 So spending is still climbing, but these figures do not show that investors doubt AI demand. They describe one supplier's finances, and no more.
Nvidia also sells tools aimed at the trust problem. Our knowledge graph lists NVIDIA NeMo Guardrails and the NeMo Agent Toolkit as developed by Nvidia. It also lists customers including Mount Sinai Health System and Yum! Brands, and names Advanced Micro Devices as a competitor.14 Nothing here says how much revenue those tools bring in. Whether you own Nvidia through an index fund depends on your fund, and our sources do not give the weighting, so we cannot say.
What we could not confirm
The original framing of this story included insider selling at C3.ai and a slowdown in chip launches. Our verified sources contain no C3.ai selling data, so we make no claim about it. The dossier does list two scheduled Alibaba T-Head chip releases, the Zhenwu V900 in Q3 2027 and the J900 in Q3 2028.7 Those are plans, and they do not show a slower cadence. Our framing that the market is pricing in a trust gap is a hypothesis. The evidence supports it in places, but it does not prove it.
What to watch
- Whether the startups above publish results, such as customer counts or audited savings, in place of market-size claims.
- How Manulife's Agent 365 rollout to more than 30,000 employees goes, which is one of the few concrete deployments in our sources.9
- Nvidia's next quarterly filings, for whether cost of revenue keeps rising faster than cash.12,13
- Whether the MIT Technology Review figures are replicated by a source that passes our checks.


