The headline number is stark: within two years, 100% of enterprise respondents to a Google Cloud-linked survey say they plan to be using agentic AI, with 69% expecting to use it widely.1 But the same body of research surfaces the number that actually explains why most deployments still look tentative — on average, AI agents inside these organizations can reach roughly 45% of company data, and at firms categorized as 'data laggards,' that figure falls to 30% or less.1 Two-thirds of those laggard organizations say legacy data systems limit how far they can scale agents (66%) and prevent agents from making decisions at speed (68%); among 'data leader' firms, only 8% report either constraint.1
A caveat belongs up front, because it is itself part of the story: the survey figures above trace to a single MIT Technology Review piece whose broader claim set has been checked against source documents and found to hold up in none of the 11 statements verified so far.1 That does not mean the 100%/69%/30% figures are wrong — they are internally consistent and directionally plausible against everything else in this dossier — but a reader evaluating a story about "data trust gaps" deserves to know that the trust gap extends to some of the reporting on the trust gap itself. Two of the corporate announcements cited below come from a wire service whose own track record shows roughly a third of checked claims holding up.2,3 Where this piece relies on direct, attributed quotes from named executives and investors, those are reproduced verbatim and are a different category of evidence than aggregated survey statistics.
The platforms are selling governance, not just capability
The response from the largest vendors has been to bundle agentic AI with the control layer enterprises say they're missing. Manulife, the Canadian insurer, renewed and expanded its five-year relationship with Microsoft in July, adopting the Microsoft Frontier Suite and deploying Microsoft Agent 365, alongside expanding Microsoft 365 Copilot to more than 30,000 employees.2 "Our partnership with Microsoft is a critical enabler of Manulife's continued evolution into a truly AI-driven organization," said Shamus Weiland of Manulife.2 The framing is explicit: adopting the Frontier Suite is described as giving Manulife "the trusted foundation to advance AI across our global operations."2
Box moved the same week, announcing agent guardrails, third-party agent activity oversight, prompt-injection detection and classification-based access policies for AI agents working across enterprise content.3 Tatsutoshi Murata of Nomura Research Institute, a Box customer, framed the value in exactly the access-versus-trust terms the survey data describes: "As we rapidly advance our utilization of AI agents, we expect Box — which has consistently led the development of security management capabilities for secure collaboration — to provide the administrative features needed to safely leverage this new era of AI."3
Nvidia sits at the center of a wider infrastructure build-out for exactly this governance layer: its portfolio includes the NeMo Agent Toolkit, NeMo Guardrails, NeMo microservices, the A-IQ platform and the Nemotron 3 Super model, sold into customers spanning healthcare (Mount Sinai Health System), government (the State of Alaska Legislative Affairs Agency) and consumer brands (Yum! Brands) — evidence that the demand for agent tooling with a governance layer attached is not confined to financial services.8
Vertical specialists are routing around the data problem entirely
A separate cohort of venture-backed startups isn't waiting for enterprise data estates to get cleaner — they're picking problems narrow enough that the data-access bottleneck barely applies. Casap, founded by former Robin Hood and Chime employees Shanti and Sayisi, targets fintech dispute resolution. Emily Man, a partner at investor Primary, said the founders "had both experienced the pain points of disputes firsthand at their respective large fintech companies and saw like the amount of internal effort and organizational work that it took to solve those challenges even with a really strong engineering team."4 Primary's interest, Man said, came from the founders' backgrounds and the specific opportunity they were pursuing: "We were immediately really excited about them because of their backgrounds, and they talked to us about this opportunity that they were thinking about tackling."4 She added that the diligence process reinforced the read: "the feedback was just resoundingly clear that these were two exceptional builders who were really passionate about starting their own thing and solving problems that they had seen before."4
Maisa AI is making the same bet across a wider swath of regulated industries. CEO David Villalon defines the company's market as automating "core business and production tasks at regulated industries" — the manual, human-handled work that sits inside a company's core product or service, in domains where outputs must be auditable, reproducible and resistant to hallucination.5 That is a deliberately narrower and more defensible claim than "automate the enterprise": it concedes that broad, cross-system agentic access isn't there yet, and builds the product around processes well-defined enough not to need it.
Penguin AI is running the same playbook in healthcare administration, and quantifies the prize in a way few of the platform announcements do. Glenn Herzberg, the company's head of marketing, sizes the market not as healthcare IT spend but as administrative labor spend: "US Healthcare Administration runs about a trillion dollars a year, about a quarter of the total health spend, and the published estimates put around $570 billion of that in work that has no effect on health outcomes."6 That $570 billion figure — administrative work that, by Penguin's own framing, produces no clinical benefit — is precisely the kind of narrow, well-bounded, high-volume process that a vertical agent can attack without needing to see a hospital system's entire data estate.
What to watch
The gap between the two strategies is the story to track. Platform players are betting that enterprises will eventually grant agents broader data access once governance tooling (Box's guardrails, Microsoft's Frontier Suite, Nvidia's NeMo stack) earns enough trust — a bet that pays off slowly and at enterprise scale.1,2,3,8 Vertical specialists like Casap, Maisa and Penguin are betting they don't need to wait: pick a process narrow enough to audit end-to-end, and the 45%-of-data ceiling never binds.1,4,5,6 Given that the underlying survey numbers carry a currently unverified track record, the more durable signal in this dossier may be the pattern in the deal-making itself — where investors and CEOs are choosing to build — rather than the specific percentages cited to justify it.


