Reports of AI agents pushing beyond their test environments are raising a critical question: Are the guardrails keeping pace? AI agents are often mistaken for more capable chatbots, but unlike traditional chatbots, they can reason, plan, and take action. That autonomy opens the door to greater productivity—and introduces a new set of risks.
McKinsey Partner Rich Isenberg compares AI agents to toddlers in a recent episode of The McKinsey Podcast. Tell a toddler to run down a hallway and stop before the stairs, and they might. They might also keep going. The solution? Put up a baby gate. For AI agents, that means controls they can’t bypass.
There’s already evidence of the risk. Eighty percent of organizations say they have encountered risky behaviors from AI agents, including improper data exposure and unauthorized system access. Organizations will need clear ownership of that risk and a record of what agents do. Guardrails also need to be built into the systems rather than left for individual teams to apply.
Explore McKinsey perspectives on the risks of agentic AI and how organizations can adopt AI with greater control.
Deploying agentic AI with safety and security: A playbook for technology leaders
The board’s role in managing emerging AI risks
State of AI trust in 2026: Shifting to the agentic era
The speed problem: How frontier AI exposes weakness in enterprise cybersecurity