ResearchJul 15, 20266 min read

Enterprise Content Is the New Agentic AI Bottleneck

96% of enterprises say agents need company-specific content; only 36% have actually wired it up. Box's new survey says the 2026 constraint isn't model capability — it's the plumbing.

Jordan Matthews

Senior Tech Correspondent

Share:

AI agents are no longer a pilot-program curiosity inside the enterprise — 83% of organizations are now running them, according to Box's 2026 State of AI in the Enterprise report, a Harris Poll survey of 1,640 IT decision-makers across the US, UK, France, and Japan fielded April 30–May 8, 2026. That number alone would have been a headline eighteen months ago. It isn't anymore. The gap the report actually surfaces is more useful: 96% of organizations say it's important for agents to access company-specific content, but only 36% have connected agents to trusted internal content across meaningful use cases.

That 96%-to-36% spread is the story. As the report puts it: "If the first phase of enterprise AI was defined by access to models, the next is defined by access to context." Everyone agrees on what agents need. Almost nobody has built the plumbing to give it to them.

The Governance Paradox

The reason for the gap isn't ignorance — it's risk, and the data on risk is uncomfortable. 49% of organizations have experienced an AI-related data exposure incident, where an AI tool surfaced content a user shouldn't have seen; 16% describe theirs as significant. Counterintuitively, the most mature AI adopters report the highest incident rate — 60% — which the report attributes not to sloppier practices but to a larger surface area: more agents deployed, more places to misconfigure, and better detection catching things that older, simpler setups would have missed silently.

Formal governance hasn't caught up to deployment speed. Only 34% of organizations have formal standards governing how agents access company data, and just 39% have comprehensive visibility across sanctioned and unsanctioned AI use inside their own walls. The top barriers cited are security and privacy concerns (38%), regulatory and compliance risk (29%), fragmented data (25%), integration difficulty (24%), and missing permissions or access controls (21%) — and more than two-thirds say legacy or on-prem systems are a moderate-to-major obstacle to fixing any of it.

Here's the paradox at the center of the report: 76% say current governance slows agent deployment down, yet 93% agree that better governance would actually let them move faster over time. Governance isn't the enemy of speed here — the absence of agent-native governance is. Controls built for human workflows (a person logs in, a person clicks approve) don't map cleanly onto software that acts continuously and autonomously. The fix Box points to is specific: granular permissions, action-level visibility, audit trails, and restrictions to trusted sources — governance designed for non-human actors, not retrofitted from human IT policy.

The Ground Truth Behind the Economics Story

This report is the ground-truth companion to McKinsey's new agentic economics framework: McKinsey argues that proprietary context is becoming the real competitive moat for agent deployments, and Box's data shows almost nobody has finished building that moat yet. Only about a third of enterprises have wired agents into trusted content at scale, which means the other two-thirds are running agents on incomplete or ungoverned information — exactly the condition that produces the 49% exposure-incident rate flagged elsewhere in the agent security conversation.

It also exposes an unfinished piece of the agent stack that gets less attention than model capability. The industry has largely converged on MCP as the standard for how agents call tools — but calling a tool and being safely, correctly permissioned to see the content behind it are different problems. MCP solved connectivity. It didn't solve identity, permissioning, or governance for autonomous agents acting at machine speed, and this report is a clear signal that gap is now the binding constraint, not model quality.

What This Means Going Into H2

The agent capability curve — sharper reasoning, longer autonomy horizons, frontier models like Fable 5 — has been the industry's headline story all year. Box's survey is a reminder that capability was never the bottleneck for most enterprises. Plumbing is. An agent with a Mythos-class model behind it is only as good as the trusted content it's allowed to see, and right now, two-thirds of enterprises haven't built the permissioning to let it see much of anything. The next competitive edge won't go to whoever has the smartest agent — it'll go to whoever finishes wiring the moat first.

#box#enterprise-ai#ai-agents#data-governance#ai-security#unstructured-data

Jordan Matthews

Senior Tech Correspondent · The Neural Dispatch

Covering the intersection of AI, engineering, and the future of building. We dig into what the tools actually do, how builders are using them, and what it means for the industry.

Keep reading

Related dispatches