Acuity AI Advisory
← Insights
·5 min read

The Rollback Rate Is Highest Where AI Governance Is Best

G

Ger Perdisatt

Founder, Acuity AI Advisory

Sinch surveyed 2,527 decision-makers. Firms describing their AI governance as fully mature pulled back 81% of agent deployments, against 74% overall. That inversion is the story.

Sinch commissioned research across 2,527 senior decision-makers in January and February this year. Sixty-two per cent had AI agents running in production. Seventy-four per cent had been forced to reverse or terminate at least one of those deployments. And among the organisations that described their governance frameworks as fully mature, the rollback rate rose to 81%.

The firms with the best guardrails pulled more agents out of production than the firms with weak ones. That inversion is the most useful piece of information published about enterprise AI this year, and it says something uncomfortable about how most organisations are spending their governance money.

Mature governance is a detection system

Read the 81% correctly and it stops being alarming. Those organisations did not fail more often. They found out more often. A firm with real monitoring, real logging and real escalation paths discovers that an agent is quoting the wrong prices or emailing the wrong counterparties, and it switches the thing off. A firm without those controls carries the same failure and never books it as an incident. What the rollback rate measures is visibility.

Which leaves the real problem in plain sight. All that governance investment is doing its work after the agent is live, in front of customers, holding credentials, taking actions that are hard to unwind. The controls are catching failures at the most expensive possible point in the lifecycle.

Grant Thornton put the same finding a different way in March. Of 950 business leaders surveyed, 78% lacked strong confidence that they could pass an independent AI governance audit inside 90 days. At the piloting stage, 7% were very confident. Firms only reach confidence once systems are fully integrated, which is to say once the mistakes have already been made and paid for.

Binary governance is what breaks

Gartner published research in May on why this keeps happening, and the diagnosis is sharp. Enterprises treat agent governance as binary. An agent is either locked down or fully trusted. Shiva Varma, the analyst behind it, named that as the root cause of failure, and Gartner's projection is that 40% of enterprises will demote or decommission autonomous agents by 2027 because of governance gaps found only after a production incident.

The distinction that goes missing is between what an agent can do and what it is allowed to reach. A document summariser reading a shared drive and an agent with write access to your billing system are not the same risk, and a single AI policy applied to both will either strangle the first or wave through the second. In practice it does both.

Tiering fixes it, and the tiers are not complicated. An agent that only reads defined sources and shows output to the person who asked needs scoped access, authentication and logging. An agent that drafts recommendations for a human to review and execute needs output quality review and hallucination testing on top. An agent that acts without a human in the loop needs transaction limits, reversibility, a named owner and a kill switch someone has actually tested. Most Irish organisations we assess have one policy covering all three, usually written for the first case and quietly applied to the third.

In Ireland the rollback now has an audience

Until this month the cost of pulling an agent was commercial. It is now supervisory as well. The AI Office of Ireland has been operational since 2 August under the Regulation of Artificial Intelligence Act 2026, with Paul Byrne as its first chief executive, coordinating enforcement across sectoral regulators including the Data Protection Commission, the Central Bank and Coimisiún na Meán. Article 50 transparency duties are enforceable from the same date, along with the full penalty regime.

The high-risk obligations were pushed out to December 2027 by the Digital Omnibus, and a lot of Irish boards have read that as breathing room. It is not, for a specific reason. An agent that misfires in production generates a data protection question, a consumer protection question or a fitness-and-probity question today, under law that is already in force, regardless of where the AI Act deadlines land. The rollback itself is now a disclosable event in regulated sectors.

What to do before the next agent goes live

Four things, in order, and none of them require a platform decision.

Sort your agents into autonomy tiers before you write another policy. Read-only, advisory, and acting. If a system holds credentials it can use without a human, it belongs in the third tier no matter how it was sold to you.

Move one control from post-production to pre-production. Pick the failure mode that would embarrass you most and test for it in staging with real data, not sample data. This is the single change that shifts governance from detection to prevention.

Give every acting agent a named human owner and a tested kill switch. Not documented. Tested. If nobody has switched it off in anger, you do not have a control, you have a paragraph.

Log the near-misses. The 81% figure exists because those firms counted. An organisation that only records incidents severe enough to reach the board is flying on a fraction of its own data.

The Acuity AI position

We diagnose before we prescribe, and this is a clean illustration of why. An organisation reporting no agent rollbacks is either running nothing consequential or seeing nothing. Both readings change the advice completely, and you cannot tell which one you are looking at from a framework document. You tell it by going into the systems, listing what is actually deployed, checking what credentials those things hold and asking who would notice if one went wrong on a Friday evening.

Every organisation in that Sinch sample had governance of some description. The ones that came out best were the ones whose governance told them the truth early, and cheaply. That is achievable, and it is mostly a question of where in the lifecycle you spend the effort rather than how much of it you spend.

We work with Irish boards and leadership teams on exactly that assessment: what is running, what it can reach, what happens when it fails, and which controls are earning their keep. Vendor-neutral, evidence first.

ai governanceagentic aiboard advisoryirelandoperational risk