Hive Talk to us
Governance · June 2026

Saying the wrong thing was the old risk.

McKinsey’s 2026 AI Trust Maturity Survey finds organisations deploying agents faster than they build the discipline to govern them. Most are reusing controls designed for text generation on systems that now take actions.

Two years of AI governance work in most organisations was aimed at one failure: the system says something wrong. Hallucinated facts, biased outputs, leaked data in a response. McKinsey's 2026 AI Trust Maturity Survey of roughly 500 organisations, taken over the winter and published in March, puts the new failure plainly: systems that do the wrong thing. Unintended actions, misused tools, operation beyond the guardrails. The controls built for the first problem do not cover the second.

1. The numbers

Average maturity rose to 2.3 on McKinsey's scale, from 2.0 a year earlier. Progress, but only about a third of organisations reach level three or higher on strategy, governance and, newly measured this year, agentic AI governance. Because that last dimension was only added in 2026, most organisations are starting near zero. They have model monitoring, data infrastructure and a responsible-AI policy, and they are pointing all three at agents that take actions in live systems.

2. Why the old controls miss

Output review catches a wrong sentence. It does not catch a payment that was made, a file that was moved, an email that was sent. Governance for agents has to sit at the action, not the output: which systems an agent may act in, with which permissions, what it must stop and ask about, and what record each action leaves. That is an operating question owned by whoever runs the workflow, not a policy question owned by legal.

A policy document governs what people intend. Only an operating control governs what an agent does.

3. What the mature third do

  • Scope permissions per workflow, not per tool. The same agent platform has different reach in the finance close than in a client mailbox.
  • Define the consequential step in each workflow and place a human there, with evidence on screen and the decision logged.
  • Keep the record in their own hands. An audit trail in a vendor console is not an audit trail the firm's auditor can use.
  • Rehearse the incident. What happens when an agent does something wrong that reached a client: who is told, what is reversed, what is disclosed.

4. For professional firms specifically

Firms hold client data under duties of confidentiality and act under professional supervision rules that predate any of this. That is an advantage. The disciplines of file ownership, sign-off and documentation map almost directly onto what agentic governance requires. The gap is not conceptual; it is that the controls need to be built into the workflow software rather than written into the manual. Firms that make that move will find the insurer's questionnaire and the client's vendor review considerably shorter.

Hive Newsroom follows what is changing in AI and professional services. Sources are linked in the text; figures are as published at the time of writing. Comments and corrections: press@get-hive.ai. Back to the .