The intent-to-readiness gap
The headline number is stark: within two years, every enterprise respondent surveyed says it plans to be using agentic AI, and 69% expect to use it widely, according to reporting on enterprise AI adoption from MIT Technology Review.1 That kind of near-unanimous intent is rare for any enterprise technology. It is also, on its own, not very informative about whether agents will actually work inside these organizations — because the same reporting puts the constraint in plain terms: AI agents can access an average of 45% of company data, a figure that falls to 30% or less at organizations the report categorizes as "data laggards."1 Via News's fidelity checks against this specific source were unable to confirm any of the 11 claims tested from it, so the figures above should be read as reported rather than independently verified — a caveat worth stating plainly rather than passing the numbers off as settled fact.
The access gap compounds into a decision-quality gap. At data-laggard firms, two-thirds say legacy systems limit how far AI agents can scale (66%) and prevent agents from making decisions at the speed the business needs (68%) — versus just 8% of "data leader" organizations reporting either constraint.1 That is roughly an eight-to-one gap in how much an organization's own data infrastructure gets blamed for holding agents back, and it maps a fairly clean line between companies that can trust what an agent tells them and companies that can't.
Platform players respond by selling trust, not just capability
The largest enterprise vendors are visibly repositioning around that gap — building governance and access-control layers around agents rather than just shipping more capable ones. Box, the enterprise content management platform, announced a set of controls on July 21, 2026 aimed squarely at this: agent guardrails, oversight of third-party agent activity, prompt-injection detection, and classification-based access policies, all framed as letting enterprises "confidently deploy Box-native and third-party AI agents across their content."2 Nomura Research Institute's Tatsutoshi Murata, describing why that matters to an actual customer, said: "As we rapidly advance our utilization of AI agents, we expect Box—which has consistently led the development of security management capabilities for secure collaboration—to provide the administrative features needed to safely leverage this new era of AI."2 Murata also cited valuing Box's multi-vendor support for switching flexibly between AI models, and expressed confidence Box's protective layer would keep critical content protected as AI use expands.2
A day earlier, Manulife and Microsoft announced a five-year renewal and expansion of their partnership, with Manulife adopting Microsoft's Frontier Suite, deploying Microsoft Agent 365, and expanding Microsoft 365 Copilot to more than 30,000 employees.3 Manulife's Shamus Weiland framed the move as infrastructure for trust as much as capability: "Our partnership with Microsoft is a critical enabler of Manulife's continued evolution into a truly AI-driven organization. Adopting the Microsoft Frontier Suite represents the next phase of that transformation, giving us the trusted foundation to advance AI across our global operations…"3
NVIDIA's own agent tooling shows the same pattern from the infrastructure side. Alongside model and compute products like the DGX Spark hardware and the Nemotron 3 Super model, NVIDIA has built NeMo Guardrails, the NeMo Agent Toolkit, and A-IQ — evaluation and control tooling that exists specifically to make agent behavior auditable rather than just more autonomous.4 NVIDIA's customer base for this stack already spans healthcare (Mount Sinai Health System), government (the State of Alaska Legislative Affairs Agency), and consumer brands (Yum! Brands), with distribution partners including TD Synnex and derivative products like HPE's Agentic Trend Analyzer built on top of the NVIDIA stack.4 Note that AMD is named in the same graph as a direct competitor to NVIDIA on this infrastructure layer — a reminder that the governance tooling being built now is also a competitive moat.4
The vertical bet: skip the data problem, don't solve it
A separate, venture-backed cohort is pursuing a different answer to the same problem: instead of building enough governance to trust an agent against messy, partially accessible enterprise data, target processes narrow and well-defined enough that the data-access question barely arises.
Maisa AI's CEO, David Villalon, describes the company's target market in exactly those terms: "I define my market like the market of process automation of core business and production tasks at regulated industries. So, at the end, it's all the core tasks that are today being manual or handled by humans that are part of the core product or the core services of the company."5 The emphasis on regulated industries is deliberate — those are environments where processes must already be auditable and reproducible, which happens to be exactly what makes them tractable for an agent that needs to be hallucination-resistant rather than merely capable.
Penguin AI is making the same bet inside healthcare administration, and its market-sizing argument is unusually explicit about why back-office process automation, rather than general AI capability, is the immediate opportunity. Head of Marketing Glenn Herzberg put the addressable waste in dollar terms: "US Healthcare Administration runs about a trillion dollars a year, about a quarter of the total health spend, and the published estimates put around $570 billion of that in work that has no effect on health outcomes."6 That is the pitch in miniature: don't wait for enterprise data platforms to reach 100% agent accessibility — go after the slice of administrative work that is already isolated, rules-based, and measurably wasteful.
Casap is pursuing the same logic in fintech dispute resolution, and its origin story illustrates why founders are choosing this path. According to Primary partner Emily Man, Casap's founders, Shanti and Sayisi, built the company directly out of firsthand frustration at large fintech employers: "They had both experienced the pain points of disputes firsthand at their respective large fintech companies and saw like the amount of internal effort and organizational work that it took to solve those challenges even with a really strong engineering team."7 Man said Primary's interest was immediate: "We were immediately really excited about them because of their backgrounds, and they talked to us about this opportunity that they were thinking about tackling."7 The diligence signal, she said, came from people who had worked with the founders directly: "the feedback was just resoundingly clear that these were two exceptional builders who were really passionate about starting their own thing and solving problems that they had seen before."7
Reading the sourcing
The adoption statistics anchoring this story — universal two-year deployment intent, the 45%/30% data-access figures, the 66%/68%-versus-8% trust gap — all trace to a single MIT Technology Review report, and Via News was unable to confirm any of the 11 claims from that report checked against underlying sources.1 That does not mean the numbers are wrong; it means they haven't cleared our verification bar, and readers should weight them as reported industry data rather than confirmed fact. Separately, the corporate announcements from Box and Manulife are drawn from a wire source where roughly a third of checked claims have historically held up — a reminder that vendor press releases, even when accurately quoting named executives, are not the same evidentiary category as filings or audited data.23
What to watch
The two strategies described here — platform vendors building governance layers, specialists avoiding the data problem by staying narrow — are not mutually exclusive, and the next signal worth tracking is which one actually moves the 45%-of-data-accessible number. Manulife's Frontier Suite and Agent 365 rollout and Box's new agent-classification controls are both live deployments now, not pilots, so their results should surface in coming quarters. Whether vertical specialists like Maisa, Penguin AI, and Casap can scale beyond their initial regulated-industry beachheads — or whether they stay permanently narrow by design — is the test of whether "bypass the data problem" is a real strategy or just a way to launch first.

