In June 2025, Gartner published a warning that rippled through the tech market: more than 40% of agentic AI projects will be canceled by the end of 2027. This was not a technology problem. It was a case of expectations that never matched reality. Gartner named the culprit: "agent washing" — vendors rebranding old AI assistants and automations as "agents" with no real change underneath. Of the thousands of companies claiming to sell agents, Gartner estimated that only about 130 deliver something real.

For companies in Brazil and Latin America, this matters now. When a company decides to invest in agentic AI, it is looking for work actually done — not a polished conversation. And the gap between what the slide promises and what gets delivered is exactly where the cancellations happen.

The problem no AI solves alone

A rebranded agent is a chatbot that answers better. A real agent is a program that acts. The difference goes beyond marketing — it is architecture.

When finance needs an agent to audit accounts receivable, the expectation is that it logs into the system, checks who is overdue, sorts by days late, drafts a collection email and, before sending it, pauses and asks a manager to approve. All of it leaving a record of every step.

What many vendors ship instead is a better chatbot that talks about accounts receivable, while someone in finance still has to carry out every action by hand.

According to Outreach, five capabilities separate a real agent from a rebranded automation: intelligent decisions in the face of varied signals, not a fixed script; pulling information from several systems at once, not a single record; carrying out time-consuming tasks without manual intervention; spotting critical signals and acting on them; and recommending the next best step for that specific situation.

Many canceled projects started right there, in that gap: between deciding and suggesting, and actually executing and adapting on its own.

A common back-office routine makes the difference easy to see. Every week, the finance team at a mid-size company receives dozens of vendor invoices to check against purchase orders before releasing payment. A rebranded chatbot can explain the process and even flag a mismatch when someone asks. A real agent logs into the finance system, matches each invoice against its purchase order, flags the ones that do not line up, and only releases payment after someone confirms it — without anyone copying data from one screen to another.

Why banning it and going it alone both fail

Why banning it and going it alone both fail

Many companies try two approaches that fail. The first is distrusting anything that promises agentic AI and banning the technology outright. The second is collecting disconnected pilots, each team running its own agent, with no shared identity or audit standard.

The numbers show the pattern. According to a survey by Anagram of professionals in the United States, 45% of employees have already used AI tools banned by their employer — 26% of them within the week before the survey. A policy with no comfortable alternative does not cut usage. It cuts visibility into it.

Letting each team build its own agent does not solve it either. Whatever works well stays locked to whoever found it. There is no record of who authorized each action. When an incident happens, nobody can reconstruct what the agent did or why.

The Cloud Security Alliance found that 71% of connections to AI tools happen through personal accounts, outside corporate control. In that scenario, it is impossible to know who asked for what, with which information, and under whose authorization.

The problem is not limited to mislabeled agents. A 2025 study from MIT's NANDA initiative, based on 300 deployments analyzed, 150 executive interviews, and a survey of 350 employees, found that only about 5% of generative AI pilots at companies accelerate revenue; the vast majority stall, with little to no measurable impact on the bottom line. According to the study, the reason is rarely the technology itself: it is the lack of integration into the team's actual workflow, the same blind spot that leaves room for agent washing.

What has to be in place

An environment with real agents rests on four verifiable mechanisms. None of them is about distrusting the team. They are about letting people work with AI without carrying the weight of every decision alone.

Corporate identity, not a personal account. The agent signs in with the same network login — the person controlling it uses their corporate identity, the profile comes from the directory, and someone removed from the directory loses access along with it, with no dependency on anyone remembering to revoke a stray account. That answers a simple question: who was in control?

Access role by role. If an agent only needs to read HR documents, it gets read access to HR. If it also needs to schedule meetings on a corporate calendar, calendar permission gets added. Nobody grants "everything" because "that was the only way". Granularity exists so a single security incident does not hand an attacker every key in the building.

Human approval before a sensitive action. Risky actions — sending an email on the company's behalf, recording financial data, scheduling a meeting with a decision-maker — make the agent stop and ask a person to confirm before moving forward. Critical documents can require two-person review, with whoever drafts kept separate from whoever approves, making clear who authorized that content to become information the agent will use.

A detailed audit trail. Every action the agent takes is logged: which tool was connected, which permissions were used, who approved it, what changed, and when. In an audit or an incident investigation, that is the difference between reconstructing events in minutes and not being able to reconstruct them at all.

That is how Skyller was designed: agents that run on real corporate identity, human approval before sensitive actions, and an audit trail on every step.

The payoff isn't just for IT — it's for the whole company

The payoff isn't just for IT — it's for the whole company

When an agent runs under clear rules of identity and approval, whatever works well no longer stays locked to one person. The analyst who found the perfect script for processing an invoice can document it once, and the agent runs it for everyone with permission. Someone on the team creates it; the whole company moves forward.

The second payoff is budget. When every team buys its own AI subscription, some licenses sit idle while other people hit their limit. Credits shared across the team fix both problems: whoever needs more uses more, and consumption stays visible.

For a company in Brazil or Latin America still running much of its back office on spreadsheets and email, that payoff counts twice. It is easier to justify the investment to leadership when the result is measurable — less rework, fewer people stuck on repetitive tasks — rather than just a polished demo. And because the process stays documented inside the environment itself, an employee leaving does not take the workflow they built along with them.

Four questions to ask in the demo

Before signing with an agent vendor, bring these questions to the demo. The answers reveal whether you are buying a real agent or a chatbot with a new name.

  1. "If an employee is let go today, how many tools can they still log into tomorrow?" If the answer depends on someone remembering to cancel accounts on every platform, the problem is not security — it is the lack of corporate identity. A real agent plugs into the company directory.

  2. "When the agent needs to do something important, does it stop and ask a manager to approve inside the conversation, or does it just report back afterward?" If the answer is "it just reports back" or "the user has to approve everything", you are looking at an assistant. A real agent balances autonomy with risk: it handles some things on its own and pauses for others.

  3. "If there was an incident — an agent sent the wrong message or connected to the wrong data — can you reconstruct exactly what happened, who approved it, and why?" If the answer includes "that would be hard" or "it depends on logs that might not be available", there is no real audit trail. The company will not be able to investigate afterward.

  4. "Can the agent work with minimal permissions — reading one type of document, connecting to one system — or does it need broad access?" If it needs broad access, a single mistake will reach further than it should. Granular permissions are the sign that the vendor designed for security, not for implementation convenience.

Try Skyller for free