
FIFA Forward Enterprise: Risk and Governance Lessons from a $20B Failure
August 3, 2026A vendor walks your executive team through a demo. The screen fills with the word “agentic.” The product, they explain, reasons through problems, sets its own path, and acts without waiting for a human. Six months and a seven-figure contract later, your audit team opens the hood and finds a chatbot wired to a decision tree that someone wrote in 2021.
That gap between the pitch and the product now has a name. It is called agent washing, and it belongs on your risk register.
What Agent Washing Actually Means
Agent washing describes the practice of relabeling older technology as agentic AI. Vendors take chatbots, virtual assistants, robotic process automation, and rules-based workflow tools, then market them as autonomous agents. Gartner defines the practice as labeling basic AI or generative AI features as AI agents to generate marketing attention and drive sales.
The scale of the problem is larger than most audit committees realize. Gartner estimates that of the thousands of vendors claiming agentic capability, roughly 130 offer the real thing. The firm also predicts that more than 40 percent of agentic AI projects will be canceled by the end of 2027, citing rising costs, unclear value, and weak risk controls.
The distinction that matters to auditors is simple. A genuine agent plans, adapts its approach when conditions change, and pursues a goal across multiple steps without a human directing each one. A rules-based system follows a script. That script may be long, branching, and impressive to watch, but it does not deviate from what a developer anticipated.
Why This Risk Is Growing
The control implications flow directly from that distinction, and they run in both directions.
If you buy a genuine agent and treat it as automation, you will underbuild your controls. You will skip the guardrails, escalation thresholds, human review points, and activity logging that autonomous systems require. You will also miss the failure modes that only appear when a system improvises.
If you buy a scripted tool and treat it as an agent, you waste governance capacity. Your team spends months designing oversight for autonomy that does not exist while real risks elsewhere go unexamined.
Regulators have already moved on the broader problem of exaggerated AI claims. The SEC settled with two investment advisers, Delphia and Global Predictions, over false statements about their AI capabilities, resulting in a combined $400,000 in penalties. The FTC launched Operation AI Comply and reached orders with DoNotPay, which marketed itself as a robot lawyer it could not deliver, and pursued Evolv Technologies over AI-powered threat detection claims. Your organization can face exposure both as a buyer of overstated technology and as a seller of it.
Where Agent Washing Shows Up
Gartner warned in May 2026 that agent washing is creating real risk in the supply chain planning technology market, where pressure to show results makes buyers less skeptical. Similar patterns appear across the enterprise:
- Procurement. Vendors advertise dozens of agents. Under review, many turn out to be templates or single-function scripts counted individually to inflate the number.
- Customer service. A tool marketed as an autonomous resolution agent routes tickets using keyword matching, then escalates anything it does not recognize.
- Finance and close automation. Reconciliation tools branded as agentic apply fixed matching rules that have existed in the product for years.
- Internal audit and compliance functions. Continuous monitoring platforms claim agentic testing while running scheduled queries against static parameters.
- IT operations. Incident response tools promise self-healing infrastructure and deliver predefined runbooks triggered by alerts.
What Internal Auditors Should Do Now
Bring the question forward into procurement rather than discovering it during a post-implementation review. Practical steps include:
- Write a capability definition your organization uses consistently. Document what qualifies as an agent in your environment, covering goal-setting, planning, adaptation, tool use, and memory. Apply it to every purchase.
- Ask vendors for evidence, not adjectives. Request architecture documentation, model details, decision logs from live deployments, and a demonstration of the system handling an input it has never seen.
- Test for adaptation. Give the system a scenario outside its training and observe the response. Scripted tools fail predictably at the edges of their rules.
- Audit contract language against delivered function. Compare marketing claims, statements of work, and actual behavior. Gaps here support both remediation and vendor negotiation.
- Match controls to reality. Calibrate your monitoring, approval gates, and audit trails to what the system does, not to what the label says.
- Review your own external claims. If your organization describes its products or services as agentic, verify those statements before a regulator does.
Internal audit has handled this pattern before. We separated cloud from hosting, blockchain from databases, and machine learning from statistics. Agent washing is the current version of a recurring assurance problem, and the profession is well positioned to answer it.
The question to keep asking is direct. Does this system decide, or does it follow instructions someone wrote in advance?






I welcome your comments via LinkedIn or Twitter (@rfchambers).