The AI Agents Report / Full analysis / Trust and control

Trust and control

Published by Iterategy. Researched with AI agents that read each vendor’s own website. Reviewed and approved by Iterategy’s CEO. Iterategy takes no money from vendors: no product paid to be listed, and we earn nothing from these links. How we did this

Owners want to know how much access to give an AI. One asked other owners whether they would let AI into their bank accounts, payroll, invoices and books, and drew the line between letting it read the numbers and letting it change them.

Vendors mostly handle this by keeping a person’s approval on any step that cannot be undone, and they sell that approval as a feature.

  • In bill pay, a person approves the payment before the software sends it in 11 of the 12 (see Bill Pay Agent).
  • Three voice and support vendors sell protection against the same risk, the agent saying the wrong thing: one leads with a claim that it never makes things up, one guarantees a resolution rate or refunds the month, and one sells a sealed record of what the agent said that cannot be altered afterwards.

Vendors also publish limits on their own products, and those limits are lower than the marketing suggests. In support, three separately published numbers put the share a product really does handle start to finish at roughly two thirds of contacts: one advertises resolving up to 90 percent but guarantees only 65 percent, and a customer example from another vendor shows 64 to 71 percent.

The general agents go further and publish their own failure rates. One warns that its agent can be talked into the wrong thing by instructions hidden inside a web page. Another reports cutting the success rate of those attacks from 23.6 percent to 11.2 percent when the agent is running unwatched.

Browser agent vendors add their own warnings: one page is titled a trial run and recommends avoiding financial, legal and medical sites.

One costly failure came from an ad setting doing exactly what it was designed to do. One advertiser turned on the setting that lets the ad platform widen the searches an ad can appear on, for one week on one campaign, and changed nothing else. The ads showed on 955 different searches instead of 30, and 72 percent of the spend went on searches that had nothing to do with the product. Separately, an owner says he followed the AI’s advice and rebuilt his campaigns just before the month he had been counting on, and it came in as his worst.

An ad agent can spend on more searches than you can check by hand, and you see where the money went only afterwards.

The people who build these agents say what keeps them under control is plain code, the kind that does the same thing every time, rather than better instructions to the AI. Every rule on one builder’s list of what survived real use works that way. The AI proposes what to do, and the code checks the amount, the recipient, the permissions and the current state before anything that cannot be undone happens. In another builder’s account, an agent that was blocked from deleting data found a way around the block, which is why the checks have to be built carefully.

Following the rules on contacting people is a real cost, and the cheap plans do not explain it. Vendors sell consent handling and quiet hours as features you pay for. One outbound calling vendor puts compliance review on a higher tier than its entry plan. One vendor cites 224 class actions under the US telemarketing law in a single month, September 2025, against 79 a year earlier.

Cite this

Trust and control. The AI Agents Report, Iterategy, 2026. https://iterategy.com/research/ai-agents/analysis/trust-and-control/

The AI Agents Report · Iterategy How we did this · Download the data · Report a correction · What changed