TL;DR
- IDC reports that enterprises now allocate an average of 16.7% of total planned AI spending to AI and agent security and governance, from its Future Enterprise Resiliency and Spending Survey, Wave 10, fielded in January.
- IDC ties the figure to its forecast that by 2030 up to 20% of G1000 organisations will face lawsuits, substantial fines or CIO dismissals over inadequate agent controls, while 45% orchestrate agents at scale.
- For anyone building audit trails, access control, agent observability or incident readiness, the budget line already exists, so the problem no longer has to be explained before the product is discussed.
- One caveat: the 16.7% figure will be set against the 6% Arkose Labs figure from April as if funding had tripled, and the two measure different denominators.
In plain English
“Agent governance” here means the controls placed around software agents that act on a company’s systems: records of what an agent did (audit trails), limits on what it can open (access control), monitoring of its behaviour while it runs (observability), and a plan for when it goes wrong (incident readiness). IDC’s survey asked what share of planned AI budget goes to that category, and got 16.7%.
The comparison trap is about denominators. The Arkose Labs survey of 300 enterprise security leaders measured a share of the security budget, and found 6%. IDC measures a share of the AI budget. Different questions, different survey populations, so one organisation could report both figures at once with neither being wrong. A budget allocation also records an intention; Schellman found that 90% of organisations have AI governance funding while 27% call their programmes fully mature.
IDC published a blog yesterday arguing that agent governance has become a core AI investment rather than an afterthought, and it carries a number worth holding on to: enterprises now allocate an average of 16.7% of their total planned AI spending to AI and agent security and governance. That comes from IDC’s Future Enterprise Resiliency and Spending Survey, Wave 10, fielded in January. IDC’s own framing is that this puts governance at near parity with the other core layers of the AI stack.
That’s the useful part. Governance has moved out of the closing slide and into the spend, and a number attached to a budget line behaves differently in a planning meeting than a principle does.
IDC ties the shift to a prediction from its FutureScape research, published back in October 2025: by 2030, up to 20% of G1000 organisations will have faced lawsuits, substantial fines, or CIO dismissals over high-profile disruptions caused by inadequate controls and governance around AI agents. Set against IDC’s other forecast that 45% of organisations will be orchestrating agents at scale by 2030, the governance spend stops looking like caution and starts looking like the cost of being allowed to do the thing at all.
Now the caveat, because I wrote the other half of this story in April and I’d rather flag the trap than let anyone walk into it.
In April I covered an Arkose Labs survey of 300 enterprise security leaders that found 97% expecting a serious AI-agent security incident within twelve months while only 6% of security budgets were allocated to that risk. Those two numbers, 6% and 16.7%, are going to end up in the same slide before long, presented as governance funding having nearly tripled in four months. They don’t support that reading. Arkose measured a share of security budget. IDC is measuring a share of AI budget. Different denominators, different survey populations, different questions. An organisation could produce both figures simultaneously without either being wrong.
What the IDC number does establish is narrower and still worth having: agent governance is now a recognised line item that vendors can sell into and buyers have already provisioned for. If you build tooling around audit trails, access control, agent observability or incident readiness, you’re no longer explaining why the problem exists before you can talk about your product.
What it doesn’t establish is whether any of that money is buying working controls. A budget allocation is an intention. Schellman’s survey this week found 90% of organisations have funding for AI governance and 27% describing their programmes as fully mature, which is the same distance between spending and doing, measured from the other end.