This HFS Research Highlight is for CIOs and CISOs evaluating agentic AI partners on their ability to control what autonomous agents do across a fragmented, multi-vendor stack.
CIOs are increasingly discovering that data residency and compliance controls do not mitigate the risks of uninformed decision making. An AI agent does not simply hold data in a compliant location. It acts on that data, moves it across systems, and makes decisions without a human in the loop. The underlying question is how to retain control over their data once AI systems begin acting on it.
HFS data shows that this concern is real: among enterprises weighing their growing dependence on AI model vendors, data security and control are the top concerns, followed closely by vendor lock-in and loss of portability (see Exhibit 1). IT services firm Atos is addressing this by positioning its recently launched Sovereign Agentic Studios, adding the oversight, governance, and control that enterprises need before agents operate within their most important processes.
Most CIOs have run agentic AI pilots, but very few have moved them into production at scale, and the reason is rarely the technology itself. When we look at what is actually slowing enterprises down, a clear pattern emerges. Our recent Pulse study (see Exhibit 1) found that the leading barriers are not about whether AI works. They are about whether organizations can integrate agents into existing systems, find the skills to run them, trust the data, and govern what autonomous systems do. These are problems of control and coordination, not capability.

Source: HFS Research, 2026
Sample size: 202 enterprise executives
A pilot runs in a contained environment where mistakes are cheap, and oversight is manual. Production removes that comfort. The moment an agent acts on real data within a live workflow, the enterprise needs to know what the agent is doing, why it is doing so, and who is accountable when it goes wrong. Most pilots stop at exactly this point. This isn’t because the agent failed, but because the enterprise couldn’t put production-grade controls around it.
Enterprise AI does not run in one place. It runs across a stack of cloud providers, SaaS platforms, and overtly competing foundation models. Enterprises are deliberately running multi-model strategies, typically pairing a primary model with a secondary one in production. Each vendor sits in a different jurisdiction under different contractual terms and rules for accessing enterprise data.
This was already hard to govern when the challenge was simply knowing where the data was stored. Agents have now made it harder because they don’t just sit on data in a single system. They move across them, act on data in each, and make decisions based on the context given.
That shifts the risk because CIOs (incl. CISO and others) faced the traditional concern of a rogue employee sharing confidential data with a supplier. The new concern is that two agents are sharing data because their instructions told them to optimize a shared process. No human decided that. The agents worked it out on their own. Exhibit 2 shows how this unfolds across a real enterprise estate.

Source: HFS Research, 2026
Sample size: 202 enterprise executives
This is why the harder question is no longer about sovereignty in the narrow sense of data location. It is about control: knowing what every agent can reach, what it is doing, and where its decisions are taking your data.
Atos has a credible basis for playing here. The company has spent decades running technology in regulated industries, including air traffic control, defence, and critical national infrastructure. In those environments, control and accountability are the prerequisites, not a later addition. That heritage is harder to replicate than any single piece of technology.
Sovereign Agentic Studios brings process discovery, agent orchestration, cost governance, and agent security into one control layer, deployable from public cloud to fully disconnected environments. The intent is to give enterprises a single place to see what agents are doing, govern what they can reach, and hold them to defined boundaries, the exact controls that fragmented, multi-vendor deployments lack today.
One element stands out. Most enterprises run on third-party models. Through its Poolside partnership, Atos can help clients build and run their own models, on their own infrastructure, using their own data. This does not remove every dependency. It does give enterprises meaningful control over how AI operates as agents become more autonomous.
Atos has a strong positioning here. It has a relevant heritage in mission-critical environments, and Sovereign Agentic Studios is a dedicated effort to bring control to a problem that most providers still treat as a deployment exercise. But here’s the catch: the studios are still new. Early results are encouraging, and if Atos can show governance working at scale over the next year, the model becomes hard to ignore. For now, that proof is still building, and outcome-based delivery remains more ambitious than practice.
For both CIOs and CISOs, the test is simple: can the partner show what each agent is doing, govern what it can access, and remain accountable when an autonomous decision goes wrong? That is the standard worth holding any partner to, including Atos.
Register now for immediate access of HFS' research, data and forward looking trends.
Get StartedIf you don't have an account, Register here |
With the exception of our Horizons reports, most of our research is available for free on our website. Sign up for a free account and start realizing the power of insights now.
Our premium subscription gives enterprise clients access to our complete library of proprietary research, direct access to our industry analysts, and other benefits.
Contact us at [email protected] for more information on premium access.