Insights at a Glance
Application platforms are increasingly embedding a range of AI agent capabilities into their offering. While these embedded options are often less mature than stand-alone options, they may provide advantages such as contextual awareness and embedded integration with data, workflows and governance. Application leaders must decide between using the preembedded capability versus integrating a leading third-party option. This decision is further complicated by the varying maturity levels across AI agent capabilities — immature ones are likely to evolve rapidly.
Key Advice
Prioritize AI agent use cases based on business value, complexity and the maturity of both vendor-embedded and market-leading options. Then assess whether a vendor’s embedded agent functionality will remain competitive throughout the investment life cycle. Simultaneously, identify overlapping agent requirements across applications, which may warrant a single independent option for all, rather than a separate embedded approach from each application.
Core Insights
By 2027, due to application bundling of AI agent functionality, large enterprises will be operating at least four distinct AI agent platforms, each offering competing tools and features.1 Through 2027, comprehensive multivendor, multiagent governance and orchestration will remain unresolved.2
Leaders must minimize technical debt and redundant investments, while maximizing nearer-term AI solutions where needed. The capabilities and effectiveness of leading solutions outlined in this report can assist with this process.
Recommended Actions
Develop a cross-application AI agent strategy: Focus on capability sharing, governance, security and controlling agent proliferation.
Prepare for overlapping AI agent capabilities: Encourage innovation but ensure that control measures are in place.
Regularly reevaluate current vendor-embedded AI agent and best-of-breed investments: Expect significant evolution in optimal solution approach as technology and use cases evolve rapidly over the next three years.
Issue
Generative and agentic AI are bringing nine disruptive but highly useful changes to enterprise applications, enabling critical new use cases:
Autonomous AI agent capability
Conversational AI agent capability
Agent development frameworks
Agent app governance and management
Guardrail capability
Search and knowledge management (KM) capability
App-embedded AI assistant
Agent application marketplace
Each major application is embedding all or many of these nine capabilities. The overlapping functionality in each application will compete with each other and with the best stand-alone options. This creates redundancy and technical debt.
Leaders must prioritize which use cases are best addressed by embedded solutions from the application vendor and which should use a separate best-of-breed function.
Before making decisions, leaders must understand the capability, the technology maturity, and the drivers and inhibitors of maturation. Leaders must also understand what “best of breed” looks like in order to make clear comparisons with embedded functionality.
Impact
Business and application leaders must align their AI agent projects and use cases with the maturity of the underlying capability. This report assists leaders in determining the use cases for AI agents and the maturity of what is offered as stand alone. This report provides examples of best-in-class vendors.
Application vendors are embedding AI capabilities within their portfolio. For instance, Salesforce and Microsoft are preintegrating all nine capabilities outlined into their products.1 Leaders must compare the application-embedded functionality with the best-in-class stand-alone functionality.
All sourcing decisions must also be considered within the context of each enterprise’s application. For instance, RAG offers amazing use cases. However, because the data requirements for RAG embedded in CRM applications are different from those enabling RAG in ERP, the challenges must be looked at individually.
Leaders must also consider the maturity of each capability. For instance, when the functionality of even the best-in-class is still nascent, leaders should anticipate rapid evolution regardless of the sourcing option selected. This rapid evolution may favor a bundled buy over a stand-alone buy decision as either option will likely need to be changed rapidly. Such decisions ought also be considered within the context of a larger enterprise build vs. buy vs integrate framework.3
More Detail
Profiles of the AI Agent Capabilities Transforming Enterprise Applications
Each of the nine profiles contains an overview of each capability, its maturity, example vendors and recommendations for usage. Additional capability information, such as use cases and risk, are provided in the document Identify Strategic AI Agent Use Cases in Applications.
Figure 1: General Maturity of Nine Critical AI Agent Capabilities

1. Autonomous AI Agent Capability
Autonomous or semiautonomous software entities leverage AI techniques to perceive, decide, act and achieve goals within digital or physical environments.
Sample vendors:
Hyperscalers (Amazon, Google, IBM, Microsoft)
Enterprise applications (Salesforce, SAP, ServiceNow, UiPath),
Open-source-led, AI-native (Anthropic, CrewAI, LangChain, OpenAI),
N-focused (Kore.AI, n8n)
Maturity rating: Emerging
Maturity drivers:
Maturity obstacles:
Limited multiagent deployments in production
Variable capabilities and approaches to development, operations, tools, pricing and ROI
Recommendations:
Approach AI agent projects as critical learning experiences, but do not rush to production and do familiarize your teams with the risks. Even if projects fail early on, apply these lessons learned to future initiatives.
Use abstraction principles such as APIs and MCP, to integrate enterprise applications with stand-alone external AI agents.
Beware of vendor rebranding of existing functionality as agentic and AI agent. Insist on clear definition and details of underlying technology.
2. Conversational AI Agent Capability
Conversational AI agents empower applications to simulate human conversation across multiple channels and modalities, including text, voice and visual content.
Sample vendors:
Google
Kore
Salesforce
Sierra
SoundHound
NiCE Cognigy
Maturity rating: Maturing
Maturity drivers:
Agreement on the definition and best practices. Many multiagent deployments.
Hybrid architectures, combining rule-based and LLM-based capabilities, address uncertainty.
Use cases typically tied to human interactions with limited autonomy.
Maturity obstacle:
Recommendations:
When using LLM logic, ensure security and guardrail requirements are addressed.
Many conversational agent platforms offer connectors for enterprise applications. Consider using APIs or agent communication protocols, including MCP, to integrate enterprise applications with stand-alone external conversational agents.
Beware of vendor rebranding of existing functionality as “agentic” and “AI agent.” Insist on clear definition and details of underlying technology.
3. Agent Development Frameworks
Agent development frameworks assist business users to build and test applications. Increasingly, they enable basic agent development without writing formal software code, possibly using natural language or conversational assistants. Examples include no-code, low-code and coding assistants. These frameworks may be bundled with autonomous or conversational AI agent runtime capabilities.
Sample vendors:
Boomi
Google AI Studio
Microsoft Copilot Studio
Maturity rating: Emerging
Maturity driver:
Maturity obstacles:
Tools lack support for best practices and for managing applications across the full life cycle.
Lack of multiagent interoperability leads to security, governance and technical debt.
The risk of uncontrolled and unmanaged agent sprawl is a critical concern.
Recommendations:
Differentiate between projects with limited scope and broader enterprise initiatives. The latter requires stronger governance and application management.
Determine the need for integration across projects, the sophistication of the developers, and the complexity of the projects.
Consider how citizen developed agents will be shared between users and the implications for security and governance.
4. Agent Application Governance and Management
Organizations use frameworks, controls and operational practices to oversee, secure, operate and optimize the full agent life cycle within enterprise application portfolios.
Sample vendors:
Microsoft Agent 365
Boomi
Lyzr AI
OneReach
TrueFoundry
Zenity
Maturity rating: Emerging
Maturity drivers:
While the importance of AI agent governance and management is recognized, solutions remain partial and typically narrow in scope.
Homogeneous solutions for AI agent governance are early stage, but emerging. Heterogeneous solutions are still theoretical.
Maturity obstacle:
Recommendations
Define the governance and management functions that your agent applications will require before committing to a specific solution.
Define the type and level of cross-application governance needed; you may be able to leverage simpler, less complex solutions for some problems.
Agent application governance should be considered within the broader context of the enterprise AI governance cybersecurity frameworks.
5. Agent Guardrails
Agent guardrails serve as practical controls to align embedded agents with enterprise governance, business and legal priorities, and security and risk requirements.
Sample vendors:
Amazon
Active Fence
Airia
AIShield
Squirrio
Maturity rating: Converging
Maturity driver:
The definition and role of AI guardrails is clear, they operate as risk mitigation practices, though AI guardrails are often not 100% effective.
Maturity obstacles:
Best practices are established, including that the responsibility for differing guardrails varies depending on the type of risk and the business owner of the application.
Guardrails can be technically and organizationally complex to define, implement and operate. Additionally, they need to be regularly reviewed to ensure they remain effective.
Recommendations:
Work with the data and application teams and the teams responsible for applications to identify the AI risks within each application workflow.
Ensure the guardrails in use are correct and that responsibility is assigned to the right group.
Establish a method for escalating alerts for each guardrail type and for continuous monitoring and testing of the guardrails.
6. Retrieval-Augmented Generation
RAG employs a three-step process to deliver information insights:
Retrieve relevant data
Augment the data to ground the prompt
Submit the prompt to the LLM to generate a response
Sample vendors:
AWS
Coveo
Elastic
Glean
Squirro
Vectara
Maturity rating: Emerging
Maturity driver:
Maturity obstacles:
Improved RAG methods for implementing and optimizing RAG continue to enter the market, demanding new best practices.
Each step in the RAG pipeline can introduce errors and risks, making it complex to achieve success in many use cases.
Enterprise data is often not structured for RAG use cases.
Recommendations for enterprise application leaders:
RAG projects often require a multidisciplinary team with data, content and IT background.
Select the appropriate RAG architecture for your accuracy, reliability, performance and cost objectives.
Implement validation and feedback mechanisms to ensure accuracy and reliability of the RAG system.
7. Search and Knowledge Management
Modern search and knowledge management systems deliver contextually relevant insights that align with business application objectives, evolving beyond basic information retrieval.
Sample vendors:
AWS
Elastic
Coveo
Glean
IBM
Microsoft
Sinequa
Squirro
Maturity rating: Maturing
Maturity drivers:
Solutions have adapted to generative AI, their focus is shifting to information synthesis and knowledge delivery.
Providers have shifted to a blend of traditional and AI-based methods.
Maturity obstacle:
Knowledge resources, especially unstructured ones, are not ready for some AI agent use cases (e.g., for RAG applications).
Recommendations for enterprise application leaders:
Assess the relevant application data readiness and data risks for AI, specifically for your use cases.
Anticipate search and knowledge requirements to vary by agent project.
8. Application-Embedded AI Assistant (AE-AIA)
AE-AIAs are an embedded form of enterprise AI assistants. They are tightly integrated with enterprise applications. They augment and support application usage, collaboration and decision making, adapting to user or team preferences and become an integral part of the business processes.
Sample vendors:
Anthropic Claude
Google Gemini
OpenAI ChatGPT
Microsoft Copilot
Maturity rating: Nascent
Maturity driver:
Maturity obstacles:
Application vendors are seeking to embed and integrate this technology in their portfolios, or create third party connectors. Some vendors are exploring “headless” approaches where the embedded AI assistant becomes the primary user interface.
Organizations express concern about ROI, security, governance, loss of application control and unresolved legal issues.
Recommendations for enterprise application leaders:
Become familiar with EAIAs, how they work, how they can add value to your enterprise and applications.
Discuss these options with your enterprise application portfolio providers and internal IT teams.
9. Agent Application Marketplace
Agent application marketplaces facilitate the shift toward interconnected agent ecosystems, enabled by standardized protocols, frameworks, and prebuilt or customizable solutions.
Sample vendors:
Google Agent Garden
Salesforce AgentExchange
Microsoft Marketplace
UiPath Marketplace
Workday Marketplace
Maturity rating: Emerging
Maturity driver:
Maturity obstacles:
Vendor market forces and inconsistent oversight reduce credibility.
Lack of clear definitions reduces clarity. For instance, the definition of an agent vs an agent skill vs an agentic application. Lack of standards, including governance and security, reduce compatibility among offerings.
Recommendations for enterprise application leaders:
Develop enterprise strategy for how internally developed agent software can be shared with particular attention to risks associated with having software from one team picked up and used by another.
Include methods for regular review of marketplace software modules and applications.
Evaluate partnerships with domain-specific agent marketplaces.
Contributors
Tom Coshow, Ventse Derzhitski, Tristan Isles, Gary Olliffe, Justin Tung