
Ask most leadership teams where their organisation sits on the AI adoption curve, and the answer is usually more confident than the data supports. ServiceNow's Enterprise AI Maturity Index found that 59% of enterprises report using agentic AI in some form, yet only 9% have made meaningful progress on genuinely autonomous, multistep workflows. The gap between "we are doing agents" and "we have handed a workflow to one" is where most companies actually sit, and knowing which side of that gap an organisation is on matters, because the human oversight a business needs changes completely at each stage.
Enterprise AI adoption tends to move through three distinct stages: chat, connected-but-prompted agents, and autonomous agents. From a distance, each stage looks similar, an employee is interacting with something called "AI." Up close, the risk profile, and the human checkpoint required, are entirely different.
At a Glance
- Most organisations assume they are further along the AI maturity curve than they are. A chatbot licence is not agent maturity, and a deployed agent is not autonomy.
- AI adoption moves through three stages, chat, connected-but-prompted agents, and autonomous agents, and each stage carries a different oversight requirement.
- Gartner projects 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from under 5% in 2025, but true autonomy adoption is uneven and lowest in the most regulated sectors.
- Article 14 of the EU AI Act still makes human oversight of high-risk AI systems a legal requirement, not a best practice, even though the compliance deadline for these obligations has been pushed back from August 2026 to December 2027.
- Heed is not an agent platform. It sits at the accountability checkpoint inside stage three, the guaranteed-delivery, identity-bound, audit-trailed layer that keeps autonomy provably safe.
Table of Contents
Stage one: chat
At the first stage, employees are using general-purpose AI as a smarter search box. Someone opens ChatGPT, Copilot or Claude, asks a question or requests a draft, and copies the answer into whatever they were already working on. There is no connection to company systems, no memory of previous requests, and nothing the AI does persists beyond that single exchange.
This is genuinely useful, and for most organisations it is where AI adoption began. It is also the stage most commonly mistaken for progress. Buying licences for every employee, or watching usage numbers climb, measures activity, not maturity. A workforce that has adopted ChatGPT as a writing aid has not adopted an AI strategy. It has adopted a better keyboard.
Stage two: connected, but still prompted
At the second stage, a company builds or deploys an agent that is wired into its own systems, a ticketing platform, a CRM, an internal comms tool, so it can work from real data rather than a blank prompt. It can draft a report, summarise a thread, or produce a first pass at a document. Crucially, a person still has to ask it to do something, and a person still reviews the result before anything leaves the building.
This is where most regulated enterprises legitimately sit today, and it is a defensible place to be. Heed's own AI-generated notification feature is a deliberate example of stage two design. Someone types a plain-English description, a major incident affecting a core system, for instance, and the service drafts a notification with an appropriate tone, priority and audience. Nothing sends until a person reviews and approves it. The agent is genuinely useful and genuinely connected to context, but the human decision has not been removed from the loop. It has just been made faster to reach.
Stage three: autonomous, and where trust breaks
At the third stage, the agent stops waiting to be asked. It monitors a system, makes a decision, and acts, inside a workflow, end to end. An operations agent notices an anomaly and triggers the next step in an incident process. A security agent investigates an alert and runs a response playbook. Nobody typed a prompt for that specific action. The agent decided it was needed.
This is the stage most current AI investment is aimed at. Gartner projects that 40% of enterprise applications will feature task-specific AI agents by the end of 2026, up from under 5% in 2025, a genuine step change in how software behaves, not just how it is marketed. But adoption of true autonomy is uneven, and the pattern is telling. Roughly 31% of enterprises have at least one agent in production, with banking and insurance leading at 47%, while healthcare sits at 18% and government at 14%, sectors where the constraint is not what the technology can do, it is audit, explainability and accountability.
That unevenness is not caution for its own sake. It is what happens when an organisation reaches the point where an AI system can take a consequential action without being asked, and realises it cannot yet answer a simple question: if this goes wrong, who was responsible, and can the business prove a qualified person was aware?
The governance gap regulators are now enforcing
That question is no longer optional to answer. McKinsey's AI Trust Maturity Survey found that only around 30% of organisations have reached a governance maturity level that matches their level of AI autonomy, and the shortfall concentrates in exactly the industries with the most to lose, healthcare, financial services and government among them.
Regulation is catching up with that reality, even if the timeline has moved. Article 14 of the EU AI Act requires that high-risk AI systems be designed so a natural person can properly understand, monitor, correctly interpret, override and stop the system while it is in use. Those obligations were originally due to take effect on 2 August 2026, but the EU's Digital Omnibus on AI, which entered into force in July 2026, pushed the compliance deadline for standalone high-risk systems back to 2 December 2027. That is more runway, not a reprieve. The requirement itself has not changed, only the date regulators start checking for it, and the operational gap McKinsey and ServiceNow describe above exists regardless of what Brussels enforces: an autonomous agent making a consequential decision without a provable human checkpoint is a business risk before it is a compliance one.
We have written before about why Slack and email are not a reliable channel for that kind of decision, and the same principle holds here at a strategic level. An approval step that exists on a workflow diagram is not the same as a human checkpoint an auditor can actually verify happened. For organisations operating in healthcare, financial services, or the public sector, that distinction is heading towards a hard compliance requirement, and worth building for now rather than waiting for the deadline to force the issue, particularly given Heed's own work in compliance communications.
Where the human checkpoint belongs
Heed is not an agent platform, and it is not trying to be one. It sits at the point where an autonomous workflow needs a human decision, an approval, an escalation, a stop-the-line call, and makes that moment guaranteed to be seen, tied to a named identity, and provable afterwards. An agent calls a webhook, Heed delivers the request as a desktop, mobile or signage alert that cannot be missed the way a Slack message can, the decision is logged against the approver's identity with a timestamp, and the result flows back into the agent's workflow through the same API that triggered it. On-premises deployment keeps that decision, and the data behind it, inside the organisation's own infrastructure, which matters as much to an Article 14 assessment as it does to a security review.
None of the three stages above is a problem on its own. Chat is fine. Prompted agents are fine. Autonomy is fine, provided the organisation has built somewhere for the decision to land when the agent reaches the edge of what it should decide alone. Climbing the maturity curve is not about removing humans from the process. It is about moving them to the one point that has to be provable, and building infrastructure that treats that point as seriously as the AI sitting either side of it.
See how Heed adds a guaranteed, audit-ready checkpoint to AI-driven workflows, across desktop, mobile and shared screens. Book a Demo







