# McKinsey Trust Survey: RAI at 2.3 — Agentic Controls Still the Lag

Times of AI Desk · 2026-03-25 · Enterprise

[https://timesof.ai/2026/03/mckinsey-ai-trust-maturity-shifting-to-agentic-era](https://timesof.ai/2026/03/mckinsey-ai-trust-maturity-shifting-to-agentic-era)

> McKinsey 2026 AI Trust Maturity Survey (~500 orgs, Dec 2025–Jan 2026): average RAI maturity 2.3 (from 2.0), but only ~30% hit level 3+ on strategy, governance, and agentic controls. Security is top barrier to scaling agents (~2/3); training gaps lead RAI blockers (~60%). Consultant survey — self-reported, not an audit.

Adoption is racing into agents; trust tooling is not. McKinsey’s proprietary cut: **average RAI maturity ticked up**, but **agentic governance is where the middle of the market still fails** — security fear as the scale brake.

**McKinsey** (published March 25; fieldwork Dec 2025–Jan 2026) surveyed ~**500** organizations with AI governance responsibility using a five-dimension RAI Maturity Model (strategy, risk management, data/technology, governance, plus **agentic AI governance/controls**). Average score **2.3** (from **2.0**). Only ~**30%** at level **3+** in strategy, governance, and agentic controls. Asia–Pacific leads; tech/media/telecom and financial services outperform other sectors. Significant RAI investment correlates with higher maturity and material EBIT impact (McKinsey).

| Signal | McKinsey finding |
|--------|------------------|
| **Top barrier to scaling agentic AI** | Security/risk (~**2/3** of respondents) |
| **Top cited risks** | Inaccuracy; cybersecurity |
| **Mitigation vs awareness** | Active mitigation lags across most risk categories |
| **Incident frequency** | ~**8%** (stable); confidence in response **declined** |
| **RAI implementation barrier** | Knowledge/training gaps (~**60%**) |
| **Accountability** | Explicit RAI ownership → higher maturity |

RAI increasingly framed as business enabler (value, efficiency, trust), not pure compliance.

## Claims vs checks

Figures are **McKinsey survey primary** — self-reported maturity, not third-party audits. Sector and regional leads are within-sample. EBIT linkage is correlational as presented. Cross-check with other RAI surveys before treating 2.3 as industry absolute.

## Limits

- Survey of governance-responsible orgs skews toward those who already care.
- “Level 3+” thresholds are McKinsey’s model, not a standard.
- Agentic-control questions are new — year-over-year comparability is partial.

## Sources

- [McKinsey: “State of AI trust in 2026: Shifting to the agentic era”](https://www.mckinsey.com/capabilities/tech-and-ai/our-insights/tech-forward/state-of-ai-trust-in-2026-shifting-to-the-agentic-era) (March 25, 2026).
- McKinsey AI Trust Maturity Model and survey methodology (~500 organizations).
- Related McKinsey analysis on agentic AI and responsible practices.
