The real bottleneck in India's agentic AI race isn't the AI

Walk into any large Indian enterprise today and you will find an AI agent somewhere in the workflow. A loan underwriting bot reading documents. A customer service agent triaging tickets. A procurement agent reconciling vendor records against purchase orders. According to EY's AIdea of India 2026 survey, 24% of Indian business leaders say they are already running agentic AI in production, not pilots. That number will only grow through the rest of this year. What is harder to find is a straight answer to a simpler question: Does the agent have access to trusted enterprise context?
The Governance Gap Behind the Headlines
Ask that in most boardrooms and the energy in the room shifts. The same EY survey found that 64.5% of Indian enterprises rate data governance and security as a "very severe" challenge, and 78% are still wrestling with basic system integration. Our CDO Insights research, which surveyed 600 data leaders worldwide, reveals a similar trend: more than half of the respondents say poor data reliability is what keeps AI projects stuck in pilot mode. Those who are building agentic AI specifically, data quality tops the list of obstacles.
The pattern is clear: as agent adoption scales, ungoverned data doesn't just slow things down — it multiplies risk.

Why the Old Playbook Doesn't Work
For years, enterprise data lived behind a dashboard - accessible, but mediated. A person logged in, ran a query, used their judgement, and took action. That workflow relied heavily on a human-in-the loop at every step, someone to spot a stale record, a duplicate customer ID or a missing consent flag before it could impact business outcome. Agentic AI removes that manual pause. Without clean, governed data as the foundation, that speed becomes the liability.
Headless Data Management

That's precisely why a growing number of organisations, in India and elsewhere, are rethinking how data capabilities get delivered. Most governance, quality and metadata tools have always worked the same way: a person opens a dashboard, reviews what is there, and decides.
Headless data management breaks that assumption. The capability - a governance rule, a quality check, lineage and access rights - no longer lives behind a screen. It becomes a callable service. Governed, reusable, and available to any system, including an agent, directly the moment it needs it. . It is the same shift e-commerce and open banking went through years ago, when product data and account data stopped being locked inside a single interface and became something any application could plug into securely.
This matters for reasons that go beyond convenience. When governance only exists inside a platform a person has to open, it is simply not there the moment an agent needs it, which is exactly the trust gap the numbers above point to. Once data capabilities are made headless, the governance controls, quality standards, and contextual metadata travel with the data itself. So an agent underwriting a loan or reconciling a vendor invoice can act on trusted context - data that is well-governed, understood, and AI-ready - and not merely data it happens to reach first.

This is precisely why industry standards such as the Model Context Protocol have gained rapid adoption, giving agents a consistent, scalable way to discover and invoke data services without the need to rebuild existing architectures or develop fresh integration code for every new use case.
India's Compliance Clock Is Already Running
India's regulatory environment is making this shift considerably less optional than it looks from the outside. The RBI's FREE-AI framework, released in August 2025, expects regulated entities to maintain board-approved AI policies, appropriate model audit trails, explainability and meaningful human oversight over autonomous decision-making. None of that is achievable unless an AI agent operates on data whose lineage, sensitivity or consent status can be verified in real time.

The Digital Personal Data Protection (DPDP) Rules 2025 further increase the urgency. With the formal 18-month compliance runway ticking toward the May 2027 deadline for substantive data fiduciary obligations, the architecture must be built now. Assuming the notified implementation timeline remains unchanged, organisations should use the transition period to build compliant governance and technical controls well before the substantive obligations become applicable.
An autonomous agent that processes personal data without being able to verify in real time whether consent for that specified purpose remains valid isn't simply a future compliance risk. Under the DPDP framework, any use of data without a valid legal basis or beyond consented purposes is a violation the moment it occurs.
Appetite Isn't Infrastructure

India's appetite for agentic AI is real. About 85% of Indian technology services providers are now running agentic AI platforms, and nearly a quarter have moved AI projects from experimentation into production - with industry estimates pointing to a $400 billion opportunity ahead, according to Nasscom. The EY AIdea of India 2026 survey puts 24% of enterprises already in AI production - reinforcing that deployment pace is accelerating fast.
But deployment phase is not the same as deployment readiness. Governance, quality and context cannot be afterthoughts. They need to be designed into the data layer itself and made available everywhere an agent might call on it, rather than bolted on after something has already gone wrong.
The agents are already in the room - across boardrooms, contact centres and back offices. The harder question every enterprise should be asking now isn't whether to deploy more of them. It's whether the data being handed to those agents actually deserves the trust being placed in it.

Gaurav Pathak
Gaurav Pathak, Senior Vice President, Metadata and AI Products at Informatica from Salesforce
