The Agentic AI Roadmap: A 5-Level Maturity Model From Prompted to Autonomous

The Agentic AI Roadmap by Dr. Harish Kotadia, a five-step ascending chart showing Level 1 Prompted, Level 2 Piloted, Level 3 Governed, Level 4 Assured, and Level 5 Autonomous

The Agentic AI Roadmap is a five-level maturity model for enterprise agentic AI. It runs from Level 1, Prompted, where people use chatbots one at a time, to Level 5, Autonomous, where agents run production work under provable control. Each level is earned by institutionalizing the one below it, and each comes with one governance control an organization must have in place before it moves up. I built it for regulated environments, and I use it on every agentic AI architecture engagement I take on.

Instructions in, results out was IT. Intent in, outcomes out is agentic AI. An organization does not make that turn all at once. It matures into it, and forty years ago software engineering needed a way to talk about the same kind of maturity. The Capability Maturity Model gave it five honest levels, from ad hoc to optimizing. Agentic AI needs the same thing, and this is mine.

What the Agentic AI Roadmap measures

The roadmap does not measure how clever your agents are. It measures how reliably, and how accountably, your organization turns intent into outcomes. That is a property of the organization, not of the model. The same frontier model can sit at Level 1 in one company and Level 4 in another, and the difference is entirely in the controls around it.

I am not the only one saying a maturity model is needed. Microsoft published a five-level agentic AI adoption maturity model in 2026, also built on CMM, and Salesforce released a four-stage agentic maturity model in 2025. Both are good vendor roadmaps. Mine differs in one way that matters to a regulated lender: every level is defined by a control, and every step up has an exit gate you can audit.

The five levels of the Agentic AI Roadmap

The table below is the whole framework on one screen. The sections after it explain each level.

Level Name What is true at this level Exit gate to the next level
1 Prompted Chatbots and copilots, used one at a time, ungoverned First bounded pilot with a human in the loop and a rollback
2 Piloted Task-specific agents in pilots; discipline lives in the project Reference architecture, agent identity standard, agent registry
3 Governed One organizational way to build and deploy an agent Quantitative targets and an examiner-grade audit trail
4 Assured Agent behavior measured, attested, and defensible with evidence Closed-loop improvement and guardian agents in production
5 Autonomous The program improves itself; autonomy rises because control is provable None; this is the operating state

Level 1: Prompted

No agents in production. People use chatbots and copilots one at a time, and the value depends entirely on who is typing. The tooling is shadow IT, invisible to security, and nothing is repeatable because nothing about how a result was produced is captured. This is the agentic version of relying on heroics.

Level 2: Piloted

The first task-specific agents run in bounded pilots, touching real work under close watch. There is a defined use case, a human in the loop, and a way to roll back. But each agent is a one-off, and identity, logging, and scope differ from pilot to pilot. The discipline lives in the project, not the company.

Most enterprises are stuck here, and it is why so many agentic projects are quietly canceled. Gartner forecast in 2025 that more than 40 percent of agentic AI projects would be canceled by the end of 2027. The pilots never industrialize. In my loan origination work this is the level where a credit-decision agent works beautifully for one product line and nobody can say how to build the second one.

Level 3: Governed

Agents become an institutional asset rather than a personal craft. There is one organizational way to build one: a reference architecture, an agent identity standard, least-privilege scoping by default, standard human-in-the-loop patterns, and a registry so you know what is running. New agents are tailored from the standard, not invented from scratch, and a review gates deployment.

This is the level where the knowledge stops walking out the door with the person who built the pilot. It is also where the agentic AI harness, the layer of controls around the model, gets a named owner.


More on the Agentic AI Roadmap


Level 4: Assured

Agent behavior is measured, not asserted. You set quantitative targets, such as decision quality, escaped-error rate, drift, latency, and cost per outcome, and you use the data to know whether an agent is in control and to predict where it will land. The audit trail is complete enough to satisfy an examiner. Assurance, internal or third-party, attests to controls that already exist.

For a regulated lender, this is the first level where you can defend an agent’s decision with evidence instead of a story. The Federal Reserve, OCC and FDIC guidance on model risk management, SR 11-7, has expected exactly this kind of evidence from models since 2011. Agents do not get a pass.

Level 5: Autonomous

The program improves itself. Root-cause analysis of incidents feeds back into the reference architecture and the defaults. Guardian agents watch production agents and contain drift. Multi-agent systems operate with verified trust at every handoff, and the organization absorbs new capabilities on purpose rather than reacting to them. Autonomy goes up because control is provable, and improvement is itself a managed process.

The point most people get backward

The instinct is to treat autonomy as the absence of control. Let the agent off the leash and call it mature. The ladder says the opposite. You do not reach Level 5 by removing controls. You reach it by making control so reliable that more autonomy becomes safe, and that is why the levels are cumulative.

An organization that jumps from Piloted straight to autonomous agents has not followed the roadmap. It has skipped the work that makes autonomy safe.

How to use the roadmap

Place yourself honestly. Not where your most advanced pilot sits, but where your weakest production agent sits. Maturity is an organizational property, not a trophy from your best project.

Then advance one level at a time. If you are Piloted, the work is not a bigger pilot. It is the reference architecture, the identity standard, and the registry that take you to Governed. If you are Governed, the work is the measurement and the audit trail that take you to Assured. Skipping levels is how the cancellations happen. I wrote the longer version of this argument in my book Agentic AI, and the case for earned autonomy in Autonomy.

Frequently asked questions

What is the Agentic AI Roadmap?

It is a five-level maturity model for enterprise agentic AI: Prompted, Piloted, Governed, Assured, and Autonomous. Each level is defined by the governance controls that are consistently in place, and each step up has an exit gate that can be audited.

How is it different from an agentic AI maturity model from Microsoft or Salesforce?

The vendor models describe capability and adoption. Mine is control-first. A level is earned when the control is institutionalized across the organization, not when a single team demonstrates it. That makes it usable as an audit rubric in regulated industries.

What level are most enterprises at?

Level 2, Piloted. Of the 50 public enterprise deployments I mapped, most run task-specific agents in bounded pilots without a shared reference architecture, identity standard, or registry.

Intent in, outcomes out only holds if your organization can make that turn reliably and account for it afterward. The Agentic AI Roadmap measures exactly that. The goal is not the highest level. The goal is to know which one you are on.

Which level would your weakest production agent honestly land on?

Go deeper

© Dr. Harish Kotadia, Ph.D., All Rights Reserved, 2026.

Dr. Harish Kotadia, Ph.D., is an Enterprise AI Architect with 20+ years of IT consulting experience serving Fortune 100 clients, specializing in agentic AI systems built on Anthropic Claude, AWS Bedrock, and Google Vertex AI.

Disclaimer: This blog post is based on publicly available academic publications, vendor documentation, open standards, and news items from reputed media sources linked above. This post is intended for educational purposes, to help the enterprise agentic AI community build a shared vocabulary from public, authoritative sources. Views and opinions expressed here are my own and do not represent those of any employer or client, past or present. The analysis presented is my independent interpretation of the published sources linked above and does not constitute legal, financial, or consulting advice of any kind.


Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe to get the latest posts sent to your email.

Discover more from Agentic AI Governance | Dr. Harish Kotadia, Ph.D.

Subscribe now to keep reading and get access to the full archive.

Continue reading