AI agents in the mid-market, eighteen months on
What actually changed between the agent announcements of late 2024 and practice in mid-sized companies in 2026: where agents landed, the integration layer that made them possible, and the failures reported.
Contents
Between the agent announcements of late 2024 and mid-market practice in 2026, most of the movement happened in one layer: integration. Agents landed in IT, knowledge retrieval and internal workflows rather than in customer-facing roles. The failures companies report are about permissions, data quality and unclear value, not model capability.
Key takeaways
- McKinsey surveyed 1,993 respondents in mid-2025 and found 62% at least experimenting with agents, 23% scaling them in at least one function, and no single function above 10%.
- Gartner predicted in June 2025 that more than 40% of agentic AI projects would be canceled by the end of 2027, citing cost, unclear value and weak risk controls.
- The Model Context Protocol moved to the Linux Foundation's Agentic AI Foundation on 9 December 2025, with more than 10,000 published servers.
- AI use in Spanish companies with 10 or more employees reached 21.1% in the first quarter of 2025, up 8.7 percentage points in a year.
- OWASP published a Top 10 for agentic applications in December 2025, led by behavior hijacking, tool misuse and privilege abuse.
What was actually announced in late 2024
The announcements were about connection, not autonomy. Anthropic published the Model Context Protocol on 25 November 2024 as an open standard for connecting assistants to the systems where data lives. Block, Apollo, Zed and Replit were early adopters.
The problem it addressed was mundane and expensive. Every data source needed its own implementation, so integration cost grew with the number of systems rather than with use cases.
That is the part that held up. The demos of autonomous agents booking travel aged badly; the plumbing underneath them became infrastructure.
Where agents actually landed
McKinsey surveyed 1,993 respondents across 105 countries in mid-2025 and published on 5 November 2025. It put 62% of organizations at least experimenting with agents and 23% scaling them in at least one business function. No individual function passed 10%.
IT and knowledge management led adoption. That is the honest shape of it: agents landed where the work is internal, the data is already structured, and a wrong answer is caught by whoever asked.
Financial results stayed modest. In the same survey, 39% reported any EBIT contribution from AI, and most attributed less than 5% of it. Read that beside what to ask before approving an AI budget.
McKinsey's Global Survey on AI was fielded between 25 June and 29 July 2025 with 1,993 respondents in 105 countries. It found 62% of organizations at least experimenting with AI agents and 23% scaling them in at least one function (McKinsey, 5 November 2025).
The integration layer that made it possible
The decisive event was governance, not capability. On 9 December 2025 the Linux Foundation formed the Agentic AI Foundation, with MCP contributed by Anthropic, goose by Block and AGENTS.md by OpenAI. Platinum members include AWS, Cloudflare, Google, Microsoft and OpenAI.
More than 10,000 MCP servers had been published by then. For a mid-sized company, connecting an assistant to a CRM or a ticketing system stopped being a bespoke project.
It also moved the risk. When connection is cheap, the hard question becomes what the agent may change, the subject of giving an agent write access to your CRM.
The failure modes companies report
Three appear consistently, and none is the model.
The first is procurement. Gartner reported in June 2025 that of thousands of vendors claiming agentic AI, roughly 130 genuinely offered it. It predicted that more than 40% of agentic projects would be canceled by the end of 2027, on cost, unclear value and inadequate risk controls. The build, buy or wrap question in three ways to add an AI capability is the first filter.
The second is permissions. OWASP's Top 10 for agentic applications, released in December 2025, is led by agent behavior hijacking, tool misuse and privilege abuse. The project frames the shift plainly: LLM security addressed single model interactions, agentic security addresses what happens when models plan, persist and delegate across systems.
The third is the connector itself. A threat model published in March 2026 identified tool poisoning as the most critical client-side weakness. The term describes malicious instructions embedded in tool metadata, and the study found insufficient static validation across seven major MCP clients.
OWASP's GenAI Security Project released its Top 10 for agentic applications in December 2025. Agent behavior hijacking, tool misuse, and identity and privilege abuse lead the list (OWASP GenAI Security Project, December 2025).
What the Spanish and EU picture looks like now
Adoption is rising and still minority. The INE reported on 22 October 2025 that 21.1% of Spanish companies with 10 or more employees used AI in the first quarter of 2025. That is 8.7 percentage points higher than a year earlier. Services led at 25.7%, industry at 17.5% and construction at 11.4%. Eurostat put the EU figure at 20.0% for 2025, against 13.5% in 2024.
The rulebook is in motion. The European Commission proposed its Digital Omnibus on 19 November 2025. It adjusts the timeline for high-risk AI obligations to a maximum of 16 months, tied to the availability of standards. The Commission estimates up to €5 billion in administrative savings by 2029. The dates in the EU AI Act timeline are a moving target rather than a settled calendar.
FAQ
Are AI agents working in mid-sized companies yet?
In narrow places, yes. McKinsey found 23% of organizations scaling agents in at least one business function by late 2025, with IT and knowledge management leading the list. Customer-facing autonomy remains rare, and internal assistance with a human reviewing the output is the common pattern.
Why did the integration layer matter more than the models?
Because integration was the cost. Before a shared protocol, each data source needed a custom connector, so effort grew with the number of systems. MCP reduced that to one interface, and by December 2025 more than 10,000 servers had been published against it.
What should a mid-sized Spanish company do first?
Inventory what the agent would touch, then decide read or write per system before choosing a vendor. The useful early cases are read-only retrieval across existing records, the same dependency described for AI features inside a CRM.
Start read-only, log every action, and grant write access only where a wrong change is reversible and visible. Treat a vendor's agentic claim as unverified until it names the protocol, the permission model and the audit trail. Within six months the EU timeline should be settled enough to plan against, and the research on connector security will show whether tool poisoning stays theoretical.



