Agentic AI is the loudest topic in data and analytics, and if your leadership has started asking where your team stands, a shrug is no longer an acceptable answer. BARC’s 2026 research offers a better one. In corporate performance management (CPM), one of the most natural use cases for agentic AI, the barriers organizations report have almost nothing to do with agents. This article covers the three waves and what each requires, how to run an AI readiness assessment on your team, what the organizations that reached agentic AI built first, and the urgency argument that survives a skeptical executive. We wrote it for mid-market data and finance teams, big enough that AI expectations have already landed and too small to absorb a failed two-year program.
At a Glance
- BARC’s 2026 corporate performance management research found skills gaps at 51%, distrust of results among decision-makers at 45%, and data quality at 44%. Technology ranks below all three.
- Three waves, not three product generations. Wave 3 needs everything Wave 2 needs, plus mature governance, reliable data lineage, tested access controls, and proven organizational trust in AI decision-making.
- Skipping a wave buys no time. The risk it accumulates comes due later, and it comes due in production.
- Cox Enterprises, MTN Ghana, and Unilever each built the data foundation before deploying agents, per BARC’s 2026 case studies.
- Run your AI readiness assessment against what is in production today, not what got demonstrated once in a pilot.
- The urgency case that works internally is resilience. The one that gets picked apart is efficiency.
Who this is for:

The Three Waves and What Each One Requires
BARC’s framework, presented by Kassa at the same retreat, splits AI since 2018 into three waves. The third column is the one to read closely.

| Wave | What It Is | What It Requires First |
|---|---|---|
| Wave 1, 2018 to 2022, traditional AI | Predictive ML, time series analysis, anomaly detection. AI forecasts, humans interpret and act | Usable historical data and someone who can interpret it |
| Wave 2, 2022 to 2024, generative AI | Natural language interfaces, report generation, copilots. AI assists, humans validate and direct | Clean, accessible data and comfort with AI-generated output |
| Wave 3, 2025 onward, agentic AI | Autonomous AI agents with defined roles, multi-agent orchestration. AI acts within boundaries, humans set goals and monitor | Everything Wave 2 needs, plus mature governance, reliable lineage, tested access controls, and proven organizational trust in AI decision-making |
BARC gives prerequisites for Waves 2 and 3 only. The Wave 1 row is our own extension, added so the chain reads completely.
The waves work as a prerequisite chain rather than a timeline. You can buy Wave 3 technology in any year, and plenty of teams have. What you cannot do is run it on Wave 1 data with Wave 1 governance and expect it to hold. Implementing Wave 3 on top of unresolved Wave 1 problems accumulates risk that surfaces in production, at a cost far higher than the shortcut saved.
Why Wave 3 Governance Is a Different Problem
Wave 2 governance answers a question about access: who can see what, under which conditions. That is the ground our guide to data governance principles covers. Wave 3 governance answers harder questions after the fact:
- What was this system allowed to decide?
- What did it actually do?
- How would anyone reconstruct that six weeks later, when a number in the board pack turns out wrong?
Data lineage and auditability stop being compliance artifacts and become operational requirements. An AI agent working from stale or mis-permissioned data does its damage at machine speed, and by the time a person notices, the decisions built on it have spread. A separate BARC study, Merv Adrian and Kevin Petrie’s 2026 survey of 225 data and AI leaders on unstructured data, found 28% of organizations lack lineage tracking and 33% have inconsistent or no controls for data bias. If your governance amounts to a permissions matrix and an understanding that everyone will be careful, that is a Wave 2 posture, and closing that gap starts with building a durable data foundation.
Everyone Is Selling Wave 3. Most Teams Have Wave 1 Problems
The market narrative in 2026 leaves little room for doubt. Every major vendor has an agentic AI offering, every keynote shows agents doing work that used to need an analyst, and anyone not moving toward autonomy is presumed behind.

Why Most Mid-Market Teams Get Wrong About AI. Download the full report.
BARC’s research tells a more complicated story. In that same CPM context, BARC found that 51% of organizations cite skills gaps as their primary AI adoption barrier, 45% cite lack of trust in results among decision-makers, and 44% cite data quality and availability. No technology limitation appears until further down the ranking. The figures come from Kelley Lynn Kassa’s study Agentic AI in CPM: Vision vs Implementation, presented at the BARC Data & Analytics Retreat 2026, with sample sizes between 247 and 989 depending on the question. They describe AI in corporate performance management rather than AI adoption generally, and the scopes differ slightly: BARC frames the skills gap as the primary barrier in planning and forecasting, and the trust figure as the single biggest blocker in finance functions specifically.
These Are Not Agentic AI Problems
Skills gaps, stakeholder trust, and unreliable data are foundational challenges organizations have wrestled with since the first predictive ML tools shipped. Our reading is that autonomy solves none of them and makes several worse, because errors propagate before anyone reviews them, and that most mid-market organizations are being sold Wave 3 solutions to Wave 1 problems.
If your last three AI conversations were about agents while your last three data conversations were about a broken refresh, you know the shape of the problem. Our first article covers why AI pilots stall before the model is even the problem, the same gap from the project level.
How to Tell Which Wave You Are Actually In
Most AI maturity model frameworks ask you to rate yourself across a dozen dimensions. The version below is shorter, because an AI readiness assessment that takes a full quarter is a project rather than an answer. Three questions will place your team, and they only work if you point them at the right thing first.
Run the AI Maturity Assessment Against Production, Not Pilots
The wave you occupy is defined by what runs unattended and gets used, not by what was demonstrated once to an interested VP. So the questions worth asking are what runs on a schedule right now, and what breaks when it stops.
Three Questions That Settle It
What do your production use cases do:
- Predict, generate, or act?
- Does a person validate the output before anyone acts on it?
- Could you reconstruct why the system produced a result if a stakeholder challenged it?
If your systems predict and a person interprets the result, that is Wave 1.
Add generation, with a person validating before anything ships, and you are in Wave 2.
Wave 3 begins only when the system acts inside set boundaries while people set the goals and monitor. Most teams who place themselves between Wave 2 and Wave 3 land in Wave 1 once they answer the second question honestly.
An Honest AI Readiness Assessment Points to Your Next Investment
What we see with mid-market teams is that the honest answer points at the next investment rather than the aspiration. A team in Wave 1 with Wave 3 budget approval has a sequencing problem, not a funding one, and sequencing is cheaper to fix.
What the Teams That Reached Agentic AI Did First
BARC’s 2026 case studies include three organizations that got agentic AI working. Not one started there.
Cox Enterprises replaced fragmented reporting systems with a single source of truth serving 587 finance users, and only then deployed AI agents for financial analysis. The sequencing matters more than the headcount. What we take from that ordering is that the agents arrived to one set of numbers the finance function already recognized, rather than producing figures three teams could argue about.
MTN Ghana came at it from the workflow side, automating manual processes and cutting consolidation from hours to minutes before introducing real-time AI retrieval.
Unilever cleaned and structured its planning data and reduced friction in the planning logic before moving to AI-assisted analysis. The unglamorous work came first, the AI last.
BARC’s finding across all three: the agentic capability was the last mile and the reward for getting the foundation right, not the starting point. Governance ran throughout each program rather than being added afterward, including authenticated access, role-based permissions, auditability, and usage visibility.
Make the Resilience Argument, Not the Efficiency Argument
There is a real urgency case for AI-assisted planning, and it sits a long way from the cost-savings case vendors lead with. Geopolitical volatility, supply chain fragmentation, and trade policy uncertainty are moving faster than manual planning cycles can absorb. The organizations navigating that well replan quickly, scenario-plan under uncertainty, and surface variance drivers near real time. AI makes that possible, but only where the data is reliable, current, and governed.
Our reading of this is that resilience is the more persuasive framing with executives who have learned to discount efficiency claims on sight. An efficiency number invites an argument about whether it is real and who gets held to it. A resilience argument is about response time to conditions they already worry about.
The urgency is real, and it argues for building the foundation faster rather than stepping over it.
Five Things to Do This Quarter
Each fits inside a quarter, and none needs budget approval to start.
- Map Your Production Use Cases Against the Three Waves: Write down what is in production and sort each item into predict, generate, or act. It takes an afternoon and usually produces one uncomfortable surprise.
- Pick the Wave 1 or Wave 2 Problem That Blocks You Most: Skills, data quality, or stakeholder trust: BARC identifies these as the top three AI adoption barriers in CPM. Turn the most acute into a project with an owner, a timeline, and a success metric rather than a standing complaint.
- Reframe the Internal Business Case Around Resilience: Speed of response to volatility, not cost savings. Rewrite the business case before the next budget conversation, because the framing does more work than the numbers.
- Define Governed Before You Define Agentic: Answer three questions in writing before scoping any autonomous workflow. What can this agent decide without human review? What triggers escalation? How do we audit what it did? A team that cannot answer those is not ready, whatever the demo showed.
- Start With AI-Assisted Rather Than AI-Autonomous: Augmented workflows, where AI surfaces insight and flags anomalies while people stay in control, build the organizational trust BARC identifies as the single biggest AI adoption barrier in finance functions. Earn it first, then take the human out of the loop, a shift our piece on chatbots to autonomous agents covers.
How ClicData Fits
Start with the 44% in BARC’s CPM research who named data quality as a blocker. That is Wave 1 work, and it is what consolidation, transformation, and validation inside one platform is for. No AI feature substitutes for it.
BARC reports the 45% trust blocker without diagnosing its cause. In our experience with mid-market teams, it traces back to competing definitions of the same metric turning up in different meetings. Centralize the definition once and point every dashboard at it, and the argument about whose revenue number is right stops happening. Our guide to modular SQL for consistent KPIs covers the SQL-side mechanisms, from database views to dbt models. In ClicData the equivalent work happens in the Data Flow module.
Anomaly detection sits in Wave 1 of BARC’s own framework, and monitoring of that kind is the safest first move for a team under pressure to show progress this quarter. It flags deviation without deciding anything, and it needs none of the Wave 3 prerequisites. In ClicData that runs through the Alert module rather than any AI feature. You define the condition as a formula, and when the data meets it the notification goes out by email, SMS, Slack, or webhook, so an overnight swing in a cost line reaches its owner before the morning review. No model decides anything, which is what keeps it inside Wave 1. Our guide to automated dashboard alerts covers designing them without creating noise.
Several of ClicData’s AI features sit on the assisted side of the line, which places them in Wave 2. Ask AI answers questions on datasets you have scoped, narrative analytics summarizes charts in plain English, and the AI formula builder drafts transformations in the Data Flow module. In each of those a person reviews the output before it drives anything, the posture the research recommends before autonomy.
Role-based access at the data layer is a Wave 3 prerequisite, and having it in place already is far cheaper than retrofitting it under deadline pressure.
Honest limitation: none of this shortcuts the governance and lineage maturity Wave 3 requires. A platform supplies capability and enforces permissions. It cannot supply organizational trust in AI decision-making, which is earned through use.
The full report, What Mid-Market Teams Get Wrong About AI, carries the four BARC studies behind these findings, the Cox, MTN Ghana, and Unilever cases in full, and the roadmaps for the two gaps this article does not cover.
Conclusion: The Waves Are a Sequence, Not a Race
Being in Wave 1 is not a failure. Being sold Wave 3 while sitting in Wave 1 is the risk, and it lands on your budget and credibility, not the vendor’s.
The teams that reached agentic AI in BARC’s research did not move faster than everybody else. They moved in order, and that order is open to any team willing to say where it really is. A mid-market AI strategy that names its own position honestly beats one built on where leadership hopes the team is.
A next step: at the next leadership conversation about agents, answer the three data governance questions out loud before anyone names a vendor. The answers tend to settle the timeline on their own.
FAQs
What Is the Difference Between Generative and Agentic AI?
Generative AI assists with content and analysis while a person validates and directs the output. Agentic AI acts within defined boundaries while humans set goals and monitor. The difference is who is in the loop when the decision is made.
hat Are the Three Waves of AI Adoption?
Wave 1, 2018 to 2022, is traditional AI: predictive ML and anomaly detection. Wave 2, 2022 to 2024, is generative AI. Wave 3, 2025 onward, is agentic AI. Each depends on what the previous wave established.
Is My Company Ready for Agentic AI?
An agentic AI readiness check comes down to three questions. Can you reconstruct why an AI system produced a given result? Do access controls hold under testing? Do decision-makers trust AI output enough to act on it? Any no means the prerequisites are missing.
What Are the Biggest Barriers to AI Adoption in Planning and Forecasting?
BARC’s 2026 CPM research puts skills gaps first at 51%, lack of trust in results at 45%, and data quality at 44%. Technology ranks below all three.
Why Do Decision-Makers Distrust AI-Generated Results?
BARC’s research reports the blocker rather than diagnosing it. Our diagnosis is that the underlying metrics usually disagree before any AI touches them. When two dashboards report different revenue, an AI summary inherits that disagreement and amplifies it.
What Does Data Governance Mean in the Context of AI Agents?
Governance for autonomy differs from access control. Access control settles who can see which data. Governing an agent means settling what it was permitted to decide, and leaving a record complete enough to reconstruct that decision later. Documentation that only describes permissions covers Wave 2.
Should We Skip Generative AI and Go Straight to AI Agents?
No. Wave 3 depends on prerequisites Wave 2 establishes, including organizational comfort with AI-generated output and the validation habits that come with it. Skipping the wave accumulates risk rather than saving time.
How Long Does It Take to Move From One AI Wave to the Next?
BARC puts no timeline on wave transitions, and the gating item is almost never procurement. What decides it is which prerequisite is still missing, because the technology itself is available immediately. In our experience the work that takes real time is data quality and governance. Mid-market teams tend to close that gap faster than enterprises, because there are fewer systems to reconcile and a shorter distance between the people who own the data and the people who need it.



