Forrester’s “AI Agents For Marketing Are Here: Are You Ready?” argues that marketers need a disciplined way to choose among a rapidly expanding set of agentic tools. Its readiness framework sorts 52 use cases into seven marketing categories, then scores each one across priority, people, process, and technology. This is a useful corrective to the idea that every possible agent should be deployed simply because vendors now offer one.
But the framework answers the easier question: can the organization implement this use case? It does not adequately answer whether an agent should be given the job in the first place.
Readiness and suitability are not synonyms. A mature team with clean data, an optimized process, willing stakeholders, and a functioning technology stack may be highly ready to automate a process that creates little value. It may also be ready to automate the wrong process faster. Conversely, a low readiness score might identify exactly where a tightly bounded pilot would create useful learning. Treating readiness as a roadmap risks turning organizational capability into an implicit recommendation to spend.
The missing dimension is consequence. An agent that assembles content for human review is not equivalent to one that changes bids, selects audiences, suppresses customers, publishes claims, or arbitrates cross-channel interactions. Those systems may sit in adjacent marketing categories while carrying radically different error costs. The relevant questions are not only whether the people and process are prepared, but what the agent can see, what it can change, how far a mistake can travel, and whether the action can be reversed before a customer, regulator, or balance sheet feels it.
That distinction matters because agency is permission plus autonomy, not merely a more capable interface. OWASP describes excessive agency as a combination of excessive functionality, permissions, or autonomy that allows damaging actions when a model responds badly or is manipulated. A marketing readiness assessment therefore needs to specify identity, access scope, approval thresholds, audit logs, rollback, rate limits, incident ownership, and prohibited actions. “Technology has been piloted” says almost nothing about whether those controls exist.
The scoring mechanism introduces another problem: false precision. Priority is self-selected, while people and process maturity are often assessed by the same sponsors seeking budget for the project. A numerical output can make optimistic judgments look comparable even when teams interpret “prepared” or “optimized” differently. The score may be consistent without being calibrated. Before it guides investment, assessors need evidence standards: observed baseline performance, named owners, test results, exception volumes, documented controls, and agreement about what failure means.
Forrester rightly notes that agents require implementation, maintenance, use, and monitoring resources. Yet return on investment is not established by adding those costs to a readiness worksheet. An agent can reduce execution time while increasing review work, vendor consumption charges, data engineering, compliance effort, and the cost of handling rare but serious failures. It can also make attribution harder when several agents alter a campaign simultaneously. A business case needs an untreated baseline, incremental outcome measures, total operating cost, and a comparison with simpler automation—not just a belief that agentic functionality is delivering “meaningful value.”
Ongoing governance also cannot end at launch. The NIST AI Risk Management Framework emphasizes defined responsibilities, continuous monitoring, periodic review, and safe decommissioning. Marketing teams need the same lifecycle discipline: watch for drift, review permissions, preserve human appeal and override paths, and retire agents whose marginal value disappears.
The better addendum is to place a decision record beside the readiness score. Name the job, baseline, expected gain, authority granted, maximum tolerable loss, human owner, evidence required for expansion, and automatic stop conditions. Then compare the agent with a rules-based workflow or a better-designed manual process. Readiness can tell a company whether it is capable of deploying. Only a risk-adjusted business case can tell it whether deployment is a good decision.