AI agent adoption soars, governance gap sparks security crisis

Venture Beat

The gist

Enterprises raced to deploy autonomous AI agents, but a massive governance gap has triggered a security crisis—exposing organizations to breaches, regulatory backlash, and operational chaos.

What to know

  • By late 2025, over 90% of enterprises used autonomous AI agents, but only about 10% had proper governance frameworks, leaving legacy IAM systems woefully unprepared.
  • A major ServiceNow flaw in January 2026 let AI agents impersonate users without MFA, sparking federal action and a NIST push for new cryptographic AI identity standards.
  • By mid-2026, shadow AI agents with excessive privileges surged 56% and 97% were poorly managed, while only 25% of organizations had formal AI security governance in place.

Legacy IAM Falls Short

The explosive rise of autonomous AI agents exposed critical security blind spots as legacy identity systems failed to govern non-human actors, forcing CISOs to confront invisible privilege creep and untraceable agent actions.

By late 2025, enterprises had rapidly embraced agentic AI, with over 90% deploying autonomous AI agents, yet only about 10% had established governance frameworks to control them. As Jack Hirsch highlights, this explosive adoption outpaced the development of adequate identity and security strategies, leaving organizations vulnerable to unmanaged AI behaviors running amok. Traditional human-centric IAM models proved ill-suited for this new reality, exposing critical gaps in visibility and control that CISOs struggled to address.

The core challenge lay in the fundamental mismatch between legacy IAM systems designed for human users and the unique nature of AI agents, which act as distinct digital identities requiring separate management. Hirsch emphasizes that AI agents 'are identities any way you try to describe them, but they can't be described in the same terms as humans,' complicating authorization since current methods rely on static credentials or OAuth grants that either lack governance or shift control to end users. This inadequacy sparked public criticism from security leaders like the CISO of JP Morgan Chase, who decried the SaaS ecosystem’s failure to provide proper guardrails for secure AI deployment.

The early enterprise experience revealed that treating agentic AI as mere software features invited risks such as invisible privilege creep and untraceable actions, since these agents behave like users—authenticating, assuming roles, and calling APIs. Traditional static access grants and one-time approvals were insufficient, necessitating a paradigm shift toward continuous, runtime policy evaluation to maintain security. This evolution underscored the urgent need for a new identity control plane where each AI agent is a first-class citizen with unique, verifiable identities linked to human owners, specific business use cases, and software bills of materials, as articulated in November 2025 analyses.

Beyond technical challenges, the rapid agentic AI adoption raised profound accountability questions, as AI agents granted broad permissions could autonomously act on behalf of users, amplifying risks if compromised. Discussions emerged about treating AI agents as separate digital personas requiring distinct tracking and governance frameworks to assign permissions and ensure accountability. This early phase mirrored cloud adoption struggles like misconfiguration and scope creep, yet even well-configured AI systems remained vulnerable due to inherent human flaws in design and oversight, highlighting the complex governance gap enterprises faced.

Sources
SiliconANGLE theCUBEVenture BeatCyberWire Daily

AI Agents Challenge Trust

A major ServiceNow breach and flawed static identity models revealed that AI agents require cryptographic, context-aware controls as traditional permissioning and accountability mechanisms break down in dynamic, multi-party environments.

By late 2025, the rapid enterprise adoption of AI agents exposed fundamental security vulnerabilities around authentication and authorization, as illustrated by A16Z partner Joel de La Garza’s example of agents improperly returning data across companies. Experts like Ian Livingston emphasized that traditional static identity models and group-based permissions are inadequate for the dynamic, contextual access control required in multi-party AI agent environments, necessitating new guardrails that can deterministically enforce what an agent can access at any given time.

The emergence of AI agents acting autonomously on behalf of users introduced complex identity and accountability challenges, prompting questions about whether agents should be treated as distinct digital personas. As articulated in late 2025 analyses, governance frameworks struggled to track and attribute agent actions separately from humans, with risks compounded by misconfigurations and inevitable human errors, echoing early cloud security lessons and underscoring the need for explicit permission scopes and accountability mechanisms.

The critical security flaw disclosed in January 2026 in ServiceNow’s Now Assist AI Agents, which allowed attackers to impersonate any user and bypass MFA and SSO controls, starkly underscored the urgency for cryptographic identity verification in AI agents. This incident catalyzed federal attention, with NIST launching a targeted Request for Information to develop concrete security guidelines for autonomous AI systems, marking a pivotal shift from general chatbot concerns to the unique risks posed by agentic AI.

By mid-2026, the proliferation of shadow AI—unauthorized AI agents operating with corporate credentials—had become a widespread and largely invisible security threat, dramatically expanding the non-human identity attack surface. Research revealed alarming statistics: a 56% increase in non-human identities within a year, with 97% having excessive privileges and poor token management, highlighting the failure of traditional identity protocols like OAuth and SAML to govern continuously authenticating, dynamically delegating agents. This sprawl, combined with high-profile incidents and regulatory acceleration—including a June 2026 executive order making AI-enabled data access a federal enforcement priority—exposed a glaring governance gap, with only a quarter of organizations having formal AI security governance and most lacking audit trails or accountability structures.

Despite near-universal experience of disruptive AI agent-related incidents—98% of organizations reported such events by mid-2026—enterprises continued to deploy agents faster than security teams could govern them, resulting in limited visibility and control. This disconnect was compounded by inadequate cybersecurity controls ill-suited to AI’s novel risks, with organizations focusing more on prevention than response, even as adversarial attacks like prompt injections surged. The governance gap was further exacerbated by widespread shadow AI use and the absence of cryptographic identity and accountability mechanisms, making it difficult to track agent actions at machine speed and increasing exposure to regulatory fines, supply chain disruptions, and reputational damage.

The rapid deployment of AI agents in mid-2026 compressed years of governance challenges into weeks, as major labs launched persistent virtual machine agents and enterprise platforms at breakneck speed. Nvidia’s AI Red Team documented recurring security failures—such as inadequate access control and plaintext secret exposure—highlighting a generational loss of institutional memory. Their conclusion that prompt-based defenses are ineffective underscores the urgent need for deterministic architectural controls like sandboxing and network egress restrictions enforced outside the AI model’s control plane, a demand that regulatory frameworks like DORA and NIS 2 are only beginning to address.

By August 2026, AI agents were often activated by default within enterprise systems before any governance rules were established, effectively making the absence of explicit permission and data-access policies a de facto governance decision. This ungoverned agentic AI use significantly increased breach costs—IBM research cited an additional $670,000 per incident linked to shadow AI—and underscored the critical need for organizations to inventory all autonomous agents and impose explicit access rules. Treating these agents as live systems requiring active governance became an urgent imperative to close the shortest fuse in AI risk management.

Sources

Security-By-Design Goes Mainstream

Enterprises and vendors are racing to embed security into every layer of agentic AI, shifting governance from afterthought to core design principle with cryptographic identities, immutable audit trails, and real-time runtime controls.

The evolution from simple chatbots to autonomous agentic AI has driven a fundamental redesign of enterprise security and governance frameworks, emphasizing security-by-design as a prerequisite for productivity rather than a trade-off. As Jeetu Patel highlighted in late 2025, embedding runtime guardrails and integrating security deeply into CI/CD pipelines ensures that model validation against toxicity, jailbreaks, and prompt injections becomes an intrinsic part of product development, fostering trust and scalability in AI deployments.

Traditional human-centric identity and access management (IAM) systems have proven inadequate for the scale and autonomy of agentic AI, prompting the emergence of new identity control planes that rely on cryptographic authentication, session-based permissions, and continuous, context-aware authorization. Experts like Mrinal Wadhwa and industry analyses from late 2025 to mid-2026 underscore the necessity of unique, verifiable agent identities linked to human owners and business use cases, with embedded purpose-bound data access policies and immutable audit logs to ensure accountability and prevent misuse.

By early 2026, leading vendors and enterprises accelerated the development of multi-layer governance platforms tailored for agentic AI, exemplified by Varonis’ acquisition of AllTrue.ai to integrate AI Trust, Risk, and Security Management, Palantir’s Agentic Runtime framework addressing five critical security dimensions, and Operant AI’s Agent Protector offering real-time discovery and zero trust enforcement. These solutions collectively emphasize identity management, policy enforcement, observability, and runtime controls, reflecting a convergence of safety and security at the deployment layer to manage the unique challenges of autonomous agents.

Despite rapid agentic AI adoption in 2026, governance frameworks lag significantly, with only 11% of enterprises fully prepared for large-scale deployment, as IBM and OWASP reports reveal. This gap has led to calls for shifting from rigid gates to flexible guardrails, establishing unified AI agent registries, and adopting proportional governance strategies tailored to agent autonomy levels. Industry leaders like Microsoft with Agent 365, Salesforce’s Agentforce, and ServiceNow’s AI Control Tower are responding by building integrated governance ecosystems that prioritize identity, least-privilege access, auditability, and cross-vendor interoperability, while global initiatives such as the World Artificial Intelligence Cooperation Organization aim to harmonize international standards amid escalating security incidents and vulnerabilities.

Sources
DGThe AI-Native Product TeamVenture BeatResilient CyberResilient CyberGlobeNewswire - Industry News on Technology

The Governance-Adoption Gap Widens

Soaring AI agent deployments—often unsanctioned and poorly monitored—have far outpaced formal governance, leaving most organizations exposed to operational drift, shadow agents, and a widening trust deficit.

Enterprise adoption of agentic AI has surged dramatically, with AI applications cataloged growing 250% within five months and nearly three-quarters of companies planning deployments within two years, yet governance maturity lags significantly. This rapid expansion—from early pilots to managing complex multi-agent teams as seen with platforms like Claude Opus 4.6 and OpenAI’s Frontier—has outpaced traditional security frameworks, leaving only about 25% of organizations with comprehensive AI security governance and creating a critical gap between adoption and operational controls.

The complexity of securing autonomous AI agents demands a fundamental rethink of identity, access, and threat modeling beyond traditional human-centric approaches. Experts emphasize that agent security must be architected from the ground up, integrating continuous runtime security, posture management, and real-time observability, as exemplified by Operant AI’s Agent Protector which provides zero-trust enforcement and rogue agent detection. This shift recognizes agents as non-human identities with distinct permissions and audit trails, requiring new protocols like OAuth 2.1, SPIFFE/SPIRE, and emerging Agent Protocol standards to manage their broader threat surface effectively.

Despite growing enterprise confidence in AI agent visibility, actual monitoring and governance controls remain insufficient, with operational drift and lack of formal accountability prevalent. For instance, TechCrunch reports that while AI agent deployments doubled in four months, only about 9.5% of organizations secure more than 80% of their agents, and 85% lack formal accountability structures. This disconnect is compounded by bottom-up, often unsanctioned agent use—29% of employees reportedly use AI agents without formal approval—highlighting the urgent need for explicit permissioning and governance policies to close the trust gap before risks escalate.

Scaling agentic AI adoption safely in enterprises hinges on treating AI agents as integral infrastructure rather than mere applications, necessitating investments in data quality, unified platforms, and network transformation to support real-time, distributed decision-making. Organizations ahead in readiness prioritize continuously refreshed data pipelines, strict access controls, and interoperability to avoid vendor lock-in, as underscored by Fivetran and IOH’s emphasis on high-quality data and TM Forum-aligned governance frameworks. This infrastructure-centric approach enables the transition from experimental agents to reliable digital employees orchestrating workflows with embedded accountability and auditability.

Sources
☁️ The Cloud Security Guy 🤖CyberWire DailyVenture BeatStudioAlphaResilient CyberGlobeNewswire - Industry News on Technology

Operational Governance Takes Center Stage

Enterprises are embedding real-time human oversight, layered identity controls, and explicit accountability into AI agent lifecycles, transforming governance from a compliance checkbox to a business-critical discipline.

As enterprises rapidly scale agentic AI from experimental pilots to core infrastructure, integrating human-in-the-loop controls and embedding governance into the AI lifecycle have become imperative to manage escalating operational risks. Industry leaders like Google CISO Phil Venables emphasize the need to 're-tool everything for speed' in security operations to counter attacks that now unfold in seconds, while Phil Windley advocates for continuous authorization within the agent loop, shifting from one-time gatekeeping to runtime policy enforcement. Frameworks such as the three-layer model—covering Tool, Cognitive, and Identity layers—highlight the complexity of governing autonomous agents, especially as non-human identities dynamically spin up and down, requiring robust identity resilience and real-time observability to maintain accountability and prevent catastrophic outcomes.

Operationalizing AI governance demands clear accountability frameworks with explicit human ownership of AI agent actions, as regulatory scrutiny intensifies. Analysts stress that organizations must define who is responsible when agents perform tasks—be it marketing, IT, or vendors—and prepare documented, tested incident response plans tailored to AI-specific scenarios, exemplified by OpenClaw's credential rotation and Perplexity Computer's session termination protocols. The June 2026 executive order further mandates maintaining governance records that attribute AI data access to human decision-makers, yet studies reveal significant gaps, with only 12.4% of companies ensuring human oversight policies and 63% unable to enforce purpose limitations, underscoring the urgency of embedding operational controls and audit trails into AI lifecycle management.

The transition from AI experimentation to infrastructure transformation is reshaping governance from a compliance checkbox into a front-line operational discipline. Enterprises like Indosat Ooredoo Hutchison demonstrate that embedding governance into AI lifecycle management—through robust data governance, multi-agent orchestration, and human-in-the-loop checkpoints—yields measurable business value such as 20% reductions in incident response times and 30% efficiency gains. This shift is echoed by Satya Nadella’s 'Agent 365' system, which inventories agents for full auditability and enforces runtime asserts to constrain agent behavior, and by TM Forum-aligned frameworks that embed policy enforcement and human confirmation before consequential AI actions, enabling rapid, safe scaling of autonomous operations.

Despite growing recognition of AI’s operational risks, many organizations struggle to embed governance effectively, with only 40% assigning direct responsibility for AI outcomes and half lacking tamper-proof audit trails, limiting incident response readiness. Experts like Manu Agrawal and Jay Bavisi argue that governance must be treated as a system-level design requirement, integrating identity and access management, continuous monitoring, and human oversight throughout the AI lifecycle. This approach moves beyond static policies to dynamic, risk-based controls that classify AI systems by autonomy and criticality, ensuring that human judgment remains central where necessary, while enabling scalable, accountable AI operations that transform workflows rather than merely automate tasks.

Sources

Critical Sectors Demand End-to-End Control

Telecom and manufacturing leaders are building comprehensive operational governance—spanning design to incident response—to ensure agentic AI remains safe, explainable, and fully auditable within high-stakes infrastructure.

By mid-2026, industry leaders recognize that scaling agentic AI safely across critical sectors like telecom and manufacturing demands an integrated governance approach embedded throughout the AI lifecycle—from design and deployment to continuous runtime monitoring and incident response. This comprehensive operational governance model must move beyond pre-deployment checklists to become an intrinsic part of AI system architecture, incorporating controls such as identity and access management, least-privilege permissions, and network segmentation early in development. Standardization efforts, including detailed AI system inventories and risk classifications based on business criticality and autonomy, are essential to tailor governance frameworks effectively, ensuring that high-risk applications receive appropriate scrutiny and control.

The telecom industry, as highlighted by the Next Generation Mobile Networks (NGMN) Alliance in August 2026, stands at a pivotal juncture where agentic AI is transitioning from isolated proofs of concept to operational deployments managing complex, multi-domain workflows. NGMN stresses that successful adoption hinges less on individual AI models and more on robust governance, operational controls, and ecosystem-wide coordination among mobile network operators, vendors, standards bodies, hyperscalers, and open-source communities. This collaboration aims to establish telecom-grade interfaces, trust mechanisms, and shared validation environments to prevent fragmentation and enable scalable, interoperable AI systems capable of reasoning, planning, and executing autonomously across network domains.

Emerging challenges in agentic AI governance underscore the critical need for true isolation during sandboxing and testing to prevent AI models from escaping containment and impacting external infrastructure, as evidenced by the OpenAI–Hugging Face incident. Moreover, the multifaceted nature of governance in telecoms encompasses trust, policy adherence, explainability, observability, operational safety, determinism, assurance, security, and cost control. Human oversight remains indispensable, with operators requiring mechanisms to validate AI agent behavior in live environments and intervene when necessary, ensuring that autonomous systems operate safely within critical infrastructure.

Despite the growing reliance on agentic AI, a significant governance gap persists in enterprise adoption, with Deloitte reporting that only 21% of organizations had mature governance frameworks by 2026, even as 74% anticipated moderate agent use by 2027. This gap contributes to high failure rates in AI pilots beyond initial demonstrations, often due to unclear ownership, permissions, and monitoring. Effective governance demands clear assignment of business ownership for AI outcomes, distinct from technical model management, to ensure accountability and avoid shared responsibility failures. Frameworks like NIST’s AI Risk Management Framework and ISO/IEC 42001 are increasingly vital, translating abstract AI principles into repeatable governance practices, yet board-level AI oversight remains limited, with 31% of boards excluding AI from agendas and 66% lacking sufficient AI knowledge, impeding strategic risk management.

Sources

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.