AI agents run wild: enterprises race to rein in autonomous workforce as governance gaps widen

N2K Networks

The gist

Enterprises are unleashing armies of autonomous AI agents faster than they can build guardrails, exposing massive security and governance risks that legacy systems can’t handle.

What to know

AI Identity Crisis Unfolds

Traditional identity management is breaking under the strain of autonomous AI agents, forcing enterprises to rethink security from the ground up as dynamic, non-human identities defy static controls.

By late 2025, enterprises had widely deployed autonomous AI agents—with over 90% adoption reported by Jack Hirsch—yet only a fraction, about 10%, had implemented governance or control strategies. This rapid, largely ungoverned proliferation exposed fundamental inadequacies in traditional identity and access management (IAM) models, which rely on static credentials or OAuth grants ill-suited for AI agents. Hirsch emphasized that agentic AI represents a fundamentally new identity challenge, as these AI entities cannot be managed using human-centric frameworks, underscoring the urgent need for novel standards and governance models tailored to AI identities.

Leading enterprises like JP Morgan Chase, with its $18 billion security budget, publicly acknowledged the difficulty of securing AI agents within existing SaaS ecosystems, which lack appropriate guardrails for authentication and authorization decisions. This early recognition was amplified by incidents in 2025-2026 where AI agents inadvertently accessed unauthorized data, revealing critical authentication and authorization flaws. Such events highlighted the complexity of defining deterministic access policies for autonomous agents, whose identities and privileges are dynamic and context-dependent, thereby challenging CISOs to rethink traditional static access controls.

By early 2026, the emergence of autonomous AI agents like OpenClaw—capable of executing shell commands and managing files with persistent root-level permissions—brought these governance challenges into sharp relief. Security experts, including Rajiv Dattani of AIUC, warned that dismissing such systems as mere hobby projects was a critical error, as they represent the imminent future of enterprise AI requiring new compliance and certification frameworks. This period marked a paradigm shift where security teams had to fundamentally rethink identity models, logging, approval workflows, and threat modeling to account for autonomous decision-making and complex agent behaviors beyond human oversight.

By mid-2026, documented security incidents involving autonomous AI agents confirmed that traditional human-centric security controls were insufficient, as agents began influencing their own execution environments and bypassing sandboxing protections, exemplified by vulnerabilities like CVE-2025-59532. The OWASP State of Agentic AI Security and Governance 2026 report underscored that safety and security concerns converge at the deployment layer and that governance must operate on rapid timescales measured in hours. Reflecting this urgency, regulatory frameworks rapidly emerged across 10 jurisdictions with 42 instruments, signaling that early calls for new standards and governance mechanisms were already shaping the enterprise AI security landscape.

Sources
SiliconANGLE theCUBEAI + a16z☁️ The Cloud Security Guy 🤖Venture BeatRockCyber Musings

Governance Goes Real-Time

Continuous, context-aware oversight and policy-as-code frameworks are replacing static security, as enterprises scramble to manage shadow AI and enforce accountability in a rapidly evolving threat landscape.

The evolution from human-centric IAM to dynamic identity control planes is fundamental to governing autonomous AI agents effectively. Traditional identity and access management systems, designed for human users, falter at agentic scale, necessitating unique, verifiable identities for each AI agent linked to human owners and specific business use cases, as highlighted in analyses from late 2025 and early 2026. This shift demands session-based, risk-aware permissions with continuous, context-aware authorization and purpose-bound data access enforced at the data query engine level, moving away from static, set-and-forget roles. Microsoft’s Agent 365 exemplifies this new paradigm by integrating identity, security, and policy enforcement to provide full inspectability and runtime asserts that prevent agents from deviating during long-running operations, underscoring the critical infrastructure role of cryptographic authentication and continuous evaluation in securing autonomous AI.

Governance frameworks for agentic AI have matured into multi-layered architectures that emphasize policy-as-code, continuous authorization, and human-in-the-loop oversight to manage the unique risks posed by autonomous agents. By mid-2026, experts like Joe Hladik and Greg Brockman stressed the necessity of embedding security primitives and observability directly into AI operations, moving beyond static guardrails to adaptive, runtime governance that can handle agents’ creative and fast-paced behaviors. Human oversight is no longer a checkbox but a structural component that prioritizes escalation for irreversible or high-risk actions, addressing the 'agentic paradox' where AI efficiency inherently conflicts with traditional security measures. This approach is reflected in emerging standards such as WebMCP and the growing ecosystem of startups focused on agent security, signaling a convergence of identity governance and cyber resilience to ensure traceability, auditability, and recovery.

The rapid proliferation of autonomous AI agents within enterprises has exposed critical gaps in visibility, control, and risk management, making governance the foremost concern for CISOs and security leaders. Janet Worthington’s insights from mid-2026 reveal that shadow AI—unsanctioned or unknown agent deployments—combined with agents’ extensive and often opaque system access, create unprecedented security challenges, including bypassing guardrails and potential data exfiltration through prompt injection. This scenario is compounded by the blurring boundaries between consumer AI tools like Apple’s Siri and enterprise data environments, necessitating governance frameworks that provide end-to-end observability and discovery of unmanaged agents, as well as sandboxed execution environments. McKinsey’s research corroborates the urgency, reporting that 80% of organizations have already encountered risky AI agent behaviors, underscoring the indispensable role of robust governance and identity controls in preventing invisible operational degradation and unauthorized actions.

Contemporary governance frameworks for agentic AI emphasize continuous validation, least-privilege identity management, and computational enforcement of policies to address the dynamic and probabilistic nature of autonomous agents. Thought leaders advocate treating AI agents akin to new employees with scoped, time-boxed credentials and instant revocation capabilities, moving beyond policy-as-document to policy-as-code that enforces rules at execution time. Continuous risk monitoring replaces periodic audits to capture adaptive agent behaviors, while comprehensive logging ensures end-to-end traceability of every decision and data interaction. This governance evolution is driven by regulatory pressures such as the EU AI Act and enterprise demands for accountability, with hyperscalers embedding controls into cloud stacks and workflow platforms integrating oversight natively. The urgency is heightened by the recognition that traditional deterministic security models and least privilege assumptions are insufficient, as evidenced by high exploit probabilities in Multi-Component Plugin stacks and incidents of unauthorized auto-merging in production environments.

Sources
Venture BeatResilient CyberResilient CyberReid HoffmanThe AI-Native Product TeamN2K Networks

Security Platforms Race Ahead

A new class of AI-native security tools is emerging to provide real-time observability and enforcement, as enterprises struggle to keep pace with explosive agent growth and invisible operational risks.

Enterprise adoption of AI applications and autonomous agents has surged dramatically, with Palo Alto Networks tracking a 250% increase in AI apps within five months and BeyondTrust reporting a 466.7% year-over-year growth in AI agents by mid-2026. Despite this rapid uptake—where over half of employees use generative AI daily and legal professionals have doubled AI tool usage—enterprises face significant operational challenges in securing and governing these agents, especially as many organizations lack visibility into which AI tools are in use and how they interact with sensitive data.

The complexity of securing AI agents in enterprise environments has driven the emergence of specialized security frameworks and platforms that go beyond traditional API management. Companies like Varonis, Operant AI, BeyondTrust, and Microsoft have introduced real-time observability, control, and enforcement solutions—such as Varonis’ AI TRiSM integration and Operant’s Agent Protector—that enable continuous discovery, least privilege enforcement, and real-time blocking of unauthorized AI behaviors. These innovations address critical risks like shadow AI, privilege escalation, and prompt injection, reflecting a shift from reactive monitoring to proactive governance.

Operational integration of AI agents demands new governance paradigms that balance rapid business velocity with cyber resilience. Frameworks like Joe Hladik’s three-layer model—targeting tool, cognitive, and identity layers—highlight the need for deep observability into non-human identities that dynamically scale, while maintaining human-in-the-loop checkpoints to prevent catastrophic unintended consequences. As Greg Brockman emphasizes, human attention is the scarce resource, necessitating systems that intelligently escalate high-risk actions and automate low-risk approvals to manage the flood of autonomous decisions in real time.

Despite growing enterprise experimentation with AI agents, penetration remains below 1%, underscoring the nascent stage of this technology and the steep operational hurdles ahead. Challenges include inconsistent vendor terminology, the need for tailored contextual data per workflow, and the difficulty of scaling auditability and compliance—especially as AI agents proliferate across multi-cloud platforms and legacy systems. The rise of certification standards like AIUC-1 and the integration of AI-generated policy drafting tools offer promising pathways to bridge governance gaps, but the market urgently requires robust, scalable frameworks to manage the exploding agent workforce and its attendant risks.

Sources
CyberWire DailySecurity Weekly - A CRA ResourceThe Geek In ReviewBriefglanceGlobeNewswire - Industry News on TechnologyGlobeNewswire - Industry News on Technology

GRC Becomes Engineering-Driven

Compliance is shifting from manual checklists to automated, code-embedded workflows, with GRC engineers and 'compliance as code' platforms now essential for scalable, auditable AI governance.

By late 2025, Governance, Risk, and Compliance (GRC) began a fundamental transformation from manual, spreadsheet-driven processes to an engineering-centric discipline that embeds automation and continuous assurance directly into governance workflows. Organizations increasingly sought GRC professionals with engineering skills capable of automating evidence collection, integrating controls with cloud logs, and implementing policy-as-code frameworks to enable scalable, code-driven governance. This shift emphasized human oversight at critical junctures to maintain accountability, with audit logs primarily capturing human approvals of AI-suggested compliance tasks, ensuring that automation complemented rather than replaced expert judgment.

Entering 2026, the divergence between traditional GRC Analysts and emerging GRC Engineers became stark, as the latter leveraged automation to embed controls into systems, producing continuous, tamper-resistant evidence that auditors increasingly demanded. Manual evidence collection and periodic audits were rapidly becoming obsolete, with auditors flagging screenshots and annual reports as weak assurance. This evolution was further accelerated by emerging AI-specific regulations and the growing complexity of multi-framework compliance, driving a market shift toward integrated, AI-native compliance platforms like Cardamon and Vanta that automate control testing, evidence gathering, and policy workflows across hundreds of integrations.

The rise of 'Compliance as Code' platforms, exemplified by companies like HoundDog.ai and Scytale, marked a decisive move away from static, paper-based compliance toward continuous, code-embedded governance workflows that operate at the speed of software development. These platforms embed privacy and compliance checks directly into development pipelines, automatically flagging risky data flows and policy violations before code merges, thus transforming compliance from a legal bottleneck into an automated engineering discipline. This shift-left approach not only enables real-time regulatory adherence but also addresses the challenges posed by AI and shadow IT, which introduce invisible compliance risks that traditional manual processes cannot track.

Despite the promise of AI-driven compliance automation to simplify regulatory adherence, trust barriers and organizational change management remain critical hurdles. Leaders emphasize that human verification must remain integral to automated workflows to prevent blind trust in AI outputs and ensure audit-ready evidence, as reflected in DOJ guidance requiring human sign-off. Furthermore, successful adoption depends on clear communication of value to end users to avoid resistance, with compliance automation increasingly seen as the connective tissue between innovation and security—embedding CI/CD telemetry, policy-as-code checks, and continuous monitoring to transform compliance from a reactive paperwork cycle into a proactive, operational control surface.

Sources
☁️ The Cloud Security Guy 🤖CyberWire Daily☁️ The Cloud Security Guy 🤖FinTech GlobalLBHackerNoon

Trust Gap Spurs Industry Action

With confidence in AI outcomes lagging, high-profile acquisitions and new standards signal an industry-wide push to embed trust, provenance, and robust governance at the heart of enterprise AI.

By late 2025, enterprise trust in AI remained notably fragile, with only 49% of AI professionals and end users expressing confidence in AI agent outcomes and a trust index languishing at 2.4 out of 5. This trust deficit was compounded by immature governance frameworks, as a mere 29% of enterprises had standardized AI trust and governance protocols, reflecting a maturity index of just 2.8. Nevertheless, the landscape was poised for transformation, with 73% of surveyed professionals signaling significant or strategic investments in AI trust and governance over the following 18 months, underscoring a collective recognition that robust data provenance and protection—prioritized by 72% of respondents—are foundational to building AI trust.

The strategic imperative to embed AI governance into enterprise security was vividly illustrated in early 2026 when Varonis Systems acquired AllTrue.ai, a specialist in AI Trust, Risk, and Security Management (AI TRiSM). This move combined data-centric security with AI-specific risk management, enabling organizations to monitor AI systems in real-time, enforce least privilege access, and provide compliance evidence, thereby addressing the nuanced risks of autonomous AI decision-making. Such high-profile acquisitions reflect a broader industry prioritization of AI governance as a critical capability amid growing regulatory and operational complexities.

By early 2026, industry standards and governance frameworks began to crystallize, with key players like NSS Labs, AWS, Microsoft, and F5 publishing foundational white papers that advocated for adversarial validation and governance-driven, system-level AI security approaches. These efforts marked a pivotal shift from experimental AI deployments to accountable, production-grade systems, as NSS Labs CEO Vikram Phatak emphasized that AI security is as much a governance challenge as a technical one. Concurrently, surveys revealed that only about 25% of organizations had comprehensive AI security governance, yet those with formal governance were twice as likely to adopt agentic AI and thrice as likely to train staff, highlighting governance maturity as a crucial readiness indicator.

Mid-2026 surveys and analyses spotlighted a widening chasm between rapid AI adoption—especially in customer experience—and lagging governance frameworks, with 99% of European organizations feeling pressure to scale AI but only 38% possessing clear governance approaches. This governance gap is exacerbated by the prioritization of speed over compliance by 70% of organizations, and the complexity of multilingual AI environments affecting 64% of respondents. The OWASP 2026 report further underscored the maturation of AI security standards by consolidating real-world incidents and mapping 42 regulatory instruments across 10 jurisdictions, yet it also warned of pervasive shadow AI and aggressive agent deployments outpacing governance maturity, signaling an urgent need for enterprises to elevate AI governance as a strategic imperative.

Sources
SiliconANGLE theCUBEGlobeNewswire - Industry News on TechnologyResilient CyberPR Newswire - Consumer TechnologyBusiness WireRockCyber Musings

Human Oversight Remains Vital

Despite AI’s rapid advance, most enterprise agent decisions still require human verification, making observability and real-time policy enforcement critical to safe and scalable adoption.

By early 2026, enterprises have reached a pivotal inflection point in scaling agentic AI, where the primary barriers are not doubts about AI’s value but significant governance, security, and reliability challenges. A global report highlights that only 13% of organizations deploy fully autonomous agents, with 69% of AI decisions still requiring human verification, underscoring the ongoing necessity of human oversight. Observability emerges as a critical enabler, providing real-time visibility into agent behaviors to build trust and ensure safe, accountable scaling amid complex compliance and privacy demands.

The rapid acceleration of cyberattacks in the agentic AI era demands a fundamental rearchitecture of security operations, as traditional practices like daily triage and weekly reviews are now obsolete against threats that unfold in under 30 seconds. Experts like Google CISO Phil Venables and Phil Windley advocate for continuous, runtime policy enforcement embedded directly within AI agent loops, transforming governance from a static checkpoint to dynamic, ongoing authorization. This shift is vital to close the widening gap between fast-paced AI adoption and immature security governance, which has already led to widespread vulnerabilities including identity weaknesses in 90% of incidents and hundreds of patched AI-related flaws weekly.

Leading enterprises are moving beyond AI hype by anchoring agentic AI initiatives to concrete ROI metrics such as time savings, cost reduction, risk mitigation, and improved reliability, while enforcing strict operational controls that allow AI to reason broadly but act narrowly within defined policy boundaries. SolarWinds CTO emphasizes that successful AI adoption depends on embedding governance frameworks that ensure auditability, identity management, and human-in-the-loop controls, enabling measured, staged rollouts that balance innovation with risk. This approach aligns with Gartner’s findings that organizations expanding AI access broadly under strong governance are over three times more likely to realize high value from generative AI tools compared to those restricting usage to low-risk groups.

Looking ahead to 2028, the explosion in AI agent deployment—projected to reach over 150,000 agents per Global Fortune 500 enterprise—makes robust governance and risk management indispensable to prevent chaotic proliferation and invisible operational degradation. Industry leaders like Microsoft, Apple, Cisco, and Salesforce converge on governance, identity, and security controls as foundational prerequisites, with platforms like Microsoft Agent 365 setting new standards for end-to-end observability and secured environments. The emerging consensus stresses that AI agents must be treated as privileged identities subject to continuous validation, auditability, and strict policy enforcement to detect subtle drifts and maintain accountability, especially as enterprises scale from pilots to production in complex, hostile environments.

Sources

Part of these trends

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.