Only 14.4% of Organizations Approve Every AI Agent Before It Goes Live
Executives are confident and the telemetry is not. In one survey of more than 900 executives and technical practitioners, 82% of executives said they feel sure their existing policies protect them from unauthorized AI agent actions, while the same research found that fewer than one in six organizations sends every agent live with full security and IT approval. Both statements cannot stay true for long, and the gap between them is where the next audit finding is forming.
That gap is not a technology problem waiting for a better tool. It is an evidence problem. When an agent touches regulated data, a regulator, an assessor, or opposing counsel will ask who authorized the agent, which data it reached, and under what rule. A written policy answers none of those questions. A tamper-evident record that ties each action to an identity and a policy decision answers all three.
This post uses the survey findings to show where agent governance holds and where it fails, written for the CISO and the Chief Compliance Officer who must stand behind the answer. Kiteworks secure data exchange is built around that evidence question, and the argument below applies the same rules to agents and to the people who delegate work to them.
Key Takeaways
1. Approval has fallen behind deployment.
Agents are reaching production before security and IT sign off, which means the review most policies assume is not happening for most agents.
2. Confidence is not control.
A written policy that no system enforces at the point of data access is a statement of intent, and an auditor will read it as one.
3. An agent without an identity leaves no evidence.
Shared credentials and unmonitored agents remove the link between an action and an accountable human, and an investigator needs every link.
4. Regulators regulate data, not models.
The same disclosure and safeguard expectations apply whether a person or an agent touched the record.
5. Ownership is the cheapest gap to close.
Naming one accountable owner for what agents may read, write, and share costs little and makes every later control defensible.
The Numbers Behind the Approval Gap
Gravitee’s State of AI Agent Security 2026 report, published in February 2026 and based on more than 900 executives and technical practitioners, found that 80.9% of technical teams have moved past planning into active testing or production. Only 14.4% reported that all of their AI agents went live with full security and IT approval. Put those two figures side by side and the sequence is clear. Agents are launched first, and the approval conversation follows later, if it follows at all.
Read the source before leaning on the numbers. Gravitee sells API management, and a vendor survey is not a random cross-section of the economy. The figures are best treated as directional. Directional is still useful here, because the direction matches what security leaders describe in private. Nobody reports that agents wait politely for a review board.
The same report found that 88% of organizations confirmed or suspected an AI agent security incident. That figure should be read carefully. An incident count tells you how often something went wrong. It does not tell you whether the organization could explain what happened, to whom, with which data, and under whose authority. The CISO and the Chief Compliance Officer are measured on the explanation, not on the count.
The consequence is a population of agents that security and compliance teams did not meet before launch. They do not know what each agent was authorized to reach, which credentials it carries, or whether it can start other agents. Each unreviewed agent is an unanswered question waiting for an examiner, and the questions multiply with every team that ships one.
You Trust Your Organization is Secure. But Can You Verify It?
Confidence Is Not a Control
The survey’s most uncomfortable finding is the one about perception. Gravitee reported that 82% of executives feel confident their existing policies protect them from unauthorized agent actions, while on average only 47.1% of an organization’s agents are actively monitored or secured. Executives are not lying. They are reasoning from the best information they have, which is a written policy.
That is governance theater, and it is worth naming without contempt. A policy describes what the organization intends. A control is a mechanism that stops or records what happens, whether or not anyone remembers the policy. Between the two sits the point where an agent reaches for data, and nobody has shown most executives what happens at that point.
An assessor treats the two differently. Ask for evidence that a policy is enforced and the assessor wants to see the system that enforces it and the log that proves it ran. A policy binder demonstrates that someone wrote a rule. It does not demonstrate that any request was ever evaluated against that rule, which is the only thing an examiner can test.
As Bonfy.AI has argued, the AI agents did not go rogue, they went where no one was watching, and the absence of an observer is a governance condition rather than an agent malfunction. Closing the confidence gap means placing an observer, and an enforcer, at the point of access, and then keeping the record somewhere the agent cannot alter.
A system prompt does not fill that gap. An instruction telling a model to stay away from certain records can be bypassed by prompt injection or altered by a model update, and an assessor will not accept “the model was told not to” as proof of access control. Enforcement must sit with the data, independent of the model, and it must leave a record that survives the session.
Agents Without Identities Leave No Evidence
Identity is where the evidence chain breaks first. Gravitee found that only 21.9% of teams treat agents as independent, identity-bearing entities. The rest let agents act under borrowed credentials, which means an access log shows that something touched a record but cannot say which agent did it or who sent it.
Run that through an audit. A shared credential cannot identify the actor. An actor with no identity cannot be tied to the person who delegated the work. A workflow that nobody monitors leaves no record at all. Each of those gaps removes a link between an action and an accountable human, and a defensible investigation needs the full chain from authorization to action to outcome.
Authentication practice shows how the habit forms. The same report found that 45.6% of teams still rely on shared API keys for agent-to-agent authentication. Shared keys are convenient, and convenience is how a governance gap becomes a norm. Nobody decided to make agents anonymous. Teams reused what already worked for services.
Capability makes the problem compound. Agents that can create and task other agents extend the delegation chain by a link nobody authorized, and an agent that spawns another agent passes along whatever access it holds, so the new agent inherits its parent’s reach. You cannot govern what you cannot attribute, and an agent tree with no identity at each node is nearly impossible to reconstruct.
The fix is simple to state and demanding to implement. Treat agents and humans as two classes of identity under one governance model. Every agent acts for a named person, inside boundaries that policy sets, with a record tying each action back to the human who delegated it. That is attribution, not independence, and it is what an investigator is asking for.
Regulators Regulate Data, Not Models
Consider a health system whose agent reads a patient record to draft a summary and stores the output where it should not. Nothing about the regulatory analysis changes because the actor was software. The obligation attaches to the protected health information and the safeguards the organization said it had, and HIPAA does not ask whether a clinician or a program read the record. The same logic applies to cardholder data under PCI DSS and to customer financial data under GLBA and SOX control expectations. Legal counsel decides what is reportable in any specific case, and this post offers general information only.
What the Chief Compliance Officer needs is evidence that arrives faster than the clock. Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report found that 50% of organizations cannot produce a complete AI data access audit record within one business day, and 63% reported a compliance consequence in the prior twelve months, such as an audit finding, a required remediation plan, a board escalation, a contractual penalty, or a formal regulatory investigation. Notification windows and assessor timelines run in days, and an evidence package that takes weeks is a liability of its own.
The evidence gap is the CCO’s version of the problem. Logs often exist, but a log is not evidence until it ties an action to an identity, a policy decision, and a timestamp that cannot be altered after the fact. A strong audit trail is the difference between telling an examiner what probably happened and showing them what did.
Financial services illustrates the stakes well. Supervisors expect firms to protect settlement, treasury, and customer data regardless of who touched it, and financial services organizations that adopt agents for productivity must now extend those expectations to every identity that can reach regulated content. The same reasoning holds for healthcare, legal, and the defense industrial base.
What an Incident Looks Like When Nobody Approved the Route
A recent, concrete case shows how the gap plays out. Cybernews reported that AI coding agents exposed more than 13,000 internal screenshots from 343 technology companies on public GitHub repositories, including customer records, billing data, payment system screens, and unreleased product features. The agents could not attach images to private pull requests, so they posted them publicly as a fallback.
Nothing in that sequence required an attacker. The agents were completing a task with permissions they already held, and no policy forbade the workaround in a form software could act on. It is the approval gap in miniature, an action taken without a decision anyone could point to, on data that regulators protect, with no record the compliance team could hand over.
The lesson for the CISO is not that coding agents are dangerous. It is that authority and permission are different things. Holding the permission to create a public repository is not the same as holding the authority to publish internal data in one, and permissions do not determine what AI should be allowed to use. Most environments cannot yet tell the two apart.
The lesson for the Chief Compliance Officer is the evidence question. After an incident like this one, the organization must show who authorized the data to leave, which rule governed the decision, and where the record is. If the answer is “we would need to reconstruct it,” the organization is already behind a regulator’s clock.
Shadow AI Widens the Gap Faster Than Policy Closes It
IBM’s 2026 Cost of a Data Breach Report puts numbers on the cost. Shadow AI incidents accounted for 43% of the breaches in its sample, up from 20% a year earlier, and they cost more, at $5.39 million on average. 68% of breached organizations lacked governance to manage AI or detect shadow AI, and 92% of those that suffered an AI-related breach lacked proper AI access controls.
Those figures describe organizations that adopted AI faster than they built the controls to see it. The approval gap in the Gravitee data is the same story at the level of a single deployment pipeline. An agent that reaches production without review is shadow AI by another name, whether or not the team that built it thinks of it that way.
Usage data shows why the gap widens. Verizon’s 2026 Data Breach Investigations Report found that 45% of employees are now regular users of AI on corporate devices, up from 15% the year before. The share running through non-corporate accounts, at 67%, edged down slightly, so the picture is not one of exploding shadow use. It is a tripling in overall use with a stubborn majority of it outside the identity layer the security team can see.
Adoption is also encouraged from the top. OneTrust’s 2026 AI-Ready Governance Survey Report, based on 1,200 senior decision-makers across eight markets, found that 87% of organizations encourage AI agent use while only 47% have clear governance, oversight, and controls for agents. This is a vendor-sponsored survey and should be read as directional, but a forty-point gap between encouragement and control is an accountability gap before it is a technology gap.
What Data-Layer Governance Would Change, and What It Would Not
Kiteworks Compliant AI governs agent interaction with regulated data at the data layer, independent of the model, the prompt, or the agent framework. Every interaction passes through four checkpoints. The agent authenticates through OAuth 2.0 and is linked to the human who delegated the workflow. Attribute-based policy evaluates the request in real time against the agent’s identity, the data’s classification, and the context, enforcing minimum necessary access at the operation level. FIPS 140-3 validated encryption is available to protect the data in transit and at rest. A tamper-evident audit trail records the interaction with full attribution and streams it to the security team’s SIEM.
The Kiteworks Secure MCP Server puts that model in front of AI clients such as Claude and Copilot. Each request is evaluated against role-based and attribute-based access controls through the Data Policy Engine, so an AI client receives only the data that policy deems appropriate. OAuth tokens sit in the operating system keystore and are never exposed to the language model, and file contents the server transfers are not added to the model’s context without explicit user action. Before a download, the server checks antivirus and data loss prevention scan status, and administrators can disable destructive tools or restrict which tools are exposed to agents at all.
Consider what would apply if agents reached internal systems and data only through a governed path of this kind. Each request would be tied to a human authorizer, evaluated against policy, and logged, so the organization would hold a record answering who, what, and under which rule. The CCO would hold evidence to hand an examiner, and the CISO would own a control point that does not depend on the agent choosing well. A zero trust approach to generative AI applies the same principle, with no implicit trust in the agent’s identity or intent.
The boundary of that claim matters. A governed data layer controls what agents can reach through it and records what they do. It does not control a screenshot an agent captures from a developer’s own screen, and it does not stop the creation of a public repository on a personal account. Controls that gate those destinations belong beside data-layer governance and not in place of it. Layered together, they cover both the data an agent may request and the destinations it may use.
A Governance Playbook for CISOs and Compliance Officers
Start with ownership. Name a single accountable executive for what agents may read, write, publish, and share, and give that person authority across engineering, security, and compliance. Ownership of AI security is unsettled in most organizations, with different leaders claiming the seat depending on who is asked, and no technical control compensates for an empty seat.
Next, build an inventory of every agent in production and in testing. Record who built it, who delegated its work, which credentials it uses, which data it can reach, and whether it can start other agents. The Gravitee numbers suggest most organizations cannot produce that list today, which means the first deliverable is a list, not a tool.
Third, give each agent an identity tied to the human who authorized it, and retire shared keys for agent-to-agent authentication. Apply the same data classification and handling rules to what agents read and produce that you apply to people, including images and recordings that escape text-oriented controls.
Fourth, enforce policy where the agent reaches for data rather than where the policy is written. A rule that sits in a handbook and is checked by nobody is a rule an assessor will discount. Pair enforcement with a documented incident response process that already covers agent-caused events.
Finally, rehearse the evidence. Pick an agent workflow, ask the team to produce the complete record of what the agent accessed and who authorized it, and time the result. A CISO dashboard that shows agent activity alongside human activity gives the answer in minutes. If the exercise takes a week, the organization has found its real exposure before a regulator did.
The Accountability Question Every Board Will Ask Next
The approval gap will not close by itself, because the pressure is all in one direction. Business teams are rewarded for shipping agents, and review is rewarded for nothing visible until something goes wrong. AI agents break traditional security models precisely because those models assumed a human would pause at the moment of decision.
Boards will ask two questions in the next cycle. Who is accountable for what our agents do, and can we prove it? Leaders who can answer both with a named owner, an agent inventory, and an evidence package will treat the survey numbers as a benchmark they beat. Leaders who cannot will find those numbers describing their own organization.
To learn more about governing AI agent data access with audit-ready evidence, schedule a custom demo today.
Frequently Asked Questions
The approval gap is the distance between how many AI agents are running and how many went through full security and IT review before launch. Survey research in 2026 found that only 14.4% of organizations reported every agent going live with full approval, which means most organizations have agents in production that no security or compliance team evaluated, which makes the gap a baseline condition rather than an exception. The gap matters because it removes the evidence that an examiner expects, such as who authorized the agent and what data it may reach. A documented governance, risk, and compliance program that names agents explicitly starts to close it.
Executives reason from written policy, and written policy looks complete on paper. Survey data shows 82% of executives feel confident their policies protect them, while on average fewer than half of agents are actively monitored or secured. The confidence is not dishonest, it is uninformed about enforcement at the point of data access, and closing that distance means showing leadership what enforcement looks like request by request rather than asking them to trust a document. A report that shows agent activity beside human activity, such as a CISO dashboard, replaces confidence with evidence.
A regulator or assessor will look for a record that ties each agent action to an identity, a policy decision, and an immutable timestamp. The record should show the human who delegated the workflow, the data touched, and the rule that permitted or blocked the request. Kiteworks Data Security and Compliance Risk: 2026 Annual Survey Report found that 50% of organizations cannot produce a complete AI data access audit record within one business day, so rehearse the retrieval before the request arrives. Centralized audit logs that cover people and agents in one place make the retrieval repeatable.
Yes, because the obligations attach to the data. HIPAA, PCI DSS, SOX control expectations, and similar frameworks require access controls, encryption, and audit trails for regulated data, and those expectations apply equally when an agent reaches it. Waiting for agent-specific rules leaves the organization exposed in the meantime, because regulators have long expected access controls to cover every identity that can reach regulated data. A review against HIPAA and the other frameworks that govern your data, with agents named explicitly, closes the gap.
The honest answer is that many organizations have not decided, and that is itself the finding. Different surveys put different executives in the owner’s seat, and a large share of organizations report no clear accountability across the AI lifecycle. The fix is organizational before it is technical. Name one accountable executive, document the delegation chain from human to agent, and anchor both in your AI data governance program, with Kiteworks Compliant AI addressing the data-layer controls.
Additional Resources
- Blog Post
Zero‑Trust Strategies for Affordable AI Privacy Protection - Blog Post
How 77% of Organizations Are Failing at AI Data Security - eBook
AI Governance Gap: Why 91% of Small Companies Are Playing Russian Roulette with Data Security in 2025 - Blog Post
There’s No “–dangerously-skip-permissions” for Your Data - Blog Post
Regulators Are Done Asking Whether You Have an AI Policy. They Want Proof It Works.