AI Agent Governance Gap Confirmed by Three 2026 Surveys

AI Agents Are Reaching Data No One Approved — Three New Surveys Confirm the Governance Gap

Three independent research efforts, published within days of each other in the summer of 2026, landed on the same uncomfortable conclusion from three different vantage points: most enterprises can’t say what their AI agents can touch, who approved that access, or how to shut it off when something goes wrong.

I read a lot of these surveys over the course of a year, and most of them measure the same general anxiety in slightly different words. What makes this trio worth stopping on is that the numbers actually agree with each other. 1Password surveyed 1,000 security and engineering professionals at large U.S. firms and found that agents routinely reach data well beyond what anyone signed off on. Okta surveyed 306 security executives worldwide for its Global CISO Insights 2026 report and found that fewer than half feel confident they can even identify every AI agent operating in their environment, let alone control what it does. And the Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report, based on primary research with 459 security and compliance leaders, quantified the same gap using measured control deployment rather than self-reported confidence — and found it just as wide, if not wider.

Read individually, each report tells a compelling story. Read together, they form something closer to an industry baseline: AI agent access has outpaced AI agent governance almost everywhere, and the organizations running agents in production are, in most cases, the last to find out how far that access actually extends. This post walks through what each data set found, where the three converge, and what a governance model built for both human and agent identities actually requires.

Key Takeaways

  • Agents already reach more than anyone approved. 1Password found that roughly four in ten organizations have AI agents accessing data outside their approval scope, and that agents collectively touch about twice as much data as anyone has signed off on.
  • CISOs can’t see what they’re responsible for governing. Okta’s global survey found fewer than half of security executives are confident they can identify every AI agent in their environment, control what it accesses, or determine what it is allowed to do.
  • Kiteworks’ measured data confirms the gap independently. Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report found an AI Governance Maturity Score of 35 out of 100 across 459 organizations — meaning the average organization has deployed roughly 7 of 19 measured AI governance capabilities.
  • Purpose binding and kill switches are the least deployed controls. Only 26% of organizations restrict AI agents to authorized tasks and data scopes, and only 21% can automatically terminate a misbehaving agent’s access.
  • Accountability is unresolved even where technology exists. 1Password found that 65% of respondents believe a different person should be accountable when an agent causes harm than currently is — while governance capable of assigning that accountability at the access-control level remains rare.

The Developer Reality: Agents Already Reach More Than Anyone Signed Off On

Start with the people building and running these systems day to day. 1Password’s survey, conducted in late May and early June 2026 among 1,000 security and engineering staff at large U.S. companies, describes an environment where AI agents have moved from pilot to production faster than the access controls meant to contain them.

Forty-six percent of developers report running AI agents in production today. That alone is not surprising — agentic AI adoption has accelerated all year. What is notable is what happens once those agents are live: 71% of developers said their agents can reach sensitive information, and in roughly four out of ten organizations, agents reach data specifically outside what was approved for them. Across the full survey population, agents collectively touched about twice as much data as anyone had actually signed off on. That is not a rounding error in an access control policy. It is a structural gap between the data classification an organization believes it has enforced and what its agents are technically able to reach. Organizations handling PII, PHI, or other regulated data categories face a compounding exposure: a confirmed data breach attributable to an agent accessing data outside its approved scope triggers the same notification and remediation obligations as a human-initiated breach, with the added complexity that the agent’s decision chain may be harder to reconstruct than a human actor’s.

The persistence problem compounds this. Forty percent of developers said they grant agents persistent access to systems and secrets that remains live after the task that required it has finished. In a well-governed environment, an agent’s access should expire with the task — the same way a contractor’s badge should deactivate when the engagement ends. Instead, agents are frequently left holding credentials indefinitely, widening the blast radius of any single compromised agent, prompt injection, or misconfigured tool integration. Data minimization applied at the agent access level — provisioning each agent with access only to the specific data sources its current task requires, with automatic expiration when the task ends — is the operational mechanism that closes the persistent-access gap 1Password measured in 40% of developers.

That last risk is not theoretical either. Forty-seven percent of developers reported that an agent took an unintended action after following instructions buried in a webpage, document, email, or tool output — the agentic equivalent of a phishing click, except the agent doesn’t pause to second-guess the instruction the way a trained employee might. And 33% of developers working with agents said their organization had experienced a breach or security incident tied specifically to overprivileged non-human identities.

Perhaps the most revealing finding in the entire survey is about accountability, not access. When asked who should be responsible when an agent causes harm, 65% of respondents said someone other than the person currently held accountable should carry that responsibility. Only 5% said the agent itself should be accountable. In other words, the people closest to these systems already know the current ownership model doesn’t match reality; they just don’t agree yet on where the responsibility should sit. That gap between where accountability currently lands and where practitioners think it should land is, to my read, the real headline buried in the 1Password data — more telling than the access numbers themselves, because it’s one no amount of additional tooling fixes on its own. Access-level controls, logged and attributable to a specific policy and a specific approver, at least give an organization the evidence needed to have that accountability conversation with facts instead of guesswork. A documented incident response plan that explicitly pre-assigns agent-incident accountability — who investigates a prompt injection event, who revokes the agent’s credentials, who assesses data scope for notification purposes — converts the accountability ambiguity 1Password documented into a practiced, pre-decided response sequence.

You Trust Your Organization is Secure. But Can You Verify It?

Read Now

The View From the Boardroom: CISOs Can’t See What They’re Supposed to Govern

Move up a level, from the people building agents to the executives responsible for the risk those agents create, and the picture doesn’t improve — it just changes shape.

Okta’s Global CISO Insights 2026 report surveyed 306 security executives around the world and found that 81% worry about excessive AI access. That’s a strong majority expressing concern. What’s more striking is how few of them feel equipped to act on that concern: only 47% are confident they can identify every AI agent operating in their environment, only 46% are confident they can control what those agents access, and only 45% are confident they can determine what any individual agent is actually permitted to do. Fewer than half, on every single dimension of basic operational visibility. The CISO Dashboard delivers the real-time visibility across all AI-mediated data access events that closes this operational blind spot — giving security executives the unified, continuously updated agent inventory the Okta data identifies as missing in more than half of surveyed organizations.

Against that backdrop, it is not surprising that AI-related threats dominate the list of what keeps these executives up at night: AI-powered phishing (61%), malicious AI agents (49%), and deepfake-enabled authentication bypass (54%) all rank among the top concerns. These are not abstract, future-tense risks in the minds of the people running enterprise security programs. They are active, present-day operational concerns — and the visibility gap Okta measured is precisely what makes them harder to detect and contain.

The report also surfaces a governance-culture problem sitting underneath the technical one. Only 31% of security leaders worldwide — and just 12% in the United States — say they are fully aligned with their C-suite and board on what level of AI risk the organization is willing to accept. That gap sits above the technology stack entirely. The people setting AI risk appetite and the people executing security controls are, in most organizations, working from two different definitions of acceptable risk, and nobody has reconciled them yet. A formal risk assessment that quantifies AI agent data access exposure in business terms — mapping which regulated data categories each agent can reach, under what access conditions, with what revocation capability — gives security leaders the evidentiary foundation for closing the board alignment gap Okta documented.

The operational specifics Okta found line up closely with what 1Password found from the developer side. One in four organizations applies the same identity-lifecycle policies to AI agents that it applies to human users — meaning three in four do not, and are instead managing agent identities through some separate, likely less rigorous, process. Twenty-one percent rely on shared credentials or broad-permission service accounts for their agents, the exact pattern that turns a single compromised agent into a blast radius covering everything that credential can touch. And 20% leave agent management to individual teams on an ad hoc basis, with no consistent organization-wide policy governing how agent access gets granted, reviewed, or revoked. Supply chain risk management programs that extend this governance gap to cover AI agents provisioned by third-party vendors — not only the agents organizations deploy themselves — close the supply chain identity surface that the ad hoc management pattern creates.

Kiteworks’ Own Data Confirms It — With Measured Controls, Not Self-Reported Confidence

Both of the surveys above rely on self-reported perception: how confident does a CISO feel, how aware is a developer of what their agent touched. That’s valuable data, but perception and deployed reality don’t always match. Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report was built specifically to close that gap, using binary, verifiable control-deployment data collected from 459 security and compliance professionals at organizations with 1,000 or more employees, across 10 industries and three global regions.

The survey introduces two composite measures. The Data Security Maturity Score (DSMS) tracks 11 general data security controls — encryption, managed file transfer, SIEM integration, kill switches, and others — and produced a survey mean of 39 out of 100, meaning the average organization has deployed fewer than half of the security controls measured. The AI Governance Maturity Score (AIGMS) tracks 19 AI-specific data governance capabilities and produced a survey mean of 35 out of 100 — roughly 7 of 19 capabilities deployed. A third measure, the Data Security and Compliance Readiness Index (DSCRI), multiplies the two together to capture the compounding effect of weak governance layered on top of moderate security: the survey mean DSCRI came out to just 16.2 out of 100.

The consequences of that gap are not projected — they were reported by respondents describing what happened in the 12 months prior to the survey. Across all respondents, 80% experienced at least one security incident — general or AI-specific — in the past 12 months. Sixty-three percent faced a compliance consequence — an audit finding, a required remediation plan, a board escalation, a contractual penalty, or a formal regulatory investigation. And 65% discovered employees using unapproved AI tools with organizational data, a shadow AI rate that closely tracks the access-visibility gaps Okta and 1Password each measured from their own angles.

What makes the Kiteworks data particularly useful alongside the other two reports is its granularity on exactly which controls are missing — the same controls that would close the specific gaps 1Password and Okta describe.

Where the Gap Actually Lives: Purpose Binding, Kill Switches, and Audit Trails

No AI containment control measured in the Kiteworks survey is deployed by more than 33% of organizations. That is worth restating plainly: across every technical mechanism the survey measured for constraining what an AI agent can do once it’s live, not one has reached even a third of the market.

Purpose binding — the control that restricts an AI agent to the specific task and data scope it was authorized for — is deployed by only 26% of organizations, meaning 74% do not technically restrict their agents to authorized tasks and scopes at all. That is the precise control that would prevent the “agents reaching data outside approval” pattern 1Password measured; without it, an agent’s effective access is bounded only by what it can technically reach, not by what a human ever approved. Access controls applied at the content layer — evaluating every agent request against content sensitivity, agent role, and task context simultaneously — are the technical implementation of purpose binding that makes the authorized scope a runtime constraint rather than a documented assumption.

AI kill switch capability — a single control point to terminate a misbehaving agent’s access across all systems — is deployed by only 21% of organizations, leaving 79% without an automated way to cut off an agent once something has gone wrong. That gap is directly relevant to the prompt-injection scenario 1Password documented, where 47% of developers reported an agent taking an unintended action after following instructions hidden in external content: detecting the deviation is only half the problem if there’s no fast, reliable mechanism to revoke access once it’s identified.

Human-in-the-loop review before an AI system accesses high-risk data is deployed by 30% of organizations. AI-specific DLP policies that technically block sensitive data from flowing into unapproved AI tools are deployed by 28%. AI access logs forwarded to a SIEM platform, the baseline requirement for detecting anomalous agent behavior at all, are in place at just 33% of organizations. Producing a complete AI audit trail — the record that would let an organization actually answer “what did this agent touch, and when” — is harder still: only 27% can do it within one business day, and just 17% can do it within one hour. Half of organizations cannot produce that record within a single business day at all.

Every one of these figures maps directly onto a gap the other two surveys described from a different angle. Okta’s finding that only 46% of CISOs are confident they can control what agents access is the confidence-level mirror of Kiteworks’ measurement that only 26% of organizations have purpose binding technically enforced. 1Password’s finding that 40% of developers grant persistent access that outlives the task is the practitioner-level symptom of the 79% gap in kill switch deployment. These are not three separate problems. They are the same underlying gap, measured three different ways, arriving at the same order of magnitude. Organizations subject to regulatory compliance obligations — HIPAA, GDPR, CMMC — should treat these control deployment percentages as a sector-wide benchmark: the 26% purpose binding figure means 74% of peer organizations are operating AI agents that regulators will evaluate under the same access control frameworks that govern human user access, without the technical controls that make those frameworks demonstrable.

Governing Agents the Way You Already Govern People

The instinct many organizations have when they read data like this is to treat AI agent governance as a new, separate discipline — a parallel track of policy, tooling, and ownership built specifically for non-human identities. I’ve sat through enough pitches for a brand-new “AI governance layer” to be skeptical of that framing, and the data backs up the skepticism: that instinct is understandable, but it’s also part of why the gap exists in the first place. Okta’s finding that only one in four organizations applies the same identity-lifecycle policy to agents that it applies to human users is not a data point about agents needing their own rulebook. It’s a data point about most organizations not yet applying the rulebook they already have.

Every one of the missing controls this data set surfaces — purpose binding, kill switches, audit trails producible within an hour, RBAC and ABAC applied consistently, zero trust enforcement at the point of access — is a control that mature organizations already apply to human users of sensitive content. The gap 1Password, Okta, and Kiteworks each measured is not that AI agents lack a governance model. It’s that the governance model already built for people hasn’t been extended, technically and consistently, to cover every identity — human or agent — that touches sensitive data. Data governance frameworks that treat AI agent identities as a governed class from initial provisioning through task completion and credential expiration — subject to the same lifecycle policies as human accounts — are what close the identity-lifecycle gap Okta measured in three out of four organizations.

This is the premise behind the Kiteworks Control Plane: one governed environment where every access request, whether it originates from a person, an application, or an AI agent, is evaluated against the same attribute-based access control policy, logged to the same audit trail, and subject to the same revocation mechanism. When an AI agent connects through the Secure MCP Server, its access to governed content is scoped per request, not granted persistently and left open after the task ends — directly addressing the persistent-access pattern 1Password measured in 40% of developers. Kiteworks Compliant AI enforces purpose binding and data minimization at the policy layer, so an agent’s effective reach matches what was actually approved rather than what it happens to be technically capable of reaching — the exact control missing at 74% of organizations in the Kiteworks survey.

None of this replaces the identity and access management stack an organization already runs, and it does not resolve the accountability question 1Password’s respondents flagged as unresolved — that’s an organizational decision, not a technical one. What a governed secure data exchange layer does provide is the evidence: a single, attributable, auditable record of what any identity, human or agent, actually did with sensitive content, produced in minutes rather than requested and waited on for a week. That record is also what lets an organization finally answer Okta’s boardroom-alignment question with data instead of estimation — because the risk the board is approving and the access actually granted are, for the first time, describable in the same terms. The CISO Dashboard surfaces this unified agent-and-human access record in real time, giving security leadership the continuously updated data picture that makes the board alignment conversation grounded in current facts rather than lagging survey estimates.

To learn more about governing AI agent data access with the same rigor your organization already applies to human users, schedule a custom demo today.

Frequently Asked Questions

AI agent governance refers to the policies, technical controls, and audit mechanisms that determine what an AI agent can access, how long that access lasts, and how it’s logged and revoked. It became urgent in 2026 because AI data governance has lagged AI deployment: 64% of organizations in the Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report have deployed AI in production, but the survey’s AI Governance Maturity Score of 35 out of 100 shows that governance capability hasn’t kept pace. Independent research from 1Password and Okta corroborates the same gap from the developer and executive perspectives, respectively. Organizations subject to regulatory compliance obligations should treat AI agent governance as a direct compliance requirement: the same access control and audit trail standards that frameworks like HIPAA, GDPR, and CMMC impose on human user access apply equally to AI agents that process or access regulated data.

Identity and access management determines whether an agent is authenticated and what role or credential it holds. Data governance determines what that agent can actually do once authenticated — which specific content it can reach, under what conditions, and for how long. 1Password’s finding that 40% of developers grant agents persistent access that outlives the task illustrates the gap: the agent’s identity was properly authenticated, but the data governance controlling what it retained access to afterward wasn’t enforced. Supply chain risk management programs should extend this same distinction to AI agents provisioned by third-party vendors — vendor-deployed agents are typically authenticated through the vendor’s identity system, but the data governance layer that restricts what organizational content those agents can access must be enforced by the organization, not the vendor.

No — and this is a common misreading of the data. The gap these surveys measure isn’t that AI agents need their own separate governance framework; it’s that the governance already applied to human users of sensitive content hasn’t been consistently extended to cover agent identities as well. A properly governed zero trust architecture evaluates every access request — human or agent — against the same policy, under human-defined purpose binding and oversight, rather than granting agents autonomous authority separate from the people who deployed them. Data minimization applied at the agent credential level — ensuring each agent holds access only to the minimum data its current task requires — maintains human control over the effective scope of agent access without requiring human review of every individual agent request.

The Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report measured purpose binding (deployed by only 26% of organizations) and AI kill switch capability (deployed by only 21%) as two of the least-adopted AI governance controls. Purpose binding restricts an agent to its authorized task and data scope; a kill switch provides a single control point to terminate an agent’s access across all systems when something goes wrong. Kiteworks Compliant AI, delivered through the Secure MCP Server, addresses both by evaluating and scoping every agent request against policy in real time rather than granting standing, persistent permissions — constraining access at the request level instead of relying on a single after-the-fact switch. An incident response plan that explicitly covers the “kill switch activation” scenario — with a defined sequence for agent credential revocation, access log extraction, and data scope assessment — converts the kill switch from a technology capability into a tested, operational response.

The Kiteworks 2026 Data Security and Compliance Risk: Annual Survey Report found that only 27% of organizations can produce a complete AI audit log within one business day, and only 17% within one hour — meaning half of organizations cannot produce that record in a single business day at all. Closing that gap requires AI access logging built into the same governed platform where the access occurs, rather than reconstructed after the fact from disparate systems. When every agent interaction with sensitive content is logged natively as part of a Kiteworks secure data exchange environment, that record is available on demand rather than assembled under deadline pressure. Data classification applied to the content agents access — labeling records by sensitivity and regulatory category at the point of ingestion — further accelerates breach scoping by making it immediately clear which records, if accessed by an agent outside its authorized scope, trigger mandatory notification obligations under applicable frameworks.

Additional Resources

Get started.

It’s easy to start ensuring regulatory compliance and effectively managing risk with Kiteworks. Join the thousands of organizations who are confident in how they exchange private data between people, machines, and systems. Get started today.

Table of Content
Share
Tweet
Share
Explore Kiteworks