ai6 min read

Enterprises Embrace AI Agents Rapidly, Outpacing Governance

Enterprises are quickly integrating AI agents, with deployments doubling in just four months. However, monitoring and accountability systems lag significantly, creating growing risks.

A graphic from the 'State of AI Agent Security 2026' report showing that a significant percentage of organizations lack formal accountability for AI agent behavior.

Enterprises are quickly integrating AI agents, with deployments doubling in just four months. However, monitoring and accountability systems lag significantly, creating growing risks.

Around the corporate world, artificial intelligence agents are increasingly taking on autonomous roles. Imagine an AI in a financial services firm independently accessing customer accounts, compiling data from various internal systems, and making operational decisions without immediate human oversight. This scenario is not a future projection, but a current reality within many organizations, as highlighted by Gravitee's "State of AI Agent Security 2026" report. The report illustrates a stark discrepancy: the rapid adoption of AI agents within enterprises is far outstripping the implementation of adequate control and governance mechanisms.

The core finding reveals that the number of AI agents operating within the average enterprise has effectively doubled in just four months. This dramatic increase is juxtaposed against a critical statistic: the percentage of these agents undergoing proper monitoring has barely shifted. The growth in AI agent deployment is significantly outpacing the establishment of essential oversight, a trend most organizations acknowledge as problematic.

Gravitee, a company specializing in AI Agent Management, conducted a survey in April 2026, polling 750 executives and technical leaders. These results were then compared against a baseline established in December 2025. The survey found that the typical enterprise now deploys between 76 and 100 agents, a substantial jump from the previous range of 26 to 50 agents. Looking ahead, a significant 81.7% of organizations intend to deploy even more agents over the next year, with 28% planning a 'significantly more' aggressive expansion. Companies in the travel and transport sectors show the strongest intent, with 90% planning further AI agent integration.

The Disconnect Between Confidence and Coverage

A critical gap exists between organizations' increasing confidence in their AI agent deployments and their actual ability to monitor these agents. In December, the mean monitoring coverage stood at approximately 46.96%. By April, despite the doubling of agents, this figure only marginally increased to about 52%. This indicates that the absolute number of unmonitored agents operating in production environments is growing, not shrinking. A mere 9.5% of organizations report securing more than 80% of their deployed agents. Simultaneously, stated confidence levels regarding agent visibility rose by nine points during the same period, climbing from 82.6% to 91.8%. This combination of rising confidence and stagnant monitoring coverage creates a precarious situation, often preceding significant incidents.

The pre-deployment landscape reveals a similar lack of preparedness. Only 19.7% of organizations state that all their agents are thoroughly secured and governed before being put into live operation. Moreover, fundamental pre-deployment controls, such as security reviews, documented procedures for revoking access, or clearly defined scopes for agent capabilities, are not universally applied, with none being utilized by even 40% of organizations.

Common Patterns in AI Agent Incidents

Over the past year, more than half of organizations, specifically 54%, have either experienced or suspected an AI agent-related security or data privacy incident. Telecommunications (67.3%) and financial services (54.7%) sectors reported the highest rates of such incidents. Gravitee analyzed hundreds of open-ended responses from both survey waves, identifying six recurring patterns of failure. These include excessive permissions leading to over-privileged access, violations of data retention and privacy policies, prompt injection and adversarial manipulation attempts, the existence of 'shadow AI' deployed without IT's knowledge, and a lack of transparency from third-party vendors. A new pattern observed in the April data involves agents generating confidently incorrect outputs that subsequently influence significant financial, clinical, or compliance decisions.

Many of the narratives behind these incidents point to what appears to be ordinary operational drift, rather than sophisticated cyberattacks. For instance, an internal AI assistant initially granted broad access during a pilot phase may never have had its permissions scaled back. A voice system might inadvertently store raw audio data, despite protocols stating otherwise. Or a vendor could alter data processing methods without informing its clients. These scenarios highlight how systems gaining more autonomy than their surrounding processes can accommodate lead to vulnerabilities. A notable shift between the two survey waves is the nature of incidents: while December's incidents were primarily accidental, by April, deliberate adversarial exploitation, including prompt injection and jailbreak attempts specifically targeting agents, had become a significant concern.

The Absence of Clear Accountability

Perhaps the most profound gap identified in the report is the lack of accountability. A striking 85% of organizations have no formal structure to assign responsibility for AI agent behavior. Only 7.2% can pinpoint a specific individual who would be held accountable if an agent acts inappropriately. For the majority, accountability is either unclear, vaguely shared, or simply an unaddressed topic. This absence of clear responsibility exists despite significant internal pressure: 81% of respondents feel compelled to deploy agents quickly, even if governance protocols are not fully established. A large majority, 79.7%, still believe it is possible to achieve rapid deployment without compromising security. However, when viewed against the backdrop of incident rates and monitoring data, this belief seems more aspirational than evidence-based.

Regulatory Frameworks Lagging Behind

Regulation is not keeping pace with the rapid evolution of AI agents either. Only 39.5% of respondents believe current regulations adequately address AI agent risks, while 48.8% feel they cover some risks but not others. The most frequently cited regulatory gaps—concerning data access and privacy within agentic systems, how agents handle sensitive information, and accountability for agent-induced harm—mirror the issues observed in the incident data. Regarding organizational readiness, only 30% of organizations consider themselves very prepared to manage agents as distinct, authenticated entities with their own identities. Another 60% describe themselves as only somewhat prepared, and 8% admit to being entirely unprepared.

Gravitee, a company with extensive experience in API management, has long focused on building infrastructure that enables large organizations to control who or what can access specific systems and under what conditions. The company's core argument, emphasized in both its report and recent documentary work, is straightforward: APIs have gateways, human employees have managers, but AI agents are a new class of enterprise actor largely operating without comparable oversight. The survey data, originally reported by TechCrunch, strongly supports this assertion.

Why it matters

The findings from Gravitee's report underscore a critical challenge for industries heavily reliant on data and complex operations, such as telecommunications, data centers, and advanced manufacturing. The rapid deployment of AI agents without commensurate control and accountability structures introduces significant operational risks. For telco and data center operations, unmonitored AI agents could lead to network misconfigurations, data breaches, or service disruptions. Technicians in the field could find themselves troubleshooting issues caused by autonomous systems operating outside established protocols. This highlights an urgent need for robust AI agent management frameworks, clear lines of accountability, and integrated monitoring solutions to prevent potential systemic failures and ensure the reliability and security of critical infrastructure.

#ai agents#enterprise ai#ai governance#ai security#risk management#digital transformation

More from Trends

RSS