82% are confident, 14% have approval
Executives report confidence that their policies cover unauthorised agent actions. Only 14.4% of organisations send agents to production with full security or IT sign-off. The gap between those two numbers is the whole enterprise agent story this year.
Two figures from this month's enterprise surveys sit badly together. 82% of executives report confidence that existing policies protect against unauthorised agent actions. Only 14.4% of organisations report sending agents to production with full security or IT approval. Separately, 94% say AI sprawl is raising security risk and operational complexity.
These are not in tension — they are the same fact
Confidence is measured at the level where policy is written. Approval is measured at the level where software ships. An executive can be entirely accurate about the policy and entirely unaware of how many agents went live without touching it. The 82% is not a delusion; it is an answer to a different question than the one that matters.
The 94% acknowledging sprawl is the tell. An organisation that knows it has sprawl and believes its policy holds is describing a policy that is not being enforced at the point of deployment.
Why agents break the usual approval path
Conventional software review has a natural checkpoint: something gets deployed. An agent is often configured rather than deployed — a connector added, a permission granted, a workflow pointed at a new tool. None of those look like a release, so none of them trip a release process.
The control that actually maps to the risk
The pattern gaining ground is an agent gateway sitting between the agent and its tools, intercepting every tool invocation before execution. It works because it is placed where the damage happens rather than where the intent is declared, and because it does not depend on anyone remembering to file for approval.
The accompanying principle is least privilege, for a blunt reason: an over-privileged agent turns a single prompt injection into a full environment compromise.
AGAT Software — AI Agent Security in 2026: What Enterprises Are Getting Wrong → · Beam — AI Agent Security in 2026: Enterprise Risks & Best Practices → · ITNET — Securing enterprise AI agents: agentic workflows 2026 → · Lyzr — Understanding Enterprise AI Agents: The 2026 Guide →