Enterprise AI Agents: Closing the Governance Gap to Mitigate Emerging Risks

Enterprises are rapidly deploying autonomous AI agents, creating critical security vulnerabilities due to inadequate governance. Immediate action is required to establish robust control mechanisms and address the widening gap between adoption and security.

The Rapid Rise of Autonomous AI Agents

Enterprises are rapidly deploying AI agents, systems that autonomously plan, execute multi-step tasks, and adapt behavior without constant human intervention. Gartner projects that 40% of enterprise applications will embed task-specific AI agents by the end of 2026, a significant increase from under 5% in 2025 [Source 1, 6]. This rapid adoption is introducing new security challenges. A mid-2025 Cisco/Splunk CISO Report found that 86% of CISOs fear agentic AI will increase social engineering attack surfaces, and 82% worry about faster adversarial persistence [Source 1].

The Widening Governance Gap

Existing governance frameworks, such as NIST AI RMF 1.0 and ISO/IEC 42001:2023, were designed for AI systems whose behavior is largely known and stable at deployment, a condition autonomous agents routinely violate [Source 1]. The EU AI Act, with enforcement deadlines in August 2025 for general-purpose AI, also lacks specific definitions for agentic systems [Source 1, 6]. This leaves a significant governance gap.

By early 2026, security researchers documented approximately 8,000 Model Context Protocol (MCP) servers exposed publicly without authentication, creating direct attack surfaces for agentic systems [Source 1]. Prompt injection has also been identified as a critical attack surface in production LLM systems since 2025 [Source 1].

Critical Enterprise Security Vulnerabilities

The lack of tailored governance creates several critical vulnerabilities:

  • Identity and Authorization: AI agents present a novel identity challenge, acting on behalf of users with delegated credentials and making real-time authorization decisions. The 2026 CISO AI Risk Report found 92% of large-enterprise security leaders lack full visibility into their AI identities, and 86% do not enforce access policies for them [Source 1]. Furthermore, 70% of organizations grant AI systems more access than a human employee performing the same job [Source 4].
  • Audit Opacity: Autonomous agents generate complex audit trails across distributed tool ecosystems, with intermediate reasoning states often inaccessible to conventional logging. A March 2026 EY/AIUC-1 Consortium survey revealed only 38% of organizations monitor AI traffic end-to-end, and just 17% continuously monitor agent-to-agent interactions [Source 1].
  • Shadow AI: Unsanctioned AI usage is already linked to breaches and higher incident costs. SentinelOne reports that 72% of organizations have experienced or suspect a breach involving non-human identities, yet only 44% have implemented policies to manage AI agents [Source 4].

The Urgent Need for Action

The U.S. government formally acknowledged this structural gap with the CAISI Request for Information (RFI) in January 2026, followed by NIST's AI Agent Standards Initiative in February 2026 [Source 1]. However, substantive NIST deliverables and international standards are still years away [Source 1].

Enterprises cannot wait for future standards. The immediate deployment of AI agents without adequate security controls creates an urgent need for organizations to establish robust governance and control mechanisms now, focusing on agent discovery, identity management, runtime guardrails, and continuous monitoring [Source 5].

Sources