There's a telling disconnect at the heart of enterprise AI right now. Ask most IT leaders whether their AI agents are under control and the majority will confidently say yes. Ask them to name who is actually accountable for those agents' behaviour — who owns them, monitors them, and answers when something goes wrong — and the conversation gets uncomfortable fast.

This isn't a hypothetical problem. It's a crisis hiding in plain sight, dressed up as confidence. And for the growing number of organisations racing to deploy autonomous AI agents across their operations, the gap between perceived control and actual governance accountability could cost them dearly.


The False Confidence Problem in AI Agent Governance

IT leaders are optimistic about their AI posture. But that optimism is increasingly decoupled from reality.

According to Gravitee's State of AI Agent Security report — based on a survey of 750 senior technology leaders across the UK and USA — enterprise AI agent fleets roughly doubled since late 2025. Confidence in security has risen. But monitoring coverage, accountability structures, and pre-deployment controls have barely moved. Organisations are becoming more comfortable with a risk they haven't actually reduced.

This pattern — rising confidence alongside stagnant controls — is precisely what makes the ownership question so dangerous. When leaders feel secure without actually being secure, they stop asking the hard questions.

Only 7.2% of organisations have a named individual with formal accountability for AI agent behaviour. The majority describe accountability as unclear, shared but undefined, or simply undiscussed. This is the governance crisis inside the security crisis.

The ownership illusion stems from a subtle but critical confusion.

Earlier surveys suggested ownership existed — with CTOs (28.2%) and CISOs (26%) named as accountable parties. But later questioning revealed that what looked like named ownership was, for most organisations, actually informal or undefined. That earlier framing exposed optimism; the later framing exposed the reality behind it.


The Scale of the Problem: AI Agent Sprawl Is Here

Before tackling governance, it's worth understanding just how rapidly the landscape has shifted — because the scale of deployment is outrunning every framework designed to manage it.

Gartner predicts that by 2028, an average global Fortune 500 enterprise will have over 150,000 agents in use, up from less than 15 in 2025, generating significant agent sprawl, IT complexity, and management challenges.

Already, 98% of organisations report unsanctioned AI use, and 49% expect shadow AI incidents within the next 12 months. Gartner predicts 40% of enterprise applications will feature task-specific AI agents by end of 2026 — up from under 5% in 2025.

According to Gravitee's State of AI Agent Security 2026 report, more than 3 million AI agents are now operating within corporations. Only 47.1% are actively monitored or secured — leaving an estimated 1.5 million agents running without oversight, accessing sensitive data, making decisions, and connecting to critical systems with no audit trail.

The deployment pattern is familiar.

AI agent sprawl — where teams across the enterprise deploy autonomous agents without centralised oversight — is becoming the defining governance challenge of 2026.

A marketing team builds a content agent. Sales deploys one for lead scoring. Finance automates invoice processing. Each decision seems reasonable in isolation. Together, they create an unmanaged fleet operating in the shadows.

According to Forrester's State of AI Survey 2025, while over 70% of firms have AI in production, most lack the strategic clarity and governance to manage it — resulting in shadow AI, where 68% of employees use unsanctioned tools and 57% input sensitive corporate data into them.


Why Ownership Gaps Are a Security and Financial Time Bomb

The absence of clear AI agent ownership isn't just an administrative inconvenience — it has direct, measurable financial consequences.

A Dark Reading poll found that 48% of cybersecurity professionals now identify agentic AI and autonomous systems as the single most dangerous attack vector. According to IBM's 2025 Cost of a Data Breach Report, shadow AI breaches cost an average of $4.63 million per incident — $670,000 more than a standard breach.

63% of breached organisations either don't have an AI governance policy or are still developing one. Of those organisations that do have AI governance policies in place, only 34% perform regular audits for unsanctioned AI.

One in five organisations have experienced a breach linked to shadow AI, and those with high levels of shadow AI spent an average of $670,000 more on breach costs. Among organisations that experienced an AI-related breach, 97% lacked proper AI access controls, and 63% had no AI governance policy at all — or were still developing one when the breach occurred.

The threat is not just external.

Unlike shadow AI tools that merely answer questions, shadow agents are granted persistent permissions to your data. They move files, send emails, update records, and even communicate with customers.

When they operate without a named owner, there is no one to call when they do something unexpected — and no accountability trail when regulators come asking.

Without clear accountability, agent-related incidents have no owner.

That is not a metaphor. It is a literal operational gap.


The Identity Crisis: Who — or What — Is Your AI Agent?

One of the most underappreciated dimensions of AI agent governance is the identity problem. Agents aren't users. They're not applications in the traditional sense. They exist in a grey zone that most enterprise identity and access management systems were never designed to handle.

Enterprises can't move AI agents from pilot to production because identity governance isn't there yet. Teams are sharing human credentials and access tokens with agents because no alternative exists for securing identity within autonomous workflows.

Only 18% of security leaders expressed high confidence that their current identity systems can effectively handle agent identities.

According to Entro Labs' H1 2025 research, non-human identities now outnumber human identities at a ratio of 144 to one in enterprise environments — up 44% from the prior period.

Each of those non-human identities is a potential surface for attack, misconfiguration, or undetected data exfiltration.

Unlike traditional AI systems, agentic AI operates autonomously, persists across sessions, and interacts directly with sensitive data and enterprise systems. Six trends are shaping agentic AI governance in 2026 and beyond: AI agents as digital identities, governance shifting to the data layer, real-time AI risk monitoring, agent observability, AI compliance automation, and unified AI access governance.


The Regulatory Reality: Governance Is Becoming Non-Negotiable

For organisations that still view AI agent governance as optional, the regulatory clock is ticking loudly.

Singapore's Model AI Governance Framework for Agentic AI, launched in January 2026 as the world's first national governance framework specifically designed for agentic systems, provides guidance across four dimensions — risk bounding, human accountability, technical controls, and end-user responsibility — and establishes that organisations remain legally accountable for their agents' behaviours regardless of voluntary compliance.

EU AI Act enforcement is operational: prohibited practices have been banned since February 2025, penalties have been active since August 2025, and high-risk obligations will take effect in August 2026.

By the end of 2026, Forrester projects ungoverned use of generative AI will cost B2B companies more than $10 billion in enterprise value, driven largely by legal settlements and fines.

Enterprises that can demonstrate governed, auditable AI agent deployments will navigate this regulatory environment. Those running ungoverned agent sprawl will face enforcement actions when something goes wrong.

New Cloud Security Alliance research shows that governance has become the main factor separating teams that feel prepared from those that do not. Governance maturity stands out as the strongest indicator of readiness. About one quarter of surveyed organisations report having comprehensive AI security governance in place — the remainder rely on partial guidelines or policies still under development.


Practical Tips: How to Close the AI Agent Ownership Gap Right Now

The good news? This is a solvable problem. You don't need a multi-year transformation programme to begin taking control. Here are six actions you can take immediately.

1. Build a Complete AI Agent Inventory

You can't govern what you can't see.

Start by conducting a full audit of every AI agent deployed across your organisation — sanctioned or otherwise. This includes third-party tools connected via OAuth, API tokens, and browser-based agents. Use network traffic analysis, OAuth audit logs, and department-level interviews.

2. Assign a Named Owner to Every Agent

The NIST AI Risk Management Framework's GOVERN 2.1 principle states that all AI risk roles and decision-making authority must be clearly documented and understood across the organisation — meaning every AI system needs a named owner who is accountable for its outputs.

No agent should be in production without a named human accountable for its behaviour.

3. Implement a Formal RACI Model

A RACI model (Responsible, Accountable, Consulted, Informed) is a practical way to formalise governance, especially as AI initiatives span multiple teams and business units.

An AI governance RACI for each agent should assign who owns intake, data and knowledge sources, security controls, legal/compliance sign-off, monitoring, and incident response.

4. Enforce Least-Privilege Access for Every Agent

Managing human users and AI agents in separate systems creates gaps and inconsistencies. A unified access governance model ensures that all actors — employees, contractors, third parties, and AI agents — are governed under the same framework, with consistent enforcement of least-privilege access.

5. Build Human-in-the-Loop Controls Before Scaling

42% of regulated enterprises plan to introduce manager features such as approvals and review controls, compared to only 16% of unregulated enterprises. Governance is emerging as a hard requirement in high-risk environments.

Don't wait until you're regulated to adopt these controls — treat them as table stakes for any production deployment.

6. Conduct Regular Agentic Security Assessments

60% of organisations have not conducted a formal agentic or AI security risk assessment in the last 12 months.

Schedule quarterly reviews of your agent fleet, reviewing permissions, monitoring coverage, incident history, and ownership assignments. Treat it with the same rigour as a software vulnerability assessment.


Conclusion: Control Is Not the Same as Accountability

The confidence that most IT leaders express about their AI agents is not entirely misplaced. Many organisations are doing remarkable things with agentic AI, and the productivity and ROI gains are real.

Organisations project an average ROI of 171% from agentic AI deployments, with US enterprises forecasting 192% returns.

But confidence without accountability is not governance — it's exposure in disguise. The data is unambiguous:

the monitoring mean has barely moved even as enterprise agent fleets have doubled, because deployment velocity is dramatically outpacing governance implementation.

Feeling in control is not the same as being in control, and the organisations that conflate the two will bear the costs when an incident occurs.

The question isn't whether your AI agents are doing their jobs. The question is: when one of them causes a breach, makes a damaging decision, or violates a regulation — do you know who owns it?

If the answer isn't an immediate, confident yes, then your governance framework needs attention now.

Ready to take control of your AI agent estate? Audit your deployments, assign clear ownership today, and build the governance foundations that protect your organisation — before a regulator, an attacker, or an unsupervised agent does it for you. The time to act is not after the incident. It's right now.