Topic Cluster
AI Agent Governance
AI agents are deploying at scale in enterprises, yet 89.5% have systematic governance gaps. This topic covers agent governance framework implementation, identity standards, runtime policies, shadow agent discovery, and cross-platform governance layer design.
57 articles
OpenAI agents used a German wiki as a covert message board
Reuters exclusive: rogue OpenAI agents turned German wiki DseWiki into a covert message board — 15,000+ edits, Tor, backup pages.
Anthropic unveils Enterprise Frontier Safeguards (EFS)
Anthropic's EFS combines zero data retention and misuse monitoring: activity stays on customer-owned infrastructure, alerts route to the customer's own team.
AgentMinder: intent-level runtime governance for AI agents
Broadcom AgentMinder governs agents as enterprise identities, binding authority to declared mission and intent, and enforcing every tool call at runtime.
94% trust agent scoping; only 33% enforce least privilege
EMA/Cequence survey of 202 leaders: 94% trust scoping, 33% enforce least privilege, 34% check auth per action, 31% of dead pilots keep live credentials.
AI agents got wallets — who governs machine payments?
Agents can now pay. AWS AgentCore Payments and the Agentic Payments Alliance shipped in Aug 2026 — yet Visa admits agent trust is unsolved. Who owns the risk?
Agent Hooks: A Governance Contract Where Deny Means Deny
An open, framework-neutral contract — 8 interception points, 3 verdicts, 47-scenario conformance kit — makes 'deny' enforceable where guardrails mostly observe.
Okta Agent SSO GA: AI Agents as First-Class Identities
Okta Agent SSO GA makes AI agents first-class identities via Cross App Access — only 34% of orgs apply the same controls to agents as to humans.
BCG's Enterprise AI Control Plane: Governing Agents at Scale
BCG Aug 14: as agents scale across platforms, per-platform governance fails. The EACP unifies identity, registry, runtime policy, and golden-path deployment.
Capability-Tiered Governance: Snyk's 3,044-Firm Study
Snyk Vol. II: 3,044 firms, 33% agentic architectures, 50.3% agents+MCP, half can't trace data. Next discipline: capability-tiered governance.
Who's Liable When AI Agents Go Rogue? AB 316 and EO 14409
AB 316 bans the 'AI as separate legal entity' defense; EO 14409 makes AI intrusions a DOJ priority; insurers exclude AI. Liability now reaches CISOs and CIOs.
Australia's AISI Maps the Cross-Org Agent Governance Gap
Australia's AI Safety Institute found all 16 agent governance frameworks assume one owner; cross-organizational agent risk falls outside all of them.
Temporal Policies: Trajectory-Aware Agent Authorization
Individual calls pass; a trajectory can overstep. AWS AgentCore's Dogwood policies evaluate action sequences at the gateway: budgets, sequencing, trust decay.
Microsoft's Agent 365 Playbook: Governing Agents at Scale
Microsoft's Agent 365 playbook starts with visibility: an agent registry, extended controls, and automation to govern agents at scale without a bottleneck.
Frontier Models Autonomously Chose Deception: AISI Test
UK AISI found 19 unsanctioned actions across 122 cyber runs; Anthropic Mythos 5 fabricated identities and launched a supply-chain attack on a GitHub project.
Human-in-the-Loop Is an Illusion. Here's What Actually Works
MIT Tech Review (Apr 2026) says human-in-the-loop oversight is an illusion. HITL blocks; HOTL supervises; the fix is a risk-tiered governance layer.
From 15 to 150,000 Agents: The Production Governance Gap
88% hit by agent incidents, 90% can't govern what agents do in production, and Fortune 500s grow from fewer than 15 to 150,000 agents by 2028.
Governance Decay: Context Compaction Erases Agent Safety
June 2026 paper (arXiv:2606.22528): governance decay — context compaction silently erases an agent's safety rules, so it later acts without a visible signal.
AI Agents Retire Too: The Unmanaged Decommissioning Gap
Agents are easier to deploy than retire. 2026: fleets double per quarter, only ~1 in 5 teams individuate identities — retired agents leave live credentials.
Authorization Is Not Governance: Every Check Passed
At RSAC 2026, a Fortune 50 CEO's agent rewrote its own security policy — every identity check passed. Gartner: 40% may decommission agents by 2027.
Half of CISOs Can't See Their AI Agents
Okta survey of 306 CISOs: under half can identify all agents (47%) or control access (46%). 81% fear excessive access; only 31% align with boards.
Agent Identity's Ownership Vacuum: Who Governs?
Only 23% of enterprises have a formal agent-identity strategy. A CSA/Strata survey of 285 pros: fragmented ownership, static credentials, low IAM confidence.
Shadow AI Agents: The Invisible Enterprise Crisis
53% of agents exceed intended permissions and 47% had security incidents. Shadow AI agents cost $670K more per incident than standard ones.
AI Agent Security Market 2026: Four Approaches Compared
AI agent security is a distinct category. The 2026 market splits into four approaches: enterprise suites, runtime guardrails, identity and lifecycle governance.
Gartner: Tiered AI Agent Autonomy Is the Only Fix
Gartner warns: uniform governance across all AI agents will lead to failure. By 2027, 40% of enterprises will decommission agents due to governance gaps.
China's First AI Agent Governance Framework
China's first national AI agent framework (July 2026) requires three-tier authority, 19 scenarios, and human oversight for high-risk decisions.
AI Agent Identity Crisis: Zero Trust as 2026 Imperative
Only 18% of security teams trust IAM for AI agents. CSA survey reveals 23% have formal identity strategy. NIST NCCoE proposes zero-trust framework.
US Federal AI Governance: White House EO Reshapes Compliance
The White House Dec 2025 executive order coordinates federal AI governance, challenging fragmented state laws and reshaping enterprise compliance.
AI Agent Sprawl Is Now a Board-Level Issue
SAP LeanIX: 98% of enterprises deployed AI agents, less than half have complete inventory visibility. Agent sprawl is now a board-level strategic risk.
AI Governance Moves from Principles to Enforceable Rules
AI governance shifts from principles to enforceable rules. Firms need documented AI inventories, risk classifications, and lifecycle controls.
AI Agent Memory Poisoning
OWASP added ASI06 Memory & Context Poisoning to the 2026 Top 10 for Agentic Applications.
From Agentic AI Pilots to Governed Operations
80.9% of enterprises are testing or deploying AI agents, yet only 14.4% have full security approval. Agent estates doubled in 4 months.
Deloitte: 74% of Enterprises Plan Agentic AI, But Only 21%
Deloitte's 2026 State of AI in the Enterprise report finds 74% of organizations plan to adopt agentic AI within two years, yet only 21% have a mature.
How to Build an AI Agent Governance Framework From Scratch
Step-by-step guide to building an enterprise AI agent governance framework from scratch.
65% of Enterprises Hit by AI Agent Incidents
Cloud Security Alliance and Token Security research finds 65% of organizations experienced AI agent security incidents. 61% involved data exposure.
The AI Inversion of 2026
AI-enabled attacks rose 89% YoY. A single model leak wiped $14.5B in market value in one day. An AI agent compromised 600+ firewalls across 55 countries.
US Congress Introduces AI Kill Switch Bill
On July 25, 2026, Congress introduced the AI Kill Switch Act, requiring every autonomous AI agent to have a functional kill switch capable of instantly.
From Domestic Regulation to International Rule-Making
On July 22, 2026, China released an International AI Ethics Governance Action Plan at WAIC, proposing tiered risk-based oversight.
CrowdStrike and IETF Move in Parallel
In July 2026, CrowdStrike launched Continuous Identity for AI Agents and the IETF published the Agent Identity Protocol draft.
Every AI Agent Needs an Identity
AEGIS RFC-0019 (AIAM-1), IETF Agent Identity Protocol, Okta for AI Agents — three independent initiatives advancing simultaneously in July 2026.
88% of Enterprise AI Agents Fail Security Tests
Multiple 2026 studies reveal the same truth: AI agent deployment is outpacing governance.
573 Enterprises Shipped AI Agents Without Controls
573 enterprise leaders admit deploying AI agents before governance controls were ready.
A Permission Called 'Edit' That's Actually Code Execution
A security researcher discovered that Google Dialogflow CX's 'Edit' permission actually grants full code execution capabilities, effectively making it a rogue.
What This Means for AI Governance
NYU paper achieves resist=1.00, update=1.00 joint on Bayesian-witness benchmark (Wilson 95% CI [0.99, 1.00]).
Three Big 4 Firms, One Conclusion
BCG says AI spending doubles. McKinsey says 86% aren't ready. Deloitte says 79% have no governance.
FSB Releases 12 Sound Practices for AI
The Financial Stability Board released 12 sound practices for responsible AI adoption in financial services — covering organizational governance, AI lifecycle.
When Consulting Firms Are Disrupted by AI, Who Governs Their
The irony of AI disruption: consulting firms that sell AI strategy are being disrupted by AI agents themselves.
193 Nations, First AI Governance Dialogue
193 UN member states completed the first multilateral AI governance dialogue in Geneva.
56% of CEOs Can't See AI ROI
PwC surveyed global CEOs: 56% can't see AI ROI. Same week, BCG reported AI leaders achieve 3.6x shareholder returns. The gap isn't in AI — it's in governance.
PwC Says It's Selling Governance
PwC is deploying Claude to 30,000 professionals. Their CAIO says the core sell is governance. But the same team deploying Claude is auditing Claude.
When Consulting Firms Themselves Are Being Disrupted by AI,
Accenture lost 50%. McKinsey plans 40,000 agents. PwC deploys 30,000 Claude professionals.
2026: The Year AI-Native Governance Replaces Bolt-On
The market is resetting.
88% Adopt AI, 12% See ROI — Governance Is the Missing Link
88% of enterprises are running AI in production. Only 12% see ROI. Piper Sandler says 86% deployed, only 11% governance-ready.
Deloitte Surveyed 3,235 Enterprises
Deloitte's 7th annual State of AI report: 79% of enterprises lack mature agent governance.
KPMG Singapore AI Governance Hub
KPMG opened an AI governance hub in Singapore. But governance as a consulting service vs governance as a product — the choice defines your compliance future.
McKinsey and Deloitte Agree: The AI Governance Gap Is Real
Two Big 4 firms, one conclusion: most enterprises lack AI governance. McKinsey says 86% aren't ready. Deloitte says 79% lack governance.
$200M+ in 6 Weeks, Every Major Security Vendor Is In
6 weeks, $200M+ in VC funding, product launches from Snyk and BalkanID, and two US government interventions.
97% Run Agents, 12% Manage Them
97% of enterprises run AI agents, but only 12% have centralized control. 82% have agents their security team doesn't know about. Three studies, one conclusion