A new survey-based report from the Cloud Security Alliance explores how organizations are currently managing AI agent governance. While most enterprises report strong visibility into their agents, the data reveals widespread shadow AI and frequent security incidents.
Key findings in the report include:
- The majority of organizations (53%) operate agents autonomously for low-risk tasks with human review for higher-risk actions. Only 13% of organizations report fully autonomous models. Monitoring is also largely periodic (59%), reinforcing a governance model based on checkpoints and escalation.
- While 68% report high confidence in their visibility, 82% have discovered shadow AI agents in the past year. These agents most commonly appear in internal automation environments (51%) and LLM platforms (47%).
- Organizations are improving front-end lifecycle practices. The majority (59%) report clear documentation of agent purpose and 68% conduct permission reviews. However, only 21% have formal decommissioning processes. Just 19% express high confidence that they fully retire their agents.
- Organizations are converging on action risk (63%) and human authorisation (53%) as the primary signals for governing agent behaviour.
- Nearly 79% view context-aware controls as important or very important, and 66% report clear guardrails defining agent boundaries.
- AI agent-related incidents are common, with 65% reporting at least one in the past year. These incidents have tangible business impact, including data exposure (61%) and operational disruption (43%). As a result, organizations are prioritising monitoring (28%), risk management (29%), and permission control (19%).






