AI agents expose dangerous governance gaps for CISOs

Enterprise security leaders are confronting a governance crisis as AI agents proliferate faster than identity and access controls can keep up[1][3][6]. Okta’s Global CISO Insights 2026 survey of 306 CISOs and security executives found that only 47% are confident they can identify every AI agent in their environment, 46% can control what those agents connect to, and 45% can authorize what individual agents are allowed to do[1][6][9]. More than four in five respondents worry their AI agents are running with excessive or unreviewed access, turning non-human identities into a frontline risk for modern enterprises[7][9].

Unlike traditional applications, AI agents are wired directly into productivity suites, collaboration tools and business systems, often with broad access to sensitive data and APIs[1][3]. Okta’s research shows roughly one in five organizations still let agents operate using shared credentials or highly permissioned service accounts, a pattern that makes it almost impossible to trace or constrain individual agent behavior[3][7][9]. A quarter of organizations apply human-centric identity lifecycles to AI agents, despite the fact that agents can be spawned, reconfigured and retired far more rapidly than employees, leaving gaps in onboarding, review and deprovisioning[7][9].

Shadow AI compounds the problem, as employees quietly connect unsanctioned agents and tools to corporate systems in the absence of clear governance frameworks[1][3]. Okta reports that 58% of executives now cite AI governance and oversight as their top security concern related to AI agents, yet fewer than half say their boards view AI security as a business enabler rather than a drag on innovation[12][8]. Only about a third of CISOs feel aligned with their boards on acceptable AI risk, reinforcing the sense that security teams are accountable for agents they cannot fully see or control[8][9].

Recent technical disclosures underscore how fragile the underlying agent infrastructure can be when misconfigured or exposed to untrusted networks[11][14]. The Cloud Security Alliance has highlighted CVE-2025-6514, a CVSS 9.6 vulnerability in mcp-remote versions 0.0.5 through 0.1.15 that allows arbitrary OS command execution if an MCP client connects to a malicious or compromised server, a scenario made more likely by insecure HTTP deployments and man-in-the-middle attacks[11]. Separately, reporting on inference platforms describes DeepSeek Harness (CVE-2026-82533) as a CVSS 9.4 sandbox escape and IBM Langflow (CVE-2026-81204) as a CVSS 9.8 unauthenticated remote code execution flaw during graph construction, illustrating how agent runtimes and orchestration tools are becoming regular targets[14].

For defenders, these trends mean identity stacks originally built for human users are being stress-tested by autonomous software that behaves more like a privileged insider than a traditional app[1][7][10]. Okta’s guidance urges organizations to get full visibility into their AI agent population, replace shared credentials with fine-grained, per-agent identities, and treat agents as high-risk accounts with tightly scoped permissions and rigorous monitoring[1][7][10]. Security teams are also encouraged to bring shadow AI under governance instead of simply blocking it, by creating repeatable processes for evaluating, onboarding and supervising new agent tools so staff have sanctioned options that match the pace of innovation[1][7].

In practical terms, that means CISOs should push identity and platform teams to inventory where every agent runs, what systems it connects to and what data or operations it can touch, then fold those findings into risk assessments alongside known high-severity CVEs affecting agent tooling[9][11][14]. Organizations that can answer those questions and enforce least-privilege access for non-human identities will be better positioned to harness AI agents as a strategic advantage instead of a blind spot that attackers can exploit[1][10][12].

References

  1. Global CISO Insights 2026 – Okta
  2. Shadow AI, leadership resistance make AI governance tough for …
  3. Fewer than half of CISOs can identify where their AI agents …
  4. Loss of control: The AI agent governance crisis
  5. AI Governance Lacking in 90% of Companies
  6. AI Governance Gap: 81% of CISOs Fear Agents They Can’t Fully See
  7. AI Agents at Work 2026: Securing the agentic enterprise
  8. Agents in the Wire: AI Agents as Enterprise Insider Threats
  9. Businesses at Work 2026: Closing the identity gap in …
  10. Four Weeks, Four Critical CVEs: AI Inference Infrastructure Is Now a Regular Target

Comments

No comments yet. Why don’t you start the discussion?

Leave a Reply