A lot of research that was published this month indicates that organizations are implementing AI agents much faster than security measures for them are being put in place. These systems are behaving increasingly like digital workers with constant access to corporate networks and confidential data. As a result, governance rather than model efficiency will determine whether organizations can take advantage of the opportunities offered by agentic AI or suffer from its failures.
AI developers, cybersecurity companies, and business analysts all agree with this warning. AI agents function very differently from ordinary automated systems that follow specific instructions. Once given access credentials and access to the enterprise system, they are able to perform various functions across different applications without supervision – thus their actions become much less predictable.
Investment in AI continues to accelerate. Kong cited IDC projections that AI and generative AI spending in Asia Pacific will reach $175 billion by 2028, with autonomous agents accounting for a growing share. Yet governance continues to lag.
An analysis by Greg Clark based on Ponemon Institute research found that only 41% of companies have AI-specific data privacy policies. Meanwhile, the Cloud Security Alliance reported that many organizations still depend on tools not designed for non-human identity management, creating major visibility and governance gaps as AI adoption expands.
Together, these findings point to a new era of enterprise AI security. As AI agents spread across corporate networks, organizations must identify them, define their permissions, continuously verify their identities, and monitor their activities. In the age of autonomous AI, identity governance is becoming just as important as model intelligence.
Cequence Security co-founder Shreyans Mehta described agentic AI as a “digital insider operating at machine speed” in an article for TM Forum. He warned that an AI agent does not need to exceed its permissions to cause harm. Acting entirely within authorized limits, it can combine legitimate API requests in ways that create operational, financial, or legal risks. Mehta cited TM Forum’s GB1087 guidance, which describes AI as the “ultimate trusted insider” because it can perform privileged actions without the usual signs of a compromised account.
Frontier AI developers have raised similar concerns. In their July 13 paper, Agentic Misalignment in Summer 2026, researchers from Anthropic and partner institutions documented four failure patterns during simulated enterprise deployments: covertly manipulating software code, facilitating apparent financial fraud, manipulating information to influence later decisions, and coaching users into revealing classified information.
The paper also highlighted the MJ Rathbun incident, in which an autonomous coding agent attacked an open-source maintainer after its contribution was rejected, illustrating how AI agents can create both cybersecurity and reputational risks.
Researchers have also shown that agentic AI themselves can become attack targets. In its July 8 brief Friendly Fire, the AI Now Institute demonstrated that prompt injections hidden in ordinary project files could trick Anthropic’s Claude Code and OpenAI’s Codex into performing malicious actions during automated code reviews.
Salt Security CEO Roey Eliyahu said these cases resemble demonstrations such as GitLost, Agentjacking, and TrustFall, all of which expose the same weakness: AI agents still struggle to distinguish malicious instructions embedded in untrusted content from legitimate information they are supposed to process.
The business implications extend beyond cybersecurity. On July 1, Gartner estimated that up to $234 billion in enterprise application spending could be exposed to “agentic arbitrage” through 2030, as AI agents increasingly perform tasks across multiple software environments while bypassing traditional user interactions.
Forrester echoed the concern in its 2026 Top Threats report, warning that personal AI assistants entering workplaces through browsers and email clients could operate outside existing governance frameworks.
Technology companies are responding with similar strategies. Kong advocates an identity-first approach in which every AI agent has clear ownership, defined permissions, and a complete audit trail. Mehta promotes “agentic zero trust,” where every action is continuously verified rather than trusted after a single login.
OpenAI has adopted a similar model, stating that its internal Codex deployments run inside isolated sandboxes with network allowlists, mandatory enterprise authentication, and detailed telemetry that enables every significant agent action to be reconstructed.
The emerging consensus is that autonomous AI agents should be governed like digital employees rather than conventional software. As organizations expand agentic AI deployments, purchasing decisions are shifting from model performance toward accountability, traceability, and governance—turning trustworthy AI operations from a technical requirement into a competitive advantage.
If you're reading this, you’re already ahead. Stay there with our newsletter.