Fifty-seven percent of organizations now deploy AI agents for multistage workflows, and 81% plan to expand that usage in 2026, according to an Anthropic survey. The problem: the governance infrastructure to manage those agents barely exists. A Cloud Security Alliance survey cited by Forbes found that 82% of enterprises had discovered at least one AI agent or autonomous workflow previously unknown to their security or IT teams. Sixty-five percent reported incidents including data exposure.

The numbers describe a shadow workforce. Agents are no longer confined to drafting emails and summarizing documents. They schedule appointments, update customer records, qualify sales leads, and complete work that was previously assigned to employees. Nextiva markets its XBert AI assistant as an “AI employee” capable of handling customer calls, scheduling, and lead qualification across connected business systems.

The Identity and Permissions Problem

The challenge is straightforward: if an agent has access to a connected account, it can take any action that account permits, even if the company never intended to grant that authority. Human roles carry informal boundaries. Agent permissions do not.

“Trust in an AI agent works the same way trust in an employee does. It has to be earned and it has to be verifiable,” Yaniv Masjedi, chief marketing officer at Nextiva, told Forbes. “The AI never owns the outcome. The business does. If your agent makes a promise, that’s your promise.”

Okta research quantifies the gap in basic controls: only 47% of senior executives said they could identify all agents in their environments, 46% could control agent access, and 45% could authorize individual agent actions.

The Offboarding Problem Nobody Has Solved

Anupam Satyasheel, CEO of Occams Advisory and co-founder of Occams AI, argued in Forbes that enterprises should treat agents with the same rigor as employees: a manager of record, scoped job descriptions, expiring credentials, written deferral thresholds, and offboarding processes.

“A human employee’s badge is deactivated on their last day. Most agent credentials have no last day,” Satyasheel told Forbes.

Imran Siddique, chief platform officer at Opaque Systems, framed the tradeoff: “Scope them too tightly and you’ve built an expensive way to run a script. Scope them too loosely and you’ve got no governance at all.” His recommendation: distinct machine identities and explicit, enumerated capabilities rather than broad permissions inherited from human users.

Standards Are Forming, Slowly

NIST published a concept paper in February 2026 examining how existing identification, authorization, and auditing standards should apply to agents. Microsoft, Okta, and others are building systems that assign agents distinct identities and named owners with limited permissions.

The identity binding startup Sumsub has proposed a “Know Your Agent” framework, but most organizations are still developing basic governance systems, not implementing them.

The Compliance Clock

The 82% discovery rate means enterprises are running agents they cannot audit. For organizations subject to SOX, GDPR, or sector-specific regulations, unauditable autonomous systems making decisions about customer data, financial records, or business processes represent a liability exposure that grows with every new agent deployment. The gap between adoption velocity and governance maturity is widening, not narrowing.