Quick Facts
- 85% of IT professionals say every AI agent has a named owner, but only 42% say ownership is actually clear, a 43-point gap from Ivanti’s 2026 AI Maturity Report.
- Organizational leaders are nearly twice as likely to hide their AI use as other employees, with 52% of those leaders doing it for a self-described “secret advantage.”
- Gartner predicts the average Fortune 500 enterprise will run more than 150,000 AI agents by 2028, up from fewer than 15 in 2025.
A new survey exposes a wide gap between what IT teams believe about AI agent governance and what is actually happening inside their organizations. Ivanti’s 2026 AI Maturity Report, drawn from 3,900 employees across six countries including 1,500 IT professionals, found that 85% of IT staff claim a named owner exists for every AI agent in their environment. Only 42% say that ownership is actually clear.
That 43-point gap means most enterprises are operating on assumption rather than documented accountability. Among companies that have formal AI policies, just 24% of employees say those policies are followed consistently day to day.
Leaders Are the Source of the Problem
The Ivanti data points directly at the executive suite. Organizational leaders are nearly twice as likely to hide their AI use compared to all other employees, 42% versus 23%. Of those leaders concealing usage, 52% say they do it to gain a competitive edge inside their own company.
That behavior undermines governance from the top down. When leadership bypasses oversight, security teams lose visibility into what data is being processed and where it is going.
Sam Evans, CISO at Clearwater Analytics, described the stakes plainly. “The worst possible thing would be one of our employees taking customer data and putting it into an AI engine that we don’t manage,” Evans told VentureBeat. His firm’s platform supports $8.8 trillion in assets.
The Scale of Agent Sprawl
The governance problem is growing faster than most organizations can respond. CrowdStrike sensors currently detect more than 1,800 distinct AI applications running on enterprise devices, representing nearly 160 million unique application instances across its customer base.
Itamar Golan, CEO of Prompt Security, which was acquired by SentinelOne, told VentureBeat his team catalogs 50 new AI apps every day and has already logged more than 12,000. “Around 40% of these default to training on any data you feed them,” Golan said, meaning corporate intellectual property can end up embedded in third-party models.
Microsoft Copilot Studio users created more than 1 million AI agents in a single quarter, a 130% increase from the prior period. Gartner predicts that by 2028, 25% of enterprise breaches will trace back to AI agent abuse. Only 13% of organizations believe they currently have adequate agent governance in place.
Identity and Ownership Are Broken
The ownership problem runs deeper than policy. A Gartner survey of 335 identity and access management leaders found that IAM teams are responsible for only 44% of an organization’s machine identities. The rest operate outside security’s line of sight.
A separate report from Gravitee found that only 7.2% of organizations have a named individual with formal accountability for AI agent behavior. Most describe accountability as unclear, shared but undefined, or simply undiscussed.
Cisco President and CPO Jeetu Patel, speaking at RSAC 2026, framed the production gap in stark terms. He said 85% of enterprises are running agent pilots while only 5% have reached production. “That 80-point gap is a trust problem,” Patel said.
The Business Risk Is Real
CrowdStrike CTO Elia Zaitsev described why the AI attack surface is hard to contain. “It looks indistinguishable if an agent runs your web browser versus if you run your browser,” Zaitsev told VentureBeat. “Observing actual kinetic actions is a structured, solvable problem. Intent is not.”
CrowdStrike CEO George Kurtz noted at RSAC 2026 that the fastest recorded adversary breakout time has dropped to 27 seconds, with the average now 29 minutes. IBM’s 2025 Cost of a Data Breach report puts the global average breach cost at $4.4 million.
For founders and executives building on AI agents or deploying them internally, the Ivanti data is a direct challenge. Confidence in governance without documented ownership is not governance. It is exposure.
Read more: 85% of IT teams claim every AI agent is under control. Only 42% actually know who owns them.
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
