Fewer than half of CISOs can identify where their AI agents are
Enterprises spent 2025 racing to deploy AI agents. A new report by cloud-based identity and access management company Okta found that now, governance is fragmented, with most never having built the controls at the helm.
Global CISO Insights 2026, a survey of 306 chief information security officers and senior security executives across six countries, found security leaders are managing a fast-growing population of AI agents they can’t fully see, catalogue, or contain.
As the company explains, “you can’t secure what you can’t see.”
The confidence gap shows up across the three questions that matter most for anyone deploying agents.
There are three key questions that anyone deploying agents really need to know the answers to. Where are the agents, what are they connected to, and can you control what they’re allowed to do.
According to Okta’s research:
- 47% of respondents say they can identify all the agents in their environment
- 46% say they can control what those agents connect to
- 45% say they can authorize what agents are allowed to do.
The solutions often end up improvised, with 21% of organizations governing AI agent access with shared credentials or broad-permission service accounts. This kind of setup runs the risk of turning a compromised agent into an organization-wide problem. One in four treat AI agents exactly as they treat human identities, using systems built for people and predictable software rather than for tools that act on their own.
The anxiety is close to universal, with 81% of security leaders saying they’re concerned about excessive AI access going unreviewed, and 68% report at least some unsanctioned AI use across their organizations. The most-cited AI threat was AI-powered phishing at 61%, followed by malicious AI agents at 49%, and deepfake authentication bypass at 45%.
“When we talk about governance, we’re talking about treating those AI identities as first-class identities. So having them in your directory, having the governance process over them where they have a human manager who’s responsible for what data they have access to, what scopes they can act in, or decisions they can make,” says Matt Immler, regional CSO at Okta.
Canadian respondents diverged from the group on one question. Asked to name their biggest barrier to securing the agentic enterprise, 65% pointed to the absence of an industry standard, where the global cohort most often named a lack of visibility.
Only 31% of security leaders feel fully aligned with their C-suite on acceptable AI risk, and just 46% think their boards view AI security as a business enabler rather than a compliance requirement. The people accountable for AI agents are managing a fast-moving risk without the visibility to see it or the board agreement to resource it.
Final shots
- Tech leaders need to know where their agents are, what they are connected to, and whether they can control what the agents are allowed to do.
- 21% of organizations govern AI agents with shared credentials or broad-permission service accounts, with the potential of making one compromised agent an enterprise event.
- Only 31% of security leaders agree with their C-suite on acceptable AI risk, which means the governance argument hasn’t reached the people who fund it.
Fewer than half of CISOs can identify where their AI agents are
#CISOs #identify #agents