ZDNET’s key takeaways
Nearly 1 in 2 organizations with agentic deployments haven’t applied governance processes.
More than 1 in 4 organizations cannot detect unauthorized AI agents inside their business.
One-third reported AI incidents that had a material negative business impact.
The rapid deployment of autonomous AI agents is creating new governance challenges, including the inability of organizations to detect unauthorized AI agents operating inside their companies, according to an Ernst & Young (EY) 2026 survey of 202 senior AI decision makers (board members, C-suite, VP+) at publicly traded companies with at least $1 billion in annual revenues.
Also: Give AI ‘stuff nobody wants to do’ – and 4 other ways to use agents more effectively
All survey respondents had oversight over their organization’s AI systems, governance, or audit processes of generative or agentic AI deployments. Nearly all respondents (98%) said their organizations have formal AI governance policies in place, and 69% have a fully unified AI governance. But nearly all are concerned with the lack of internal expertise needed to update their evolving AI controls. Nearly 1 in 2 (47%) of AI business leaders said that they bypass AI governance due to urgent deployments.
Autonomous AI agent risks are rising
According to EY, 85% of AI business leaders say they have a handful of agentic AI systems operating autonomously within their organizations. According to 2026 research from Salesforce, AI agent deployments in production grew from five agents in 2024 to an average of 13 agents in 2026. That said, nearly 1 in 2 business leaders noted that their existing AI governance frameworks have not been updated to include agentic AI risk and requirements, and 26% cannot detect rogue AI agents operating internally.
Cybersecurity is main driver for governance
Another major area of concern regarding AI governance is cybersecurity. The EY survey found that 89% of senior AI decision-makers reported encountering AI-related risks in the past 12 months. Forty-one percent of senior leaders lack visibility into all AI tools used within their organizations. And 36% say they have reported AI incidents and failures that caused material negative impact, including data loss, financial damage, and operational disruption due to AI agent missteps.
Also: 74% of CEOs are acting like chief AI officers – as AI spending jumps
According to EY, 81% of AI business leaders are concerned that third-party-enabled cyberattacks could compromise AI tools, while 72% believe they are failing to comply with new or emerging AI-specific regulations. EY found that the concerns stem from real-world events, including AI-related risks (89%), cybersecurity risks (59%), human risks (47%), and shadow use of AI (46%).
Adaptable and evolving AI governance is key
Nearly all AI business leaders (98%) have formal AI assurance reviews that attempt to ensure ongoing compliance for autonomous agentic use cases. The not-so-surprising finding is that 92% of those conducting formal AI assurance reviews are finding issues.
EY found that 64% of organizations modified 25% or more of their AI systems, and 14% modified over 75%. Nearly a third have paused AI system modifications, and 25% fully stopped a quarter or more of their AI systems. The most common reasons behind pausing or stopping AI system upgrades include data quality problems (57%), AI model drift (48%), and shadow AI (39%). There is a growing confidence gap that exists, given the pace of innovation with AI and the pace of governance needed to match deployment schedules.
Also: Who owns AI risk at work? Business and tech leaders can’t agree
As more autonomous AI agents move from pilots in controlled environments to production environments where the AI’s capabilities and reasoning logic are tested by employees, customers, and business partners, the need for organizations will shift from creating policies to validation and demonstration that those policies are actually working.
To demonstrate adaptive and trustworthy AI governance, business leaders must have full visibility, understandability, and accountability of their digital labor, their autonomous AI agents. The autonomous capabilities of AI agents will continue to accelerate, unlike any other technology in our lifetime. The need for AI governance, compliance, security, transparency, and positive outcomes will require businesses to adopt trust as their number one core value.
Vala Afshar
Contributing Writer
Vala Afshar is the Chief Digital Evangelist for Salesforce. Afshar is the author of The Pursuit of Social Business Excellence. Afshar is also the co-host of DisrupTV, a weekly show covering the latest digital business and innovation market trends.
See full bio