{"id":45579,"date":"2026-05-20T15:08:13","date_gmt":"2026-05-20T15:08:13","guid":{"rendered":"https:\/\/www.europesays.com\/ai\/45579\/"},"modified":"2026-05-20T15:08:13","modified_gmt":"2026-05-20T15:08:13","slug":"millions-of-ai-agents-are-running-without-oversight-is-yours-one-of-them","status":"publish","type":"post","link":"https:\/\/www.europesays.com\/ai\/45579\/","title":{"rendered":"Millions of AI agents are running without oversight. Is yours one of them?"},"content":{"rendered":"<p>Millions of AI agents are running without oversight. Is yours one of them?<\/p>\n<p>Shadow IT has been a challenge for security teams for years, and now AI is raising the stakes. As organizations race to adopt new tools, <a data-ylk=\"slk:shadow AI;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/resources\/shadow-ai\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">shadow AI<\/a> is spreading across teams. \u200d<\/p>\n<p><a data-ylk=\"slk:Vanta data;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/resources\/when-tokenmaxxing-leads-to-riskmaxxing\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Vanta data<\/a> shows that 70% of companies have AI tools accessing their environment without going through proper procurement channels, and fewer than 2% of unmanaged vendors ever receive a security review. The result is a growing gap between adoption and control\u2014one that\u2019s harder to manage because these systems can take action, not just store data.\u200d<\/p>\n<p>To close that gap, organizations need a clearer way to see, manage, and control how AI is used across the business. This guide from <a data-ylk=\"slk:Vanta;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/products\/vendor-risk-management\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Vanta<\/a> covers how to:\u200d<\/p>\n<p>Identify where AI is being used across your organization.<\/p>\n<p>Define the right level of autonomy for each agent.<\/p>\n<p>Put guardrails and access controls in place.<\/p>\n<p>Monitor activity continuously.<\/p>\n<p>AI agents are already everywhere<\/p>\n<p>AI agents sit inside customer support platforms, procurement tools, engineering workflows, and compliance processes. They both assist with and participate in how work gets done.<\/p>\n<p><a data-ylk=\"slk:Eight in 10 organizations are already deploying or planning to deploy agentic AI;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/state-of-trust\/global\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Eight in 10 organizations are already deploying or planning to deploy agentic AI<\/a>. Looking ahead, <a data-ylk=\"slk:Gartner predicts;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.gartner.com\/en\/newsroom\/press-releases\/2025-06-25-gartner-predicts-over-40-percent-of-agentic-ai-projects-will-be-canceled-by-end-of-2027\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Gartner predicts<\/a> that 40% of enterprise applications will include task-specific AI agents by the end of 2026.<\/p>\n<p>AI agents are spreading across marketing, sales, HR, finance, and security, but ownership doesn\u2019t always follow. Organizations may not have a reliable way to answer basic questions like:\u200d<\/p>\n<p>How many agents are running?<\/p>\n<p>What systems can they access?<\/p>\n<p>What actions can they take?<\/p>\n<p>Without a baseline, governance can be reactive and incomplete by default.<\/p>\n<p>\u200dAdoption is coordinated\u2014understanding isn\u2019t<\/p>\n<p>There\u2019s a noticeable mismatch between how quickly organizations adopt AI and how well they understand it. That\u2019s when the shadow AI starts to take hold.<\/p>\n<p><a data-ylk=\"slk:Vanta data;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/resources\/when-tokenmaxxing-leads-to-riskmaxxing\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Vanta data<\/a> shows that shadow IT is growing 36% year over year, fueled in part by AI adoption.<\/p>\n<p><a data-ylk=\"slk:Microsoft\u2019s Cyber Pulse Report;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.microsoft.com\/en-us\/security\/blog\/2026\/02\/10\/80-of-fortune-500-use-active-ai-agents-observability-governance-and-security-shape-the-new-frontier\/\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Microsoft\u2019s Cyber Pulse Report<\/a>, released in February, also found that 29% of data security professionals surveyed in July 2025 reported using unsanctioned AI tools at work. For example, a team might give an agent broad API access just to get it working, or skip review because a tool seems low risk. Over time, those decisions add up to systems no one fully owns or understands.<\/p>\n<p>AI incidents are outpacing governance<\/p>\n<p>As AI spreads across more systems without clear guardrails, incidents are becoming more common and harder to catch before they cause damage. The missing piece is dependable governance.\u200d<\/p>\n<p>The data reflects that shift:\u200d<\/p>\n<p>These cases are a byproduct of fast adoption without consistent oversight. One example may be an AI agent pulling sensitive data into logs, triggering the wrong workflow, or exposing information through downstream systems. Without clear visibility, it\u2019s hard to trace what happened or where it started.<\/p>\n<p>At the same time, most teams don\u2019t have the capacity to keep up. <a data-ylk=\"slk:Nearly two-thirds of organizations;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/state-of-trust\/global\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Nearly two-thirds of organizations<\/a> say they spend more time proving security than improving it, according to Vanta\u2019s fall 2025 The State of Trust Report. Per the report, teams already spend about 12 weeks a year on compliance work. That leaves little room to manage systems that are constantly changing\u2014especially when they can act on their own.\u200d<\/p>\n<p>As incidents become more common, some patterns are starting to emerge in how organizations respond.<\/p>\n<p>What effective AI governance looks like in practice<\/p>\n<p>As AI risk grows, a few patterns are starting to emerge in how organizations approach governance. The shift is toward more consistency in how AI systems are understood and controlled. \u200d<\/p>\n<p>In many environments, AI agents are increasingly treated like identities. If a system can access data or take action, it\u2019s given defined permissions, with clearer boundaries around what it can and can\u2019t do.\u200d<\/p>\n<p>There\u2019s also more attention on autonomy. Rather than letting capabilities expand organically, teams are starting to define where automation is appropriate and where human review still matters.\u200d<\/p>\n<p>Monitoring is shifting, too. Periodic reviews are giving way to more continuous visibility, especially as systems begin to act across multiple tools and datasets.<\/p>\n<p>And as AI spreads across teams, ownership is becoming more explicit. Instead of shared or unclear responsibility, organizations are starting to define who is accountable for how each system behaves.<\/p>\n<p>Across all of this, the direction is consistent: moving from fragmented oversight to systems that can keep pace with how quickly AI is actually used.<\/p>\n<p>Where teams are starting with AI governance<\/p>\n<p>For most organizations, this shift doesn\u2019t begin with a full governance overhaul. It usually starts with visibility.\u200d<\/p>\n<p>As AI use expands, teams are working to answer a basic set of questions: What\u2019s running, where it\u2019s connected, and what it\u2019s allowed to do? That baseline is often incomplete at first, especially in environments where tools have been adopted quickly.<\/p>\n<p>\u200dFrom there, structure tends to build gradually. Teams start adding guardrails around higher-risk actions, clarifying access, and introducing more consistent monitoring as systems evolve.\u200d<\/p>\n<p>The process isn\u2019t always linear. But over time, organizations that invest in visibility and control tend to move away from reactive fixes toward something more sustainable, where AI governance can keep up with how AI is actually used.<\/p>\n<p>\u200dCustomers expect security\u2014and proof<\/p>\n<p>Vanta\u2019s research has identified another dynamic shaping how organizations approach managing AI: External expectations are on the rise.<\/p>\n<p><a data-ylk=\"slk:77%25 report;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/state-of-trust\/global\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">77% report<\/a> that stakeholders expect verified proof of security and compliance.<\/p>\n<p>Those expectations extend to AI. Customers want to understand how AI is being used, what controls are in place, and how risks are managed, and partners are asking similar questions as procurement processes evolve.<\/p>\n<p>When organizations can clearly show how they control and monitor their AI systems, it builds confidence with buyers, makes security reviews smoother, and helps unblock deals that might otherwise stall.<\/p>\n<p>AI governance plays a direct role in revenue, partnerships, and growth.<\/p>\n<p>You can\u2019t manage what you can\u2019t see<\/p>\n<p>You can\u2019t manage what you can\u2019t see, and AI adoption isn\u2019t slowing down. It\u2019s only getting more embedded, more distributed, and more essential to how work gets done.\u200d<\/p>\n<p>However, most organizations don\u2019t yet have a clear picture of their own AI footprint. They might not know exactly how many agents are running, where they\u2019re deployed, or what they\u2019re allowed to do.\u200d<\/p>\n<p>Without visibility, risk grows alongside adoption. Unmanaged AI might not fail loudly in the beginning. Instead, it accumulates small gaps with unclear permissions, missing oversight, and fragmented ownership. But those gaps can connect.<\/p>\n<p>The most practical place to start is also the most foundational: Make AI visible. Once you can see it clearly\u2014where it lives, what it touches, how it behaves\u2014you can begin to shape it.<\/p>\n<p><a data-ylk=\"slk:This story;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/resources\/ai-sprawl-governance\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">This story<\/a> was produced by <a data-ylk=\"slk:Vanta;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/www.vanta.com\/products\/vendor-risk-management\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Vanta<\/a> and reviewed and distributed by <a data-ylk=\"slk:Stacker;elm:context_link;itc:0;sec:content-canvas;\" href=\"https:\/\/hubs.la\/Q03klgSR0\" rel=\"noopener noreferrer nofollow\" target=\"_blank\">Stacker<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"Millions of AI agents are running without oversight. Is yours one of them? Shadow IT has been a&hellip;\n","protected":false},"author":2,"featured_media":45580,"comment_status":"","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[6],"tags":[405,1798,7537,428,647,3913],"class_list":["post-45579","post","type-post","status-publish","format-standard","has-post-thumbnail","category-agentic-ai","tag-ai-agents","tag-ai-governance","tag-artificial-intelligence-agents","tag-governance","tag-organizations","tag-systems"],"_links":{"self":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/45579","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/comments?post=45579"}],"version-history":[{"count":0,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/posts\/45579\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media\/45580"}],"wp:attachment":[{"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/media?parent=45579"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/categories?post=45579"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.europesays.com\/ai\/wp-json\/wp\/v2\/tags?post=45579"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}