20 pages. Five findings. Zero guesswork.
How security leaders are governing agent fleets today, where the wrong-place risk is hiding, and why authorization, not activity, is becoming the evidence that matters.
Get the full reportWhat 251 security leaders told us
Fleets are already large and still growing — 58% run more than 50 agents today, rising to 66% within 12 months.
The risk is context, not capability — 84% say agents cross project boundaries more easily than employees.
Authorization is the missing layer — 87% agree it's the gap agentic AI security hasn't closed.
Confidence stops short of proof — fewer than half of leaders hold top-tier confidence in any oversight capability.
A restriction event is expected — 79% anticipate a clawback within 18 months.
Ownership hasn't kept pace — 85% say they have more agents than approved owners.
“Capability does not establish context.”Agents of Change, 2026
Restriction expectation rises with fleet size
The more agents an organization runs, the more certain its leaders are that a correction is coming. This is the report's clearest signal that scale, not sentiment, is driving the governance conversation.
See the full findings