AI Agents Outnumber Humans in 83% of Organizations, But Governance Lags Behind

3 Sources

Share

Non-human identities now outnumber human users in 83% of organizations, yet only 21% have implemented governance controls for AI agents. As autonomous actors access sensitive systems and make consequential decisions, enterprises face a critical gap between deployment speed and accountability infrastructure.

News article

AI Agents Enter the Workforce Without Proper Onboarding

AI agents are now operating inside enterprise systems with the same access privileges as human employees, yet most organizations never formally onboarded them. These autonomous actors access Salesforce, create tickets in Jira, provision infrastructure, process financial transactions, and communicate on behalf of teams

1

. The scale of this shift is staggering: JumpCloud's Q3 2026 research found that non-human identities now outnumber human users in 83% of organizations, but only 21% have implemented governance controls specifically for them

1

. Unlike human employees who go through rigorous onboarding processes with defined roles, entitlements, and named managers, AI agents typically have no named owner, no defined scope of authority, and no offboarding process when their purpose expires.

Shadow AI Creates Ungovernable Systems

Product teams, operations leaders, and individual contributors are deploying AI agents rapidly, leaving IT to inherit governance responsibility after the fact. This creates shadow AI: agents operating across production environments with no formal record, no defined owner, and no systematic way to stop them if something goes wrong

1

. The problem compounds when agents outlive their original purpose but keep running and accumulating permissions—what industry experts call "Zombie Agents." Retrofitting access controls onto live agents already woven into dozens of enterprise systems proves significantly harder than designing those controls from the outset

3

. One large insurer addressed this by adopting a simple rule: no agent enters production without a clearly defined scope of authority and an activity log that business leaders can understand

3

.

Traditional Security Controls Fall Short for Autonomous Actors

At Black Hat USA 2026, Rubrik Inc. unveiled Rubrik Agent Identity to govern agent access, arguing that AI agents demand an entirely new control layer. Dev Rishi, general manager of AI at Rubrik, explained that unlike service accounts or human users, agents pair non-deterministic models with federated identity—a combination that breaks conventional security assumptions

2

. "If you or I were accessing Salesforce [or] accessing email, we have some judgment on how we would use that, that the models don't," Rishi said. "So I feel like you need a new class of guardrails that are a lot more intelligent and semantically aware to be able to actually secure and govern what agents are doing"

2

. An agent can pull data from Salesforce, then paste sensitive fields into an outbound email—each action authorized individually, but the combination toxic. To address this without flooding humans with endless approvals, Rubrik built SAGE, a small language model trained to act as a cybersecurity professional that vets actions at machine speed

2

.

A Four-Stage AI Agent Governance Framework

Securing AI agents requires treating them as formal workforce identities. The first stage involves discovering every agent operating in your environment through ongoing inventory across cloud platforms, managed devices, SaaS integrations, and on-premise systems

1

. Second, register every agent as a formal identity in your directory with the same basic attributes assigned to employees: a defined purpose, scope of authorized action, and a named human owner accountable for its behavior. This architectural decision separates organizations that can govern their agents from those that cannot

1

. Third, manage agent access using least-privilege access principles with zero standing credentials. This means issuing just-in-time credentials for privileged operations, building approval workflows for sensitive systems, and maintaining emergency shutdown mechanisms

1

. Finally, govern agent behavior continuously through logging every agent action and conducting regular access reviews to verify that what agents actually do matches what they're authorized to do.

Observability Reveals Hidden Costs and Risks

Observability forms the foundation of accountable AI operation, but raw telemetry needs an intelligence layer to surface risk and runaway spend. Rubrik's internal deployment emits trillions of tokens, and the company discovered that 1% of sessions were driving 40% of the cost

2

. Without observability at the task level, agentic systems often retry failed actions, call expensive models unnecessarily, or become trapped in inefficient execution loops. Finance teams frequently discover these problems only after AI spending climbs well beyond expectations because they're looking at a single budget line instead of thousands of individual decisions that could have been measured and optimized

3

. A regional bank adopted governance controls proactively because regulators would inevitably ask for an accounting of automated decisions, regardless of how those decisions were made

3

.

Trust Becomes the Bottleneck for AI Agent Deployment

Many organizations have built technically capable agents only to discover that their own teams are reluctant to let those agents touch consequential business processes involving mission-critical workflows, customer data, or financial systems. The hesitation comes down to a simple question: if this agent makes a mistake, how will anyone know what happened? Capability without accountability doesn't scale—it stays confined to pilots and innovation labs while critical business functions continue relying on manual processes

3

. Organizations handling this well have treated visibility, auditability, and access control as part of the system they're building instead of a compliance exercise added after deployment. As enterprises hand more authority to software, AI governance is becoming the operating system of trust, determining whether agentic AI can move beyond pilots into production systems that approve refunds, move money between accounts, or initiate vendor contracts

3

.

Today's Top Stories

© 2026 TheOutpost.AI All rights reserved