79 Percent of Enterprises Run AI Agents. Two Percent Can Govern Them.

On October 6, four separate companies shipped products aimed at the same gap. That timing is not a coincidence, and the gap itself is the story.
SailPoint's own Horizons of Identity Security report puts the numbers bluntly: 79 percent of enterprises are already running AI agents in production, and only 2 percent have deployed identity security tools built specifically to govern them. In the UK, enterprises are adding as many as 10,000 AI agents and machine identities per month. Nobody is reviewing that volume of access by hand.
Read the two numbers together and the shape of the problem becomes clear. The industry built the capability first and the controls second, which is the normal order for infrastructure but a dangerous one when the capability can take irreversible actions. An agent that has been granted a credential and a goal can move data, spend money, and modify systems without anyone approving each step. The window between "we deployed this" and "we can account for what it did" is the window where incidents happen.
The 2 percent figure is also generous to itself. Having a tool deployed is not the same as having governance implemented. Most of those organizations are still in the phase where the tool produces a dashboard nobody reads.
What shipped on the same day
SailPoint announced Autonomous Agents at its Navigate 2026 conference in Austin. Three classes of agents that monitor runtime actions, enforce policy, and right-size privileges without a human in the loop for each step. Alongside them, Autonomous Identity Security Posture Management uses live identity context from the SailPoint Atlas platform to continuously surface exposures across every identity type and trigger remediation in real time, replacing the periodic access review that is stale the moment it finishes.
The expanded Agentic Fabric maps an organization's full AI agent surface area, adding shadow AI discovery, runtime authorization controls, and an instant kill switch that can revoke a single agent's access without disrupting everything else. Zero Standing Privilege arrives through just-in-time provisioning, so access is issued for a specific task and withdrawn when the task ends. SailPoint applies the same model to people, service accounts, and AI agents.
The company's chief technology officer, Chandra Gnanasambandam, put the design constraint plainly: the idea that an admin will review and approve access for a group of autonomous agents making 10,000 tool calls a second is not outdated, it is a fantasy. The only way to govern autonomous machines, he argues, is with autonomous machine defense.
AppViewX shipped on the same day with Agent Identity Security: a lightweight endpoint Guardian Agent that discovers approved and shadow AI agents, an MCP Gateway for governing shadow servers, and its own Agent Kill Switch that can terminate an agent automatically or on demand. It adds an expanded AI Bill of Materials, cost tracking, and alignment checks against OWASP, MITRE ATLAS, GDPR, and NIST AI RMF.
PRE Security launched AgentGuard, which treats each agent as a persistent identity with a mission, a behavioral history, and an expected pattern of activity. Instead of inspecting isolated prompts, it evaluates whether an agent is still on mission and what it will likely do next. In a demonstration, AgentGuard watched an accounts-payable agent drift from its normal workflow, toward accessing a credential store, enumerating sensitive data, and attempting an external transfer. Each action looked legitimate. Together they described an exfiltration in progress, and the transfer was blocked before data left the environment.

Hack The Box introduced AI Range Enterprise Edition, aimed at the other half of the problem: organizations add agents after they pass a vendor benchmark, then never test them against the actual work they will handle continuously. The offering lets security teams evaluate whether their agents can perform assigned roles as models, data, and threats change.
That last product points at a subtle gap the others do not address. Governance tools assume you know what an agent should be doing. Competence tools ask whether it can do the job at all. An agent that is perfectly governed within its assigned mission but incapable of reliably performing that mission is still a problem, just a quieter one. The industry has been unusually willing to accept benchmark performance as proof of production readiness, and HTB is charging for the skepticism.
Why the governance layer arrived all at once
Agent governance stopped being theoretical when agents started holding credentials. An agent that can call APIs, query databases, and execute commands is a non-human identity with real privilege, and the identity tools built for employees were never designed for a population that grows by thousands per month and acts at machine speed.
The failure mode that unites all four products is the same one. An individual agent action looks fine. A sequence of them does not. Prompt filters, which ask whether a given input is dangerous, cannot see that shape. Behavioral analytics can, which is why PRE's framing, that AgentGuard asks whether an agent is becoming dangerous rather than whether a prompt is dangerous, is the more useful question.
There is a blunt commercial signal underneath the technical one. The insurance industry is preparing for claims against AI executives under directors and officers policies, on the theory that a rogue agent's damage is a governance failure rather than an accident. When carriers start pricing agent oversight, "we have a policy document" stops being an answer.
The part nobody has solved
Four vendors shipping kill switches is progress. It is also four answers to a question that still needs a standard: what does an agent's identity actually consist of, and who signs off when it changes?
Right now each platform defines an agent identity in its own terms. SailPoint treats it as a governed identity alongside humans and service accounts. AppViewX treats it as an endpoint-discoverable entity with a bill of materials. PRE treats it as a behavioral trajectory with a mission. Those are three different primitives wearing the same word, and an enterprise running agents that interact across all three vendors will find that the classifications do not line up. There is no equivalent of the SAML handshake for agent identity yet, no portable attestation that says "this agent is who it claims to be and is authorized for this scope" in a way another platform can verify.
SailPoint is pursuing FedRAMP High, PCI DSS 4.0, and EU Sovereign Cloud compliance while opening a data center in South Korea. That is a bet that regulated buyers will want agent governance to sit inside their existing compliance perimeter. It is a reasonable bet. But the 2 percent figure is not going to move because better tools exist. It will move when leaving an agent ungoverned becomes the thing that gets a company in trouble. Given the direction of the insurance market, the timing looks less like a question than an inevitability.
Related articles
Satellite Photos Are Now Robot Training Data
The bottleneck in physical AI training stopped being compute or model capability. It became the quality of the synthetic world.
Google's Gemini 3.5 Live Translate Removes the Pause
Translation that runs continuously, in the speaker's own voice, on a phone already in your pocket, moves the feature from something you open to something simply on.
China Wrote the First Mandatory Safety Standard for AI Agents
Safety moves from a feature you advertise to a gate you pass. The risk inventory sits at 13 categories and 97 items.
AI-Generated Content Now Has to Declare Itself
This step doesn't solve every problem, but it turns “AI-generated” from an option you could hide into a question you have to answer.