---
title: "Survey Says: IT Leaders Are Wrong About AI Security"
canonical: "https://www.guild.ai/blog/agent-governance/ai-governance-report"
---

# Survey Says: IT Leaders Are Wrong About AI Security

- **Category:** Agent Governance
- **Author:** Tim Osborn
- **Published:** Oct 02, 2026

_“It ain’t what you don’t know that gets you into trouble. It’s what you know for sure that just ain’t so.“ – Maybe Mark Twain_

As AI transformation strategies mature, there’s a dichotomy forming between what many AI leaders _believe _to be true about their organizations capabilities and what’s actually being deployed on the ground.

In our recent study, the Guild team surveyed 362 U.S. IT decision-makers about the state of production agents—and the results paint a complicated picture for enterprise-readiness.

On one hand, we see an industry that’s adopted agents wholesale—with 96% of leaders affirming agents in production and 47% reporting 21 or more. On the other, we see an operational climate that’s woefully underprepared to manage those agents safely.

Put plainly, enterprise IT leaders believe they have the infrastructure to run their agents safely—but the data says it just ain’t so.

So, where’s the dissonance? What’s the impact? And what should leaders do to address these gaps head on?

## Summary: adoption has matured, but processes haven’t

![AI governance report dichotomy](https://images.prismic.io/guild-ai/m7fChoBNmUZ-zkQv_1.png?auto=format,compress)

Conducted in partnership with Morning Consult, the agent gap survey polled IT decision-makers at companies with more than 100 employees about their experience running agents in production. According to those self-selected results:

- 96% organizations have AI agents in production
- 96% are confident that their organizations have a complete inventory of agents and access-points
- And nearly 60% believe they know what their agents are doing

However, despite the obviously growing optimism, the consequences of incomplete governance and runtime processes continue to expand.

- 61.2% of respondents had lost time to duplicative agent work
- 66.7%** **reported agent-related incidents in the last 12 months
- And agent security was cited as the primary cause for slowing deployments

![](https://images.prismic.io/guild-ai/n62frENL66u9Ss1c_2.png?auto=format,compress)

At the heart of this problem is a rate of adoption that’s rapidly outpaced the infrastructure needed to manage it.

This survey suggests a dichotomy is forming between what most teams _believe_ about their ability to effectuate security—and what they're actually doing to protect it.

So, what's missing? And is it gap in technology only? Or is the a broader transformation that's failing to take hold?

## Confidence is high, but awareness isn’t

![](https://images.prismic.io/guild-ai/yC8eBrjHX2hlQllh_3.png?auto=format,compress)

It’s easy to project confidence when you’re ignoring the issues.

While the overwhelming majority of respondents report confidence that their organizations have an accurate inventory of agents, the truth is, **just 43% are actively monitoring for unapproved agents**, and **only 36% require agents to be registered before they go live**.

What’s worse, despite roughly 60% of respondents claiming to know what their agents are doing, **less than half log agent activities at runtime**—and nearly 70% have no automated solution to stop one when something goes wrong.

Far from practicing good [agent governance](https://www.guild.ai/blog/ai-insights/the-state-of-agent-governance), technology leaders seem to be confusing confidence with a lack of awareness.

Of course, not seeing a problem isn’t the same as not having one. And this lack of diligence is impacting more than just risk profiles. It’s impacting bottom lines too.

## Weak lifecycle management is impacting profits

![](https://images.prismic.io/guild-ai/3yHDeY-rnJlyH4xV_guild-state-ai-agents-2026-ch4-report-variant.jpg?auto=format,compress)

Engineering leaders are constantly under pressure to maximize value, and repurposing existing agents—or making agents "multiplayer"—is one of the safest paths to reduce waste.

But here’s the problem. Engineers can’t re-use what they can’t find.

With a scant 36% of companies requiring agents to be registered, it’s no surprise that **61.2% of engineering and IT teams included in this study reported losing time to duplicative agent work**—including rebuilding or maintaining entire agents that already exist elsewhere in the organization.

![](https://images.prismic.io/guild-ai/-1IiCKfzoq6Wb7jP_guild-state-ai-agents-2026-building-report-v1.jpg?auto=format,compress)

On top of that, just** 1 in 4 respondents reported having a formal process for retiring agents**; and **half admitted their companies have no formal policy governing agent use at all**.

As employees leave or lose interest, unregistered agents will continue to limp along unnoticed in organizations without a formalized registry, expanding risk surfaces and draining down token budgets into perpetuity.

## Experience isn’t a substitute for security

![](https://images.prismic.io/guild-ai/yaS3SePw37wDZ_84_guild-state-ai-agents-2026-agent-maturity-curve-report.jpg?auto=format,compress)

Think these problems will get easier with more engineers?

According to respondents, **organizations with larger engineering teams, (20 to 199 engineers), reported incidents at nearly twice the rate of the smallest teams (at 78% versus 43% respectively)**.

While it can be easy to conflate years of experience with maturity, the failures highlighted in this report aren’t a reflection of the engineering organization. They’re a reflection of the infrastructure that’s supporting it.

Years of experience can’t shield you from broken security or governance processes. Without a centralized solution to monitor and manage agents at runtime, the only thing AI can realistically transform is your risk profile. And not in a good way.

## The most important capabilities are the ones most companies don’t have

This report isn’t a story about AI agents failing to deliver value. It’s a story about enterprise organizations that still lack the requisite guardrails to sustain real value at scale.

All leaders have an innate desire to project confidence—to themselves and to others. But in the world of enterprise agents, ignorance isn’t a synonym for bliss.

If we want to see AI transform the enterprise, we first need to transform the infrastructure that runs, [observes](https://www.guild.ai/blog/agent-governance/why-ai-observability-is-not-ai-governance), and governs it.

![](https://images.prismic.io/guild-ai/kUGHEqKflIWxSjFp_4.png?auto=format,compress)

**But with a new [glossary](https://www.guild.ai/glossary) of new terms sprouting up by the moment, what does any of this really mean in practice? Well, according to respondents, most enterprise leaders already know what that infrastructure looks like. **

- 83.9% of respondents agree real-time visibility into agent activity is extremely valuable
- 80% want security and compliance built into their runtime tooling
- And 81% rank a centralized hub for managing and deploying agents as extremely or very important.

The good news—that’s exactly what we’re building at Guild. When we started this journey, we knew agents were multiplying faster than accountability. And as the data in this report affirms, most teams still can’t answer the basic questions:

- Who owns this agent?
- What can it access?
- What did it do?
- What did it cost?
- And what happens if it goes wrong?

![](https://images.prismic.io/guild-ai/mxaeRTERnLZAfhvr_Shadowgraphic.png?auto=format,compress)

As we can see from this report, it’s easy to fake confidence. It’s a lot harder to fake the receipts.

The first phase of enterprise AI was proving that agents _could_ do the work. The next phase is making sure agents can do it with the same visibility, accountability, and operational rigor as any other production system.

That's the infrastructure we're building at Guild.

Read the complete findings, methodology, and chapter-by-chapter breakdown in The State of Enterprise AI Agents 2026.

Download the full report below.

## Report: The AI Governance Delusion

Find out why most IT and engineering teams are wrong about their AI's security, what's happening now, and why you can do to get prepared.

Download report
