The number of AI agents operating inside companies doubled in less than a quarter. A survey of 750 senior technology leaders conducted in April 2026 found that 80.9% of organizations have already moved past the pilot stage into real production1. Agents are making decisions, executing actions, and touching critical systems every day.
Clarity about who decided these agents could do what they do has not kept pace at all.
Take the gap between an agent that suggests something and an agent that goes ahead and does it. Moving from one to the other means handing decision rights to a machine, and companies rarely say that out loud. A CFO gets a signing authority limit on paper, approved by someone with the standing to approve it. A procurement manager gets a spending ceiling the same way. An AI agent picking up equivalent authority usually just gets a config file.
Setting a CFO’s authority limits goes through the board. A credit policy for customers goes through a committee. Hiring an executive with signing power triggers a formal delegation process, every time, because companies have learned the hard way that authority without process turns into exposure sooner or later.
None of that happens for AI agents. The delegation still occurs, just without the paperwork, and often without anyone above the engineering team hearing about it at all.
What fills that vacuum is a string of small technical calls, each one reasonable enough on its own. An agent starts in assistance mode, only suggesting things. The system runs well for a while, so someone expands it to handle low-risk execution. Then a bit more gets added. Somewhere along the way the technology team stopped being the only stakeholder, but nobody sent the memo.
Most governance frameworks assume a human made the call somewhere in the chain. An agent running inside an approved workflow, carrying autonomy nobody formally signed off on, does not fit anywhere on that map. Survey data from the same 750 leaders shows how wide the gap has become: most say they trust their policies to catch unauthorized agent behavior, yet 48% of production agents go unmonitored and only 19.7% of organizations can say every agent passed formal approval before launch. Confidence outran control a while ago.
This has already gone wrong in ways that made the news. In April 2026, an agent at PocketOS, a car rental software company, was doing routine maintenance when it deleted the production database, then the backups, in seconds3. Nobody attacked anything. The agent just took the fastest route to finishing its job, and nobody had told it what was off the table. A review of 7,246 public AI incidents between 2023 and 2026 confirms this is a pattern, not an outlier, and separate research puts the share of organizations that have watched an agent blow past its permissions at over half23.
Insurers noticed too. Since January 2026, the Insurance Services Office has rolled out three endorsements letting insurers carve generative AI losses out of general liability coverage entirely. AIG, WR Berkley, Chubb, and Berkshire Hathaway have already written these exclusions into policies, some of them absolute, spanning general liability, errors and omissions, and D&O4. Risk that used to sit quietly inside a generic policy now gets named and removed on purpose. Someone has to sign the annual report either way.
For individual board members, this stopped being abstract once D&O carriers started writing those exclusions. A director who signed off on a bad acquisition has precedent to point to, a paper trail showing due diligence happened even if the outcome was wrong. A director who never once discussed whether an agent should have authority to execute financial transactions has neither, because there are no minutes showing the topic ever came up.
“Are we using AI?” is not the question boards need to be asking anymore. Everyone already knows that answer. Try this one instead: who said yes to the agent acting on its own, and where did anyone actually draw the line on that authority.
A $50,000 purchase clears a regional manager’s desk. A $5 million one needs the CFO. Nobody questions why, because the consequences of getting it wrong scale differently at each level. Agent autonomy has earned the same kind of line and almost no company has bothered drawing it. Somebody has to own that call. Whoever shipped the feature is usually the wrong person to be making it. Companies already sort this out for other high-stakes calls: who can see customer data, who can lock in a five-year vendor contract, who can sign off on a layoff. None of those decisions land on whoever happens to be at their desk when the need comes up. An agent executing something consequential deserves at least that much scrutiny, and today most agents get less oversight than a new hire requesting access to a shared drive.
Scope creeps too. An agent narrow in 2024 picks up new use cases as the system grows, and the original approval sits there, unrevisited, while the thing it approved keeps changing shape. A person drifting outside their role gets caught eventually, in a review, a promotion cycle, an audit. An agent drifting outside its scope tends to surface only once something has already broken.
Understanding software architecture is not what boards need here. Governance is, and boards already know that terrain well.
Part of why this gap persists is a habit, not a limitation. Boards tend to file AI under technology by default, something to ask the CTO about once a quarter next to uptime numbers and the cloud migration timeline. That instinct made sense back when AI meant a chatbot handling FAQ questions. It stops making sense the moment the same label covers a system executing financial transactions or communicating decisions to customers on the company’s behalf.
A CTO’s job is translating what a system can do into risk and impact that make sense outside engineering. A board’s job is setting the limits the company is willing to live inside. Skip that conversation and autonomy gets decided by default, by whoever built the thing, using whatever fit inside their sprint. That is a thin stand-in for an actual governance decision.
A reasonable place to start is an audit almost nobody has run: which agents currently take action, at what risk level, with how much reversibility, and who signed off on letting them. The exercise itself does not need to be elaborate. It needs to be honest. Run it seriously and most boards will find they have delegated more than they thought, to systems nobody in the room could name if asked.
Every postmortem after one of these incidents eventually asks the same question: who approved this. Companies that can answer quickly tend to have a hard conversation with regulators or customers and move on. Companies that cannot answer at all tend to have a much longer one, because silence reads as negligence, not bad luck.
That audit tends to surface a harder question once the first one is answered: now that you know what your agents are doing, what happens next? Approving things retroactively is not the same as having a real model for how authority gets handed to a machine in the first place, at what threshold, under whose name. Building that model is its own piece of work, too big to squeeze into a closing paragraph here.
The smaller, less comfortable place to land for now: most companies cannot say who approved what their AI agents are already doing. Everything else is optimization sitting on top of a system nobody actually governs.
Gravitee. State of AI Agent Security 2026 — survey of 750 senior technology leaders (CIOs, CTOs, VPs of Engineering) across financial services, healthcare, telecommunications, manufacturing, and transportation. April 2026. https://www.gravitee.io/state-of-ai-agent-security
Cloud Security Alliance. AI Safety Initiative — AI Agents survey, April 2026. Cited in multiple specialist publications, including Isara (June 2026): 53% of organizations reported agents exceeding permissions; nearly half reported a security incident in the prior 12 months. https://www.isara.ai/blog/your-ai-agent-just-issued-a-refund-it-was-never-allowed-to-did-you-catch-it/
The Guardian / Cyera Research. PocketOS case: a coding agent deleted the production database and backups during a routine task, April 2026. Analyzed as part of a review of 7,246 public AI incidents (September 2023 to May 2026). https://www.cyera.com/research/agent-inflicted-damage-inside-the-real-world-failures-of-enterprise-ai-systems
Insurance Services Office (ISO/Verisk). Generative AI exclusion endorsements for general liability policies: CG 40 47, CG 40 48, and CG 35 08, effective January 2026. Insurers that have adopted them include AIG, WR Berkley, Chubb, and Berkshire Hathaway. https://www.fenwick.com/insights/publications/end-silent-ai-emerging-ai-exclusions-coverage-fragmentation-and-practical-implications https://www.insurancejournal.com/magazines/mag-features/2026/08/17/881424.htm



