August 2026 · 6 min read
Half of CISOs Can't See Their AI Agents

Key Definitions
Identity governance maturity A measure of how far an organization has progressed in governing AI agent identity and access — from reactive discovery through defined, to advanced real-time automated control.
Shadow AI The use of AI tools or agents by employees without formal authorization and governance from IT and security, creating an invisible security blind spot.
AI agents are creating a governance crisis at the heart of enterprise security — and identity infrastructure is both the problem and the solution. Okta's global survey of 306 CISOs and security executives, finalized in June 2026 with Apprize360 Intelligence, reveals a blunt truth: security leaders are half-blind about the agents in their own environments. They cannot see them, control them, or account for them.
I. The Invisible Agent: A Confidence Crisis
The survey centers on three foundational questions: Do I know where my agents are? What can they connect to? What can they do? The answers are sobering. Only 47% of CISOs are confident they can identify all agents in their environment, 46% can control what agents access, and 45% can authorize what agents do. Among those who only strongly agree, the figure drops below 30%.
The root cause is fragmented governance. Organizations are applying human identity policies to non-human agents, relying on shared credentials or broad-permission service accounts to govern agent access (21% do this), and managing permissions on an ad hoc basis. That disconnected approach leaves blind spots across the agentic enterprise — and security leaders live by the mantra that you cannot protect what you cannot see.
II. Excessive Access: The 81% Anxiety
81% of CISOs are concerned about excessive AI access. The research also reveals a visibility-versus-security paradox: even among CISOs fully confident they know where their agents are, roughly 80% remain highly concerned about excessive access and permissions. Knowing an agent's location or connections modestly tempers — but never eliminates — the worry of a breach.
This anxiety is structural. Agents operate autonomously at machine speed and make decisions at runtime, yet most enterprises have not applied to them the same identity, authentication, and audit controls they already require of human users, connected devices, and enterprise applications.
III. Governance Maturity Determines Risk
Okta segments agent identity governance maturity into reactive, developing, defined, and advanced tiers — and the data maps maturity directly to exposure. Reactive organizations report extensive shadow AI in 25% of cases (vs. 13% average), 18% cannot identify or stop rogue agents at all (vs. 5% average), and 32% are extremely worried about AI-driven breaches. Advanced organizations, by contrast, revoke agent access within minutes in 50% of cases (vs. 26% average), and not a single advanced company struggles to identify and stop rogue agents.
Regional gaps are stark. The UK leads, with 36% of organizations reporting advanced, fully automated governance; France ranks last in oversight confidence, with nearly 24% only notifying users and relying on policy compliance; Japan reports the highest share of CISOs extremely worried about AI-driven breaches (29%) and is twice as likely to have no consistent agent-identity approach. Notably, 61% of reactive organizations prioritize innovation over security — 13 points above the 48% average — an explicit trade of risk for speed.
IV. Boardroom Misalignment: From Checkbox to Enabler
Only 31% of CISOs feel fully aligned with their C-suite and board on acceptable AI risk — just 12% in the US. Under half say their board sees AI security as a business enabler rather than a compliance checkbox. Without that alignment, CISOs struggle to secure the support that responsible AI adoption requires, and governance maturity stalls.
V. The Path Forward: Answer Three Questions
The survey's path forward is remarkably clear, beginning with three questions: Where are my agents? What can they connect to? What can they do? Answering them is the blueprint for a secure agentic enterprise. From there, treat every agent as a first-class identity with its own lifecycle, least-privilege permissions, and access policy — replacing shared credentials with fine-grained controls — and bring shadow AI under governance rather than just blocking it.
When you invest in maturing your AI identity governance, you experience less shadow AI, worry less about breaches, and contain rogue agents faster. The autonomous era is here, and the question is no longer whether to adopt agents — it is whether your identity infrastructure can scale them safely. Mature governance is the gate that lets enterprises keep their speed without losing control.
References:
FAQ
Why can't CISOs see their AI agents?+
In Okta's survey of 306 global CISOs, under half can identify all agents in their environment (47%), control what they access (46%), or authorize what they do (45%) — below 30% among those who only strongly agree. The cause is fragmented governance: organizations apply human identity policies to non-human agents, rely on shared credentials, and manage agent access on an ad hoc basis.
How widespread is the fear of excessive access?+
81% of CISOs are concerned about excessive AI access. Even among CISOs fully confident they know where their agents are, roughly 80% remain highly concerned about permissions — visibility tempers, but never eliminates, the worry of a breach.
How does governance maturity affect risk exposure?+
Maturity determines risk. Reactive organizations report extensive shadow AI in 25% of cases (vs. 13% average) and 18% can't identify or stop rogue agents at all (vs. 5%). Advanced organizations revoke agent access in minutes (50% vs. 26%), and not a single advanced company struggles to identify rogue agents.
Why does boardroom misalignment matter?+
Only 31% of CISOs feel fully aligned with their C-suite and board on acceptable AI risk — just 12% in the US. Under half say their board sees AI security as a business enabler rather than a compliance checkbox. Without that alignment, CISOs struggle to secure the resources responsible AI adoption requires.
How should enterprises establish control over agents?+
Start with three questions: Where are my agents? What can they connect to? What can they do? Then treat every agent as a first-class identity with its own lifecycle, least-privilege permissions, and access policy — replacing shared credentials — and bring shadow AI under governance rather than just blocking it.
Related Articles
Agent Identity's Ownership Vacuum: Who Governs?
A CSA/Strata survey of 285 pros: only 23% have a formal agent-identity strategy; ownership is fragmented.
Shadow AI Agents: The Invisible Enterprise Crisis
Over 53% of enterprise agents exceed intended permissions; shadow agents are the biggest security blind spot.
AI Agent Identity: Why Zero Trust Is the 2026 Default
Only 18% of security teams trust existing IAM for agents. Identity governance is the foundation of autonomy.
Non-Human Identity: The Agent Security Crisis
Non-human identities now outnumber human ones, forcing a structural rebuild of enterprise IAM.