Employees are building and using AI agents faster than most organizations can govern them.
Organizations are embracing AI agents to boost productivity, automate tasks and accelerate business outcomes. But many of these automations are being created outside formal oversight, creating a growing population of “shadow AI” agents that cybersecurity teams may not know exist, or can see but without any way to understand or control them.
“These shadow AI agents take multiple forms: embedded in existing enterprise software, consumed directly from the Internet or created by employees leveraging recent technological progress and “vibe coding” to improve productivity,” says Jeremy D’Hoinne, Vice President Analyst at Gartner. To gain proper oversight and support their organizations’ AI initiatives, cybersecurity leaders must create structured frameworks that map AI agents based on business risk dimensions.
Gartner has identified this challenge as one of its Top Trends in Cybersecurity for 2026 because AI adoption is expanding faster than many organizations’ ability to govern it. This trend offers a glimpse into one of the forces reshaping cybersecurity today.
You might also like this webinar: Top Trends in Cybersecurity for 2026
Agentic AI is changing how organizations think about cyber risk. Rather than focusing only on the technology itself, leaders must determine how to govern AI agents that can act autonomously, access sensitive data and interact with critical business systems.
AI agent use is spreading rapidly among employees and developers through embedded enterprise software, no-code and low-code platforms, and custom-built automations. Employees often adopt these tools without waiting for formal approval, making discovery difficult for cybersecurity teams.
Organizations are already seeing significant levels of AI activity outside formal oversight. According to Gartner, unsanctioned AI use is already common, with 75% of organizations reporting unauthorized use of AI coding assistants and 50% reporting employee access to public SaaS GenAI agent platforms. This combination of strong business demand and limited visibility means security leaders cannot simply slow AI adoption. Instead, they must find ways to identify, inventory and monitor both sanctioned and unsanctioned AI agents.
The rapid growth of AI agents is forcing cybersecurity teams to rethink existing security programs. In order to do so, organizations must extend discovery capabilities beyond basic visibility, incorporate AI agent risks into posture management practices and update incident response processes to address rogue automations.
The challenge is becoming more urgent. Sixty-one percent of senior cybersecurity professionals have observed AI agent automation in existing approved enterprise software, while 59% suspect or have evidence of unsanctioned employee use. And according to Gartner polling, an average of 41% of stand-alone GenAI prototypes reach production, highlighting the need to pace security investments carefully and focus early efforts on data security and access management.
One of the biggest misconceptions about AI cybersecurity governance is that every AI agent requires the same level of oversight. When accessing risk, CISOs should start with a practical approach that prioritizes risk reduction based on two key factors: the sensitivity of the data an agent can access and its level of autonomy (the combination of agency and automation).
Some agents operate within defined enterprise applications, while others act independently, connect to multiple resources or generate business logic through large language models. As autonomy increases, so does the potential impact of misuse, compromise or unintended behavior. To gain meaningful oversight, it is advisable for cybersecurity leaders to create AI agent risk profiles, document each agent's permissions and scope, and categorize agents according to business risk. This approach helps organizations focus their attention where potential disruption is greatest. As this might not be fast enough, cybersecurity leaders must also adopt a “track back” inventory, for example by monitoring changes in utilization patterns for their sensitive APIs.
Gartner identifies agentic AI oversight as a top priority because rapid and often unsanctioned adoption of AI agents is expanding enterprise attack surfaces and increasing the risk of rogue AI automation.
According to Gartner, agentic AI intersects with broader cybersecurity priorities involving governance, AI adoption and cyber resilience. Organizations must balance innovation with controls that reduce risk from autonomous systems.
Gartner notes that AI agents can introduce risks related to excessive autonomy in the form of unauthorized access, unmanaged automation and limited visibility into agent behavior. These risks increase as AI agents gain access to sensitive data and business processes.
Gartner recommends discovering and inventorying AI agents, prioritizing actions to reduce business risks based on these agents’ access to sensitive data and level of automation., reviewing cybersecurity posture assessments, implementing deterministic controls first and complementing them with model security. Then, facing the high volume of automated activity, CISOs will need to upgrade incident response processes to get a chance of discovering and mitigating rogue AI automations.
Attend a Conference
Accelerate growth with Gartner conferences
Gain exclusive insights on the latest trends, receive one-on-one guidance from a Gartner analyst, network with a community of your peers and leave ready to tackle your mission-critical priorities.
Drive stronger performance on your mission-critical priorities.