New Zentera Systems Research Reveals Security Leaders’ Struggles to Govern AI Agents
The new survey "Agents of Change" highlights the challenges of safely scaling a rapidly expanding technology The post
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
The new survey “Agents of Change” highlights the challenges of safely scaling a rapidly expanding technology
Milpitas, CA (PRUnderground) September 15th, 2026

News Highlights:
Rapidly Growing Agent Fleets: Most organizations run more than 50 AI agents today, with expectations for larger deployments in the coming year.
-
Contextual and Access Risks: Security concerns center on AI agents executing correct actions in the wrong environment, crossing project boundaries, or gaining unauthorized access.
-
Demand for Authorization Controls: A large majority of leaders prioritize project-level isolation and explicit authorization as critical prerequisites to scaling agent fleets safely.
-
Gaps in Oversight Confidence: Fewer than half of leaders express full confidence in their ability to monitor agent activity, audit actions, or prove explicit authorizations.
-
Anticipated Agent Restrictions: Most organizations expect to restrict agent usage within 18 months, aligning with analyst predictions of agent demotions caused by post-deployment governance failures.
Zentera Systems, the pioneer in overlay Zero Trust security for enterprise and AI workloads, today released the research report “Agents of Change.”
Based on a survey of 251 security leaders conducted in partnership with independent research agency TrendCandy, the report illuminates significant gaps between rapid AI agent deployment and traditional governance mechanisms that have failed to keep pace with that deployment.
“With the rapid growth of AI agents within organizations, cybersecurity methods have not evolved quickly enough to keep up,” said Zentera CEO Dr. Jaushin Lee. “We discovered that security leaders are seeing AI use continuing to expand but lack confidence in their ability to effectively monitor and secure that technology. The study reveals that they require, but are in most cases lacking, a stricter governance model that closely monitors AI agents while also restricting their permissions, actions, and network access.”
Survey respondents spanned a range of industries, with the heaviest concentration in semiconductors (70 percent), software and SaaS (51 percent), and financial services (43 percent). Pharmaceutical and life sciences organizations made up 14 percent of the sample.
The study uncovered five main findings:
1. Agent fleets are already large and are still growing. Fifty-eight percent of organizations operate more than 50 AI agents today. Within 12 months, 66 percent expect to operate more than 50 agents, and 38 percent expect to operate more than 100. Thirty-six percent of leaders strongly agree that company leadership has directed the deployment of AI agents or agentic capabilities.
2. The defining risk is context, not capability. Seventy-five percent of leaders are concerned that an AI agent could perform the correct task in the wrong environment or location. Eighty-four percent believe agents can cross project boundaries more easily than employees, and 80 percent are concerned that agents may hold access that was never explicitly granted. A technically correct action can still be unauthorized because of where it happens and what it reaches.
3. Leaders want boundaries in place before they scale. Eighty-five percent say project-level isolation is essential or very essential for AI adoption. Asked which controls they want before expanding agent fleets, leaders rank explicit authorization first at 56 percent, with project isolation at 51 percent and session logging at 48 percent. Eighty-seven percent agree that authorization is the missing layer in agentic AI security.
4. Evidence of authorization remains a minority capability at the highest confidence level. Forty-three percent of leaders are very confident they can demonstrate what AI agents were explicitly authorized to do. Thirty-eight percent are very confident they can prove what an agent did through audit records. Thirty-seven percent monitor agent activity very closely. For each form of oversight the survey measured, most leaders stop short of the highest confidence tier.
5. A restriction event is the expectation, not the exception. Seventy-nine percent of leaders expect their organization will need to claw back or significantly restrict AI agent usage within the next 18 months. Gartner independently predicts that by 2027, 40 percent of enterprises will demote or decommission autonomous AI agents due to governance gaps that are only identified after production incidents occur.
The Future of AI: How Zentera is Tackling Emerging Cybersecurity Challenges
Zentera’s agentic AI security tool, Ensage AI, manages the concerns unearthed in this study by filling the gaps that traditional cybersecurity tools do not address. This centers on discovery, management, and Zero Trust policy enforcement built on a five-stage model:
-
Discover: Find every agent running in your environment before you’ve written a single policy.
-
Authorize: Assign agents to enclaves. Tie identity to access. Nothing runs without a decision.
-
Contain: Enforce enclave policy at the network layer. AI agents operate within declared boundaries–no agent cooperation required, no opt-out possible.
-
Observe: Watch every session, prompt, and tool call in real time. Build the audit record as you go.
-
Maintain: Track agent inventory, rotate credentials, and decommission cleanly when projects end.
The “Agents of Change” report also provides actionable recommendations on strategies security leaders can use to address findings and concerns highlighted in the survey. To read the full report, visit https://www.zentera.net/resources/agents-of-change-ebook