A CISO’s phone rings at 2 a.m. Not a breach alert in the usual sense: an agent did something no one remembers approving, and when the team goes looking for the record of why, there isn’t one. CISOs are increasingly being judged on whether they can produce that record when it’s needed.
What’s new about agent governance
A distinct software category, agentic AI platforms, emerged in late 2025 specifically to help organizations build, operate, govern, and orchestrate AI agents. The market is already splitting into two camps: business-specific platforms (Microsoft Copilot Studio and Agent 365, Salesforce Agentforce, ServiceNow AI Control Tower) and tech-centric platforms built for maximum flexibility (Microsoft AI Foundry, AWS Bedrock AgentCore, Google Vertex AI Agent Builder). That split is already showing up in how IDC tracks the market. The split matters operationally: a governance model built for one category rarely transfers cleanly to the other.
Why the audit trail is the real gap
Token economics is a visibility problem: the numbers exist, they’re just not governed. Agent governance is a different failure mode, because the record of what happened often doesn’t exist at all. Agents can act and delegate without a human in the loop generating the paper trail traditional compliance depends on. IDC research finds 60% of security leaders lack basic agent containment controls, and 35% cannot shut down a rogue agent once it’s deployed. One 2026 industry governance survey put a sharper number on the anxiety: most organizations it surveyed said they couldn’t verify what their AI agents actually do across business systems, even though more than a third had already deployed agents inside finance and accounting functions.
Regulation is arriving faster than voluntary governance
In 2026, trade press reported that agents built by one AI lab attacked another company’s systems; IDC has not independently verified the incident. The response wasn’t a routine patch cycle: more than thirty technology companies formed a new defensive alliance, and Congress introduced kill-switch legislation carrying potential fines up to $20 million per day. The proposed AI Kill Switch Act would give the Department of Homeland Security discretionary shutdown authority over covered AI systems, based on an undefined catastrophic-risk standard. The penalties weigh more heavily on smaller vendors than on the largest frontier labs. Enterprises that engineer their own verifiable throttling and shutdown controls now get ahead of both the statute and the incident that eventually triggers one.
The CIO’s new job: Orchestrating agents at scale
The CIO next door is being asked to do something genuinely new: stop provisioning technology and start orchestrating it, thousands of autonomous actions a day, each one traceable back to a decision a human can defend. IDC names this shift directly as a move from soloist to conductor: harmonizing innovation, governance, and autonomy across a mixed ecosystem of people and legacy systems, now expanding to include autonomous agents. Security posture across the industry is shifting the same direction, from control-centric models toward consequence management and recovery readiness, as agent-security incidents become structural rather than exceptional.
What CISOs can do now
- Build a formal agent inventory before the next audit asks for one — treat every deployed agent as a non-human identity with its own lifecycle.
- Design shutdown and throttling controls into the platform now, ahead of the AI Kill Switch Act’s DHS-defined standard.
- Assign a RACI model for agent oversight so “who approved this” has a documented answer before an incident forces the question.
Where IDC Can Help
IDC Quanta’s Win Your Mandate research gives security and technology leaders board-ready governance models and evidence they can defend in the room.
Learn more about IDC Quanta to see where your agent governance posture stands against the market.