While AI agents may be redefining work and productivity, but some of their top impacts include widespread shadow AI and frequent security incidents.
This is according to a Cloud Security Alliance report commissioned by Token Security which explores how organisations are managing AI agent governance.
The research highlights a shift toward risk- and context-driven policy models. Organisations base their governance decisions on action risk and human authorisation rather than static permissions.
At the same time, agentic AI lifecycle management is maturing, though weak decommissioning practices are creating long-term risk.
Ultimately, this report shows that AI agent governance is evolving into a connected system spanning visibility, lifecycle controls, policy design, and monitoring. As agents scale, organizations must move toward a cohesive governance model aligned with real-world operational impact.
The report found that the majority of organisations (53%) operate agents autonomously for low-risk tasks with human review for higher-risk actions. Only 13% of organisations report fully autonomous models. Monitoring is also largely periodic (95%), reinforcing a governance model based on checkpoints and escalation.
While 68% report high confidence in their visibility, 82% have discovered shadow AI agents in the past year. These agents most commonly appear in internal automation environments (51%) and LLM platforms (47%).
Organisations are improving front-end lifecycle practices. The majority (59%) report clear documentation of agent purpose and 68% conduct permission reviews. However, only 21% have formal decommissioning processes. Just 19% express high confidence that they fully retire their agents.
Recommended reading
- AI Agents Are Transforming Enterprise AI Adoption
- AI Agent Deployments Are Outpacing Security Posture
- AI Agents Go Mainstream, But Fragmentation Is a Major Obstacle
Organisations are converging on action risk (63%) and human authorisation (53%) as the primary signals for governing agent behavior.
Nearly 79% view context-aware controls as important or very important, and 66% report clear guardrails defining agent boundaries.
AI agent-related incidents are common, with 65% reporting at least one in the past year.
These incidents have tangible business impact, including data exposure (61%) and operational disruption (43%). As a result, organisations are prioritising monitoring (28%), risk management (29%), and permission control (19%).





