AI Agent Governance: Trust Without Control
AI agents are gaining organizations’ trust faster than the controls needed to manage them. A new Harness survey shows a gap between confidence in AI agents and the systems in place to test, secure, and stop them when things go wrong.
Companies trust their AI agents more than they can control them
Why it matters
The numbers look reassuring. But when you look at the systems organizations have in place to test, monitor, and stop their AI agents, the picture changes.
Harness surveyed 700 technology professionals at large enterprises already using AI agents in production, pilots, or live proofs of concept. 74% said their testing and evaluations would catch a production impacting failure. Only 19% had an automated gate that blocks every bad release. That's a 55 point gap between confidence and the control in place to back it up. Across testing, security, inventory, cost, and rollback, confidence ranged from 74% to 77%. But organizations often had fewer controls in place to support that confidence.
Can they stop an agent?
That gap becomes clearer when an agent goes wrong and someone needs to stop it.
76% said they could disable or roll back a misbehaving agent within 15 minutes.
Only 33% had an instant kill switch.
Having a way to roll back an agent is not enough. The question is how quickly and reliably someone can intervene when something goes wrong.
Security confidence doesn’t tell the whole story
75% said they were confident in their AI agents’ end to end security
Yet 87% reported at least one agent related security event in the previous 12 months.
Among organizations that said they were confident in their security, 88% had experienced an incident.
Harness found no statistically significant relationship between confidence and incident experience.
Confidence alone doesn’t tell you whether those security controls will hold up when something goes wrong.
What this means for buyers and sellers
For buyers, it’s worth looking beyond confidence and asking how the agent is actually managed:
What can the agent access?
How is it tested before deployment?
How quickly can someone intervene?
What happens when it fails?
For sellers, answering those questions with clear evidence gives buyers a better picture of how the system is controlled and managed.
The takeaway
The organizations in this survey aren’t lacking confidence in their AI agents. The bigger question is whether their controls actually match that confidence. As AI agents take on more responsibility, knowing what they can access, how they are tested, and how people can intervene becomes just as important as knowing what the agent can do.
Work Cited:
Harness. (2026). The State of Agent DLC 2026: Agents Unsupervised: Confidence Without Control. https://www.harness.io/state-of-agent-dlc-2026
Related briefs
- AI Is Running Government. Accountability Is Not Keeping Up. — More than half of government organizations are using AI. Less than half have a formal policy for it. That is not a planning failure. It is an accountability gap that is already producing consequences.
- What Happens When You Add AI Into Education — 85% of teachers feel unprepared to manage AI in their classrooms. 86 percent of students are already using it. That gap does not close on its own. Here is what it actually requires.
- Who Is Healthcare AI Actually Built For? — AI is helping doctors catch diseases earlier and streamline care. But here is the question most healthcare organizations are not asking: does this AI work the same way for every single patient it touches? Because right now, for most healthcare AI systems, the honest answer is that nobody really knows.