
Okta’s new Global CISO Insights 2026 survey asked 306 security chiefs whether they trust the AI agents running inside their own companies, and 81 percent effectively said no. The bigger problem sits underneath that worry. Most of these security leaders cannot yet see or govern the AI agents they are already accountable for, which turns AI governance into a visibility problem long before it becomes a control problem.
- Okta surveyed 306 CISOs and cybersecurity executives across six markets; 81 percent worry their AI agents are running with access no one is reviewing.
- Barely half can see the problem they own: 47 percent can identify every agent, and 46 percent can control what those agents reach.
- Only 12 percent of US CISOs feel aligned with their board on AI risk, the authority gap the practitioner steps below are built to close.
What 306 CISOs Admitted About Their Own AI Agents
Ask a CISO in this survey where their AI agents are running right now, and more than half cannot give a complete answer. Only 47 percent said they can identify every agent in their environment. Fewer still, 46 percent, can control what those agents connect to and what corporate data they can reach, and just 45 percent can authorize what the agents are allowed to do. Okta built the report around three plain questions every security team should be able to answer: where are my agents, what can they connect to, and what can they do. On these numbers, most cannot answer any of the three with confidence.
Shadow AI is why the inventory keeps slipping. 68 percent of CISOs reported seeing at least some unsanctioned AI use, staff wiring in helpful tools without approval or a security review. Where agents are sanctioned, the boundaries stay loose. Roughly one in five organizations let agents reach network resources through shared credentials or highly permissioned service accounts. Only about a quarter manage their agents through a dedicated access framework, the kind of shortfall that other 2026 AI governance surveys keep finding. The concern reaches past the agents themselves: 57 percent of these leaders are extremely or very worried about AI-driven breaches, climbing to 84 percent in the United States.
Why AI Governance Stalls at 12% Boardroom Alignment
The report reads, at first, like a maturity problem: catalog the agents, tighten the access framework, close the gap. That framing suits Okta, which sells identity governance, and it is not wrong. It is incomplete. The deeper constraint the survey surfaces is authority, not tooling. Only 31 percent of CISOs feel fully aligned with their CEO and board on how much AI risk the business should accept, and in the United States that number falls to 12 percent. Fewer than half believe their board treats AI security as a business enabler rather than a brake on growth.
That alignment gap is the load-bearing risk. A security team can buy an access framework, but it cannot unilaterally slow the rollout of agentic AI that the CEO is championing for productivity. When 81 percent of security leaders worry about ungoverned access while their boards keep the throttle open, accountability has outrun authority. The same pressure is showing up elsewhere: we recently covered how the governance burden landing on CISOs is pushing a quarter of them to consider walking away.
How Security Teams Close the AI Agent Visibility Gap
The order matters, because you cannot govern what you have not found, and you cannot win board backing without the inventory to show them.
Run Okta’s three questions as an inventory sprint – Point your identity and platform teams at where every agent runs, what it connects to, and what it can touch. Only 47 percent of your peers can answer the first question today.
Kill shared-credential access before you approve another agent – Roughly one in five organizations still let agents ride shared credentials or over-permissioned service accounts. Give each agent its own scoped identity, and put it behind the dedicated access framework only a quarter of firms run today.
Take the 12 percent alignment number into your next board meeting – Pin down an explicit AI risk appetite before the next agent ships. Reframe security as the enabler that keeps the rollout moving under guardrails the board has signed off on.
The CISO who still cannot say where every agent runs has plenty of company, since 81 percent of this survey share the worry. What comes next is the inventory and the board mandate to act on it, and this quarter is when AI governance turns from a worry into a list.
Join our LinkedIn group Information Security Community!









