
Zentera Systems, a pioneer in overlay Zero Trust security for enterprise and AI workloads, has published its latest research report, “Agents of Change.”
The report, based on a survey of 251 security leaders conducted with independent research agency TrendCandy, identifies a growing disconnect between the rapid adoption of AI agents and the traditional governance mechanisms organizations rely on to secure them.
“With the rapid growth of AI agents within organizations, cybersecurity methods have not evolved quickly enough to keep up,” said Zentera CEO Dr. Jaushin Lee. “We discovered that security leaders are seeing AI use continuing to expand but lack confidence in their ability to effectively monitor and secure that technology. The study reveals that they require, but are in most cases lacking, a stricter governance model that closely monitors AI agents while also restricting their permissions, actions, and network access.”
The survey included organizations across multiple industries, with semiconductor companies representing the largest portion of respondents at 70 percent, followed by software and SaaS at 51 percent and financial services at 43 percent. Pharmaceutical and life sciences organizations accounted for 14 percent of respondents.
The research identified five key findings:
1. AI agent fleets are expanding rapidly. Fifty-eight percent of organizations currently operate more than 50 AI agents. That figure is expected to reach 66 percent within the next 12 months, while 38 percent anticipate operating more than 100 agents. In addition, 36 percent of security leaders strongly agree that their company leadership has instructed the organization to deploy AI agents or agentic capabilities.
2. Context represents a major security risk. Seventy-five percent of respondents expressed concern that an AI agent could execute the correct task but do so in an inappropriate environment or location. Eighty-four percent believe AI agents are more likely than employees to cross project boundaries, while 80 percent are concerned that agents could possess access that was never explicitly authorized. The findings indicate that even when an action is technically correct, it can still represent an unauthorized activity depending on the environment and resources involved.
3. Security leaders want controls established before expanding deployments. Eighty-five percent of respondents consider project-level isolation essential or very essential to AI adoption. Before increasing the size of their AI agent fleets, respondents identified explicit authorization as the most important control, cited by 56 percent, followed by project isolation at 51 percent and session logging at 48 percent. Meanwhile, 87 percent agree that authorization represents a missing layer in agentic AI security.
4. High-confidence authorization and audit capabilities remain limited. Only 43 percent of security leaders are very confident that they can demonstrate what AI agents were explicitly authorized to do. Thirty-eight percent are very confident they can establish what an agent actually did using audit records, while 37 percent say they monitor agent activity very closely. Across every oversight capability evaluated in the survey, a majority of respondents did not reach the highest confidence level.
5. Organizations anticipate restricting AI agent usage. Seventy-nine percent of respondents expect their organizations will need to claw back or substantially restrict AI agent usage within the next 18 months. Separately, Gartner predicts that by 2027, 40 percent of enterprises will demote or decommission autonomous AI agents because of governance gaps discovered only after production incidents take place.
The Future of AI: How Zentera is Addressing Emerging Cybersecurity Challenges
Zentera’s agentic AI security tool, Ensage AI, is designed to address the issues identified in the research by providing capabilities that traditional cybersecurity tools may not cover. Its approach combines agent discovery, management, and Zero Trust policy enforcement through a five-stage model:
- Discover: Identify every agent operating within the environment before policies are created.
- Authorize: Assign agents to enclaves and connect identity with access. No agent operates without an authorization decision.
- Contain: Apply enclave policies at the network layer so AI agents remain within defined boundaries, without requiring agent cooperation or providing an opt-out mechanism.
- Observe: Monitor sessions, prompts, and tool calls in real time while continuously building an audit record.
- Maintain: Maintain an up-to-date agent inventory, rotate credentials, and properly decommission agents when projects are completed.
The “Agents of Change” report also outlines actionable strategies that security leaders can use to respond to the challenges and concerns identified by the research.
The full report is available at https://www.zentera.net/resources/agents-of-change-ebook.
Join our LinkedIn group Information Security Community!











