Why Companies Can't See What Their AI Agents Are Actually Doing
Three separate 2026 surveys covering nearly 2,600 IT and business leaders all land on the same finding: as AI agents take on more real work, the people running them are losing track of what those agents are actually doing, and it's already causing breaches.

The Blind Spot Nobody Budgeted For
AI agents are supposed to be the thing that finally frees people from watching every step of a process. The irony showing up across three separate 2026 surveys, covering nearly 2,600 IT and business leaders combined, is that as agents take on more real, autonomous work, the people responsible for them are losing track of what those agents are actually doing — and it's already causing security incidents, not just theoretical risk.
AvePoint's State of AI 2026 report, based on a survey of 750 global IT leaders across financial services, healthcare, and government, found that 21.1% of organizations say they don't know whether unsanctioned tools are being used to build AI agents for work processes at all — up from a lower baseline the year before for the equivalent GenAI question (6.3% in 2025 rising to 17.6% in 2026). Meanwhile, 88.4% of the same organizations report experiencing at least one AI agent-related security breach in the past 12 months, with data leakage (50.1%) and manipulation by malicious or untrusted inputs (49.6%) the most common incident types.
What the Data Actually Shows
Dynatrace's Pulse of Agentic AI 2026 report, a survey of 919 senior leaders directly responsible for agentic AI implementation at large enterprises, found the single biggest barrier to moving agentic AI into production isn't cost or even security — it's "technical challenges to managing and monitoring agents at scale," cited by 51% of respondents, essentially tied with security/privacy/compliance concerns at 52%. The same report found only 13% of organizations currently use fully autonomous agents; the rest keep a human in the loop somewhere, and 44% still review communication between AI agents manually because they don't yet have automated tooling to do it.
Monte Carlo's research, cited in its own 2026 Guide to Agent Observability Tools, adds a third data point: in a survey of enterprises building agents in production, 73% said they won't ship an agent without monitoring and alerting already in place — a good instinct, the guide notes, because 53% of the same respondents also expect to significantly redesign agents they've already deployed. In other words, teams that already know they'll need to rebuild what they shipped are still finding it hard to see, in real time, what that shipped agent is doing.
Why Visibility Is Becoming the New Governance Priority
The response shows up in where budgets are actually moving. AvePoint's survey found 62.4% of organizations plan to increase investment specifically in tools that monitor AI agents' actions for policy alignment, 55.7% plan to spend more protecting agents from interference, and 52.4% plan to increase spending on agent cost-management tooling. Dynatrace's respondents lean the same way: nearly 70% already use observability tooling during agentic AI implementation specifically to get real-time visibility into agent behavior, and adoption climbs further (57%) once agents reach live operation.
That's a meaningful shift in framing. A year or two ago, "AI governance" conversations were mostly about model selection and prompt safety. In 2026, the conversation these surveys describe is closer to classic IT operations: who approved this action, what tools did the agent call, what did it actually change, and can someone reconstruct that trail after the fact. Both AvePoint and Dynatrace frame observability as the thing that has to exist before an organization can responsibly hand agents more autonomy — not a nice-to-have layered on top of it.
What This Means for Teams Running Agents Today
If there's one number worth sitting with from all three reports, it's this: even the organizations most invested in agentic AI, the ones Dynatrace surveyed specifically because they're responsible for implementing it, still can't tell you with confidence what most of their agents did last week without dedicated tooling for it. For any team running more than a handful of agents across real business processes, the practical takeaway from this research isn't "wait until the tools mature" — it's that monitoring and audit trails are consistently the thing separating organizations that can scale agent use safely from the 88% currently absorbing breaches they didn't see coming.
Workmate
See what an agent team would do for your business.
Keep reading

AI Agents Are Your Fastest-Growing Identity Risk
Machine identities now outnumber humans by 45-to-1 in the average enterprise, and AI agents are the fastest-growing, least-governed category. What two 2026 security reports reveal about the access-governance gap nobody owns.

Your Company Has Shadow AI Agents. Here's How Many You Don't Know About
A new CSA and Token Security survey finds 68% of organizations feel confident in their AI agent visibility, yet 82% discovered an agent security or IT never knew about in the past year, and 65% had an actual agent security incident. Here's the gap.

AI Agents for CPG Brands: What Reckitt's Global Rollout Shows About Retail Execution at Scale
Reckitt's AI-enabled RGMx and Smart Execution platforms, built with McKinsey and rolled out across 35 markets, now guide pricing, promotion, and shelf-level decisions store by store. Here's what that shows about where AI agents are actually landing in consumer packaged goods.