I keep talking to CTOs who have absolutely no idea how many AI agents are running inside their own companies. They can’t even give me a ballpark guess.
That is where we are in late 2026. The reason being the last two years followed the oldest technology pattern: deploy first, secure second. The bill is showing up now.
The Quiet Sprawl Nobody Wanted
Walk into a mid-sized enterprise right now, and you will usually find something like this:
- An AI assistant sitting inside the CRM.
- Coding agents pushing changes to internal repositories.
- A customer-service agent with production data access.
- Third-party AI features baked into SaaS tools nobody re-evaluated.
- Internally built agents, some of them side projects that quietly became critical.
- MCP servers wired to external tools.
- Two or three model providers, sometimes more.
- Employees running personal AI tools on work laptops, entirely off-book.
Each piece looks reasonable in isolation. That is the trap. The security problem lives in what happens when they interact.
I ran a testing engagement at QAwerk this year where the first useful deliverable was a map. Just a plain map of what existed inside the client. They read it and went quiet for about a minute.
The Ordinary Questions Nobody Can Answer
I think we are romanticizing this conversation. The scary talk about “rogue AI” makes for great headlines. The real problem is much more boring.
Try answering these about your own company:
- How many AI agents are running right now?
- Who owns each one?
- Which model does each one call?
- What tools can it invoke?
- What databases can it read, and which can it write to?
- Which agents can take actions rather than only generate text?
- Where do their credentials live?
- What is logged, and for how long?
- What happens on the day the underlying model gets swapped?
- Which of these deployments has security ever formally looked at?
If your team cannot answer these in under an hour, welcome to the club. Most CISOs I talk to cannot either.
This is why I keep telling engineering leaders they need something like an AI agent bill of materials. A living inventory of models, agents, permissions, tools, data reach, owners, and third-party dependencies. Without it, you are securing pieces of a system you do not fully see.
The Attack Surface Is Not the Model
Vendors love to talk about “model security”. I understand why. It sells. An AI agent’s real attack surface, though, is larger than the model, and larger than the prompt.
It looks more like this:
model + prompt + tools + data + APIs + credentials + third-party integrations + surrounding application
Testing the model in isolation misses most of the ways things actually go wrong.
Why Boards Are About to Get Loud
For a long time, AI security lived somewhere between “compliance nice-to-have” and “future problem”. That is changing very fast.
More than 100 companies, including OpenAI, Anthropic, Google, Microsoft, CrowdStrike, Okta, and Fortinet,
Gartner also predicts that by 2028, half of enterprise cybersecurity incident-response work will involve incidents connected to custom AI applications. Half. And they explicitly warn that many of those systems are hitting production before they are meaningfully tested.
The consumer side is also showing the shape of the problem. A product like
We Have Seen This Movie Before
If this feels familiar, it’s because the AI security challenges we are facing right now are the same problems we dealt with in the early days of cloud computing.
Cloud did not die when security teams found misconfigured buckets, exposed keys, shadow infrastructure, and access-control nightmares. An entire industry grew up around making cloud governable. CSPM, CIEM, CNAPP, all of it. The companies that adopted cloud well were the ones that could see, name, and control what they had.
AI is walking the same path.
The first phase asked: how fast can we deploy agents? The next one asks: do we actually know what our agents can touch, and what they can do on their own?
What I Would Do This Quarter
If I were a CTO looking at this today, I would not chase the shiniest defensive product. I would start with the map.
- Inventory every agent and AI-enabled workflow, including the ones hiding inside SaaS tools.
- Write down every external tool and data connection each agent uses.
- Test prompt-injection resistance on the most critical ones.
- Audit credentials and secrets exposure.
- Validate access boundaries. Assume agents will try to reach places they shouldn’t.
- Review third-party AI integrations the same way you review any vendor.
- Simulate misuse and chained tool calls that no one designed for.
- Confirm you can reconstruct, from logs alone, what an agent did after the fact.
- Repeat the whole thing every time models, prompts, tools, or permissions change.
Checking all these boxes takes time. However, using a clear
The rush to ship agents was rational. Anyone who
The Winners of the Agent Race Will Be Boring
I do not think the next few years belong to the companies with the most agents in production. They belong to the ones who can put agents into production without building an invisible security estate they no longer understand.
The security shortcuts everyone took are finally catching up with us, so I’d much rather be the CTO who fixes them steadily over time than deal with a massive crisis in 2028.
Click Here For The Original Source.
