Complete data security

Agentic AI governance gap: why data security must be complete

Samuel Hill, Product Marketing at MIND

Sep 16, 2026

Policies were written for what AI produces. The risk now sits in what AI does with your data.

Ninety-eight percent of large US companies now have formal AI governance policies. Twenty-six percent of the ones running AI agents can't detect an unauthorized agent operating inside the business. Both numbers come from the same survey, EY's inaugural US AI Risk and Governance Survey, published on Tuesday. Side by side, they describe the problem most security leaders are living with this fall. The policy work is finished while the agents it was meant to govern are still running unseen.

EY's own framing is the sharpest line in the report. Governance designed for AI outputs may not be sufficient for AI actions. An agent that runs code or places an inventory order is touching data along the way, in places a policy document never named.

Why doesn't anyone own the AI agent after deployment?

EY surveyed 202 senior AI decision-makers at publicly traded US companies with at least $1 billion in revenue. Among those already using agentic AI, 49% said their governance framework hadn't been updated for agentic risk. Cybersecurity Dive's read of the report adds two findings worth sitting with. Nearly six in ten respondents perceived that no single group oversaw agents once deployed. Nearly four in ten described accountability for agent oversight as undefined.

The technical picture underneath looks the same. The agent gets approved once, at deployment. Then it runs. It reads from SharePoint, writes to Salesforce and pastes into a chat window. Each of those surfaces is watched by a different control owned by a different team, so nobody sees the whole path.

Identity is heading the same way. IDC research published with GuidePoint Security this week found non-human identities outnumbering humans by as much as 75 to 1 in some environments. Non-human identities were the initial entry point in 19% of confirmed incidents across roughly 650 organizations, level with phishing and stolen credentials. Nearly eight in ten respondents said they had high confidence they could see every identity across their environments, yet more than four in ten also named inventory or ownership gaps as a top challenge.

What does a governance gap cost when it reaches your data?

EY found that 89% of respondents encountered AI-related risk in the past year. Thirty-six percent reported an incident with a materially negative impact, data loss included. IBM's 2026 Cost of a Data Breach Report fills in the mechanism. Among organizations that suffered attacks on their AI systems, 92% had failed to properly control access to those tools. The share of breaches involving shadow AI more than doubled year over year to 43%. IBM's researchers called the outcome predictable, with expanded attack paths and incidents driven by basic enforcement gaps that don't require attacker sophistication.

If you're the security leader reading these numbers, you've likely felt the pattern already. You signed off on an agent pilot in Q2. It now has a service account, a token to your CRM and a habit of summarizing documents from folders nobody has labelled since 2019. Your DLP watches email and endpoints. Your DSPM watches cloud storage. Your CASB watches sanctioned SaaS. The agent moves across all three in a single task. Each tool sees a fragment.

Why can't fragmented tools cover an agent's full path?

Most data security stacks were assembled one gap at a time. DSPM for data at rest. DLP for data in motion. Something else bolted on for AI prompts. Each product classifies data its own way and enforces policy at its own chokepoint. That worked when a human moved data one step at a time through predictable channels.

An agent doesn't do that. It reads a contract from a file share and, within seconds, sends three sentences of it into a prompt. A control that only understands data at rest never sees the send. A control that only inspects the network never understood what the file was. The seams between tools have become the route the data takes out.

Microsoft's 2026 Data Security Index, based on responses from more than 1,700 security leaders, ranks poor integration and the lack of a unified view across environments as the top barriers to visibility and governance. It also found that 32% of data security incidents already involve generative AI tools. The people who run these programs have already named the problem.

How does complete data security close the gap?

It doesn't have to be this way. The oversight problem gets smaller when the control sits with the data rather than with any one channel, because the data is the one constant on the agent's path.

This is what MIND means by Complete. Discovery, detection and prevention run in one platform, from one classification of what the data is. MIND connects to where sensitive data lives, across SaaS apps, on-premise file shares, endpoints, email and AI tools. Classification works by content and context together, so a payroll report is recognized as a payroll report whether it's sitting in a share or half-pasted into a prompt.

Data at rest and data in motion are covered from the same architecture. When a risk shows up in a repository, MIND can remove the public link, adjust permissions or escalate to the owner. When the same data starts to move, prevention happens in real time on the endpoint and in the browser, with no SSL inspection in the path.

Identity and data are handled together, including agentic identities. MIND's controls extend to AI agents acting on behalf of humans, so an agent's data exposure carries the same boundaries a person's would. It gives the unowned agent in EY's survey an owner of a practical kind. We aren't just logging what the agent touched. We're minding the boundary of the data itself, wherever the agent takes it.

None of this asks you to rip out what you have. Existing labels and Purview deployments get smarter rather than replaced. The platform has scaled to hundreds of thousands of endpoints across customers with zero operational issues.

“What's been missing is a central place that could put everything together. Tell us not only about data at rest, but data in flight.”

CISO and CTO

Global Investment Firm

What should a CISO do this quarter?

EY's own advice is to focus assurance less on whether a control was designed and more on whether it can identify and interrupt autonomous activity before it becomes a material failure. That's a data question before it's a governance question. Pick one agent that's in production today and trace every place it reads from and writes to. If that path crosses three tools with three different definitions of sensitive, you've found your gap.

Then see what one platform looks like against that same path. MIND deploys in minutes and shows you what it found within a day. Book a demo and bring the agent you're least sure about.

Let's mind what matters.

Tell us what’s on your mind. Get a live demo or just reach out to us.