惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

U
Unit 42
博客园 - Franky
T
Tailwind CSS Blog
OSCHINA 社区最新新闻
OSCHINA 社区最新新闻
月光博客
月光博客
人人都是产品经理
人人都是产品经理
雷峰网
雷峰网
Hugging Face - Blog
Hugging Face - Blog
有赞技术团队
有赞技术团队
freeCodeCamp Programming Tutorials: Python, JavaScript, Git & More
阮一峰的网络日志
阮一峰的网络日志
C
Check Point Blog
爱范儿
爱范儿
T
The Blog of Author Tim Ferriss
aimingoo的专栏
aimingoo的专栏
Stack Overflow Blog
Stack Overflow Blog
博客园 - 聂微东
钛媒体:引领未来商业与生活新知
钛媒体:引领未来商业与生活新知
L
LangChain Blog
云风的 BLOG
云风的 BLOG
MyScale Blog
MyScale Blog
Microsoft Security Blog
Microsoft Security Blog
The Cloudflare Blog
博客园 - 三生石上(FineUI控件)

Latest news

LG G6 vs. LG G5: I compared the latest OLED TV models, and it's a surprisingly tough choice I saw the 'MacBook Pro for Linux users' for the first time, and it's a legit Windows threat I'm putting Motorola above Samsung when it comes to flip phones - and won't think twice I got an early look at ChatGPT Images 2.0, and it's impressive - with one exception I tested Surfshark's new Dausos VPN protocol - here's how it compares to WireGuard How to easily encrypt your files on an Android phone - for free I'm not giving up on DJI cameras yet - not when they can upset my GoPro like this The best website builders for small businesses in 2026: Expert tested and reviewed Why I'm recommending last year's phones over 2026 models - with one exception This powerful Gemini setting made my AI results way more personal and accurate After testing this HP laptop, I get why its 'boring' design is adored by business users The best TV antenna of 2026: Expert tested Your old iPad or Android tablet can be your new smart home panel - here's how Apple's original AirTag still tracks effectively, and you can get a 4-pack for its best price ever T-Mobile will give you an iPad for $99 when you sign up for a new line - here's how How to qualify for Apple's education discount - and get a $499 MacBook Neo for school T-Mobile will give you a Samsung Galaxy Watch 8 for free - how to get yours Prolonged AI use can be hazardous to your health and work: 4 ways to stay safe Verizon will give you a free iPad or Apple Watch with your next iPhone - how the deal works The best laptops of 2026: Expert tested and reviewed I hid 4 Bluetooth trackers (including AirTags) to test their reliability - here's how Android rivals compared I stopped using my iPhone's hotspot after testing this 5G router - and that won't change The best Kindles in 2026: Expert recommended Does Best Buy price match? Everything to know about matching prices online and in-store The best WordPress hosting services of 2026: Expert tested and reviewed The best Apple Watch of 2026: Expert tested and reviewed The best TV screen cleaners of 2026: Expert recommended The best 50-inch TVs of 2026: Expert tested I traded my Sonos Era 300 for Denon's new home speaker - and see no reason to go back AI-powered website builders have come a long way - here's your best option in 2026
77% of IT managers say their AI agents are out of control...
2026-04-28 · via Latest news
aicubesgettyimages-2267424540
J Studios/ DigitalVision via Getty Images

Follow ZDNET: Add us as a preferred source on Google.


ZDNET's key takeaways

  • Only 23% of IT managers have complete control over their agents.
  • A majority say security guardrails will be inadequate within the next six months.
  • Agent management needs to be a 'first-class discipline.'

AI agents -- so easy to spin up -- are proliferating out of everyone's control. And that's becoming a problem that may undermine any benefits they are delivering.

That's the conclusion of a just-released survey by Rubrik ZeroLabs, which finds that fewer than one in four IT managers (23%) say they have "complete" control over the agents within their organizations. To make matters worse, these agents aren't necessarily delivering the productivity sought. A majority, 81%, report that the agents under their purview require more time in manual auditing and monitoring than they were intended to save via workflow improvements. Security is also less than stellar, the survey adds.

Also: Scaling agentic AI demands a strong data foundation - 4 steps to take first

Creating AI agents is easy, and the problem is "users often turn off VPNs or otherwise skirt security controls to spin up agents to act as assistants," the report's authors state. The result is a large volume of unsanctioned AI applications, both internally and launched by vendors.    

Agent sprawl resembles early cloud adoption

Across the industry, there is concern that agents are starting to get out of hand, with agent sprawl now a pervasive problem. "We are already seeing patterns similar to early cloud adoption, where teams spin up agents independently using different frameworks and vendors," said Kriti Faujdar, senior product manager at Microsoft. "This leads to fragmentation, inconsistent governance, and hidden security gaps."  

Also: The rise and risks of agent management platforms

The authors of the ZeroLabs survey found a disconnect between perceived control and operational reality among agents. Just about all IT managers, 86%, anticipate that agentic proliferation will outpace security guardrails in the next year. More than half (52%) expect this to happen within the next six months. Plus, nearly all respondents indicate they lack the "undo" capabilities necessary to roll back unintended agent actions. 

Also: User interfaces as we know them are dead - 4 ways to prep for 'disposable' UIs

With the proliferation of agents across enterprise systems, industry observers worry that such sprawl is becoming too difficult to manage and contain. "Any team with API access can spin up an agent in an afternoon," said Nik Kale, principal engineer and member of the Coalition for Secure AI. "Multiply that across a large enterprise, and you get hundreds of agents with overlapping permissions, no consistent identity model, and no one who can tell you the full inventory."  

Agentic observability can be notoriously challenging, and the ZeroLabs authors point to a growing need for telemetry for understanding chains of agentic actions, punctuated by enforcement points for security.

5 post-deployment questions 

Tracking agent viability means answering the following questions post-deployment, as identified by the ZeroLabs study's authors: 

  1. What did the agent do? Called a trace, this is the ability to replay or at least reconstruct exactly what happened.
  2. Why did it do it? What did the agent believe caused it to take certain steps?
  3. What did it touch? Audit trails should contain a comprehensive list of any data or tools an agent interacted with.
  4. Did it succeed, safely, and at what cost? How are organizations measuring task success rate, cited outputs, policy violations, or human escalations for an accurate understanding of ROI?
  5. Where did it fail? Can we reproduce the failure in order to address it?

These are questions that are currently not being answered, the report states. As a result, many administrators and their organizations are unable to "define acceptable agentic behavior; audit what resources and tools agents can access; create policies for triggering a human in the loop; or roll back agentic actions."

Trade-off between speed and governance

As agents act autonomously, they pose a greater risk than traditional software, said Faujdar. In today's environment, there is a trade-off between speed and governance. "Organizations want to move fast, but without clear guardrails, they risk creating systems that are difficult to trust, audit, or scale. The winners will be those who treat agent management not as an afterthought, but as a first-class discipline."

Keeping agents current is also a vexing challenge -- as their foundation models tend to drift. "The agent you certified in Q1 is behaviorally different by Q3, through no fault of the platform," said Renze Jongman, founder and CEO of Liberty91. "Your governance model has to assume the ground moves."

Also: I asked 5 data leaders about how they use AI to automate - and end integration nightmares

At this point, there are "too many agents operating outside any governance boundary, including the ones teams build themselves," said Kale, who advises keeping the orchestration layer in the agent stack separate from the model and governance layers. "If all three live inside one vendor's platform, you've handed over your agent's brain, its permissions, and its accountability chain in a single contract."

Agent oversight, Kale added, "should involve security, architecture, and the business unit that owns the outcomes, not just the team that wants to ship the fastest."