Confidence and incidents cannot both be right
A survey of 362 IT decision-makers at companies with 100 or more employees, commissioned by Guild.ai and conducted by Morning Consult, found that 96.4 percent of respondents are confident they have a complete inventory of the AI agents running in their organization. The same survey found that 66.7 percent of those organizations experienced an agent-related operational incident in the past 12 months. Those two numbers cannot both describe a well-governed environment, and the gap between them is the real finding: IT leaders are confident in a picture of their agent footprint that their own incident history contradicts.
The survey, fielded in early August 2026 with a margin of error of plus or minus five percentage points, also found that 96 percent of organizations report having AI agents already in production, and 47 percent are running dozens or more. That scale, combined with a two-thirds incident rate, means agent-related operational failures are now a routine feature of enterprise IT rather than an edge case, and the confidence gap suggests most CIOs are learning about their real exposure only after something breaks, not from a proactive inventory process.
The tooling gap behind the confidence gap
The instrumentation data explains why confidence outpaces reality. Only 42.7 percent of surveyed organizations have a centralized dashboard or monitoring tool covering their AI agents, and just 39.8 percent maintain logging or audit trails sufficient to reconstruct what an agent did after the fact. Without either capability, an inventory claim is closer to an estimate than a verified count, since teams cannot systematically detect agents deployed outside sanctioned channels or track what those agents actually did once running.
This mirrors a pattern enterprise security teams have seen before with shadow IT and unmanaged SaaS, but the stakes are different because agents take autonomous action rather than just storing data. A dashboard gap in traditional software inventory means you might miss a license renewal; a dashboard gap in agent inventory means you might miss an agent that has been taking unauthorized actions against production systems for months. CIOs who have not yet built centralized agent observability should treat this survey's incident rate as the cost of that gap, not a hypothetical risk.
Kill switches lag further behind than dashboards
Even fewer organizations can act quickly once a problem is identified. Just 31 percent of surveyed organizations can immediately stop a malfunctioning agent through an automated kill switch, though that figure rises to 76.5 percent when combining automated and manual intervention methods within a few minutes. The remaining organizations, roughly a quarter of respondents, have no fast way to halt an agent once it starts misbehaving, which turns any incident into an extended-duration event rather than a contained one.
The distinction between automated and manual stopping matters operationally. A manual kill process depends on a human recognizing the problem, locating the right control, and acting fast enough to limit damage, a chain with far more failure points than an automated circuit breaker triggered by anomaly detection. Organizations relying primarily on manual intervention are effectively betting that their monitoring will surface problems fast enough for a human to react, a bet the 66.7 percent incident rate suggests is not consistently paying off across the industry.
Growth is outrunning governance, not the other way around
The survey found incident rates climb sharply with team size: organizations with 20 to 199 engineers reported a 78 percent incident rate, compared to 43 percent at the smallest organizations surveyed. That pattern suggests governance processes that work at small scale, informal awareness of who is running what, break down as agent deployment spreads across more teams, and that most organizations are not proactively rebuilding governance to match. Growth is exposing weak governance rather than governance maturing alongside growth.
Compounding the risk, 61.2 percent of engineering and IT teams report losing time to duplicate agent work, meaning the same governance gaps that create incident risk are also creating direct productivity waste as teams unknowingly build redundant agents. And 60.6 percent of IT leaders believe employees are deploying agents without approval, while only 35.9 percent of organizations require agent registration before deployment. That gap, most leaders suspect unauthorized deployment is happening but few have the policy in place to prevent it, is one of the more directly actionable findings in the survey.
What this means for your governance roadmap
This survey gives CIOs a rare, quantified benchmark for a problem most have been managing by instinct: a 66.7 percent incident rate against 96.4 percent inventory confidence is a governance maturity gap you can now measure your own organization against directly, rather than guessing whether your agent oversight is ahead of or behind the field. If your organization cannot answer whether it has centralized agent monitoring, audit logging, and an automated kill switch, you are statistically more likely than not to already be exposed to an unreported incident.
The most immediately fixable gap is the cheapest one: requiring agent registration before deployment costs far less than building full observability infrastructure, yet only 35.9 percent of organizations have done it despite 60.6 percent suspecting unauthorized deployment is already happening. Before investing in dashboards and kill switches, CIOs should close the registration gap first, since it is the control most directly aimed at the exact behavior most leaders already say they suspect is occurring inside their own organization.



