Only 37% of organizations have policies to manage AI or detect Shadow AI. The rest are governing systems they can't fully see.

What it says

OWASP's State of Agentic AI Security and Governance (v2, June 2026) makes one evidenced argument: the agentic threats that were hypothetical a year ago now have production incidents, CVEs, and vendor advisories attached to nearly every category.

That 37% figure (drawn from IBM's breach data and cited in the report) is the starting point, not a footnote. Shadow AI is the default condition in most organizations: unsanctioned agents connected to real systems, outside anyone's governance. You can't tier the risk of something you haven't found.

Two more points stand out:

  • Safety and security converge at the deployment layer. Once an agent acts on production systems with real tool access, the same controls govern both an honest mistake and a deliberate attack.
  • Regulators now assume continuous oversight. DORA's 4-hour notification and NIS2's 24-hour warning can't be met by quarterly audit cycles.

Why it matters

OWASP's maturity model ties it together: match governance capability to what you actually deploy, or lower the deployment tier. A vendor copilot and an autonomous agent with external tool access are not the same risk.

And this is becoming a business gate, not only a compliance one. Insurers are now writing AI exclusions into standard policies, and dedicated AI cover requires demonstrated governance to underwrite. Security posture increasingly determines insurability and deal velocity.

Key takeaways

  • Inventory your most autonomous agents first, Shadow AI included, before writing policy.
  • Treat governance maturity as a deployment gate, not a parallel workstream.
  • Stand up runtime monitoring and signed audit logs now; pre-deployment certification expires the moment an agent starts acting.

Sources:
· OWASP — State of Agentic AI Security and Governance (v2) — genai.owasp.org, June 2026
· IBM breach data, cited in the OWASP report

Before an agentic workflow runs in production, what's non-negotiable for you: runtime monitoring, signed audit logs, or a kill switch that works at agent speed?

Mathieu Flamant
Founder · Tech Leader · mathieuflamant.com