The bottom line: While AI agents already approve transactions and manipulate databases, more than half of companies cannot fully trace their actions.
AI agents are increasingly gaining access to business-critical financial processes, yet 79 percent of organizations lack a dedicated AI governance structure. This is shown by the 2026 AI Governance Gap Report from Pathlock, which reveals significant blind spots in tracking autonomous systems.
According to the Pathlock survey, 38 percent of surveyed organizations have authorized AI agents to create or modify business records and supplier data. 35 percent allow them to execute workflows across systems, and 28 percent grant them approval rights for transactions. Approximately one-quarter of companies grants AI agents direct access to backend databases. At the same time, 36 percent of companies have already implemented AI agents in finance and accounting environments or are actively planning to do so.
The control deficit is significant: Only 19 percent of organizations have complete real-time visibility of AI agent activities across the entire business system. 53 percent cannot fully verify actions triggered by AI agents. 48 percent have no end-to-end traceability across multiple systems, which makes reconstructing AI-driven outcomes difficult or impossible. Particularly critical is incident response capability: Only 13 percent can investigate AI incidents in real time, 22 percent cannot reliably analyze AI-driven actions at all.
Previous governance approaches are insufficient. Traditional controls have focused for decades on access management – who is allowed to access a system. Autonomous AI agents, however, create a new problem: it is unclear what actually happens after access is granted. Susan Stapleton, GRC expert at Pathlock, emphasizes that real-time verification, traceability, incident response and explainability of AI-driven actions across all business applications will determine an organization’s AI readiness.
Three trends are converging simultaneously: the growth of machine identities, increasingly interconnected enterprise applications, and AI agents autonomously executing business processes. This constellation requires a fundamental shift in perspective – away from reactive, checkbox-oriented security audits toward active, game-theoretic defense approaches. Traditional security methods are not suited to address the challenges posed by autonomous, millisecond-speed AI systems.
Source: www.csoonline.com · Published July 30, 2026
Lumi AI News — AI-assisted curation in accordance with Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.