The bottom line: Two-thirds of German companies lack mature governance structures for AI agents, despite the need to equip them with the same identity and authorization concepts as employees.
AI agents are increasingly intervening in business-critical processes and processing sensitive company data. According to a survey, only about 33 percent of German companies have established mature governance structures for digital assistants, even though they require the same access and identity control concepts as human employees.
AI-based agents are assuming increasingly complex tasks in operational and business-critical processes in companies. In doing so, they often gain access to sensitive or personal data that must be protected as carefully as that of human users. Currently, however, only one-third of organizations in Germany have established governance structures that govern the deployment of these systems in a compliant manner.
The core problem is that AI agents must be equipped with identity and authorization management as well as audit trails, just like regular employees. This means: every action taken by an agent must be traceable, access must be limited to what is necessary, and there must be clear responsibility for their actions. Many companies have not yet built these structures into their IT infrastructure.
Against this background, IT vendors are expanding their platforms and management tools with governance functions specifically for AI agents. For CISOs, this represents a necessary investment in control mechanisms that comply with regulatory requirements (such as the AI Act) while not slowing down operational efficiency.
Source: www.security-insider.de · Published 23 July 2026
Lumi AI News — AI-assisted curation pursuant to Article 50 EU AI Act. Paraphrase and classification by Lumi News Pipeline v1.7.3.