AI Governance Institute logo
AI Governance Institute

Intelligence for Compliance and GRC Teams

← News

Two-Thirds of Enterprises Lack Agent Governance Policies as Network-Layer Controls Emerge

What happened

Zero Networks announced Least Agency Enforcement, a network-security capability described in coverage by CSO Online that applies the emerging OWASP Top 10 for Large Language Model Applications Least Agency principle at the network and identity layers rather than relying solely on application-level controls. The product uses identity-based micro-segmentation, automated policy generation, and just-in-time multi-factor authentication to restrict AI agents to only the systems they are explicitly authorized to reach, blocking lateral movement if an agent is compromised or manipulated through prompt injection or similar attacks. The announcement is grounded in Zero Networks' own enterprise survey research, which found that approximately two-thirds of organizations currently deploying AI agents have not yet established governance policies for those agents. This data point lands at a moment when a series of documented agent incidents has demonstrated that identity and logging controls are routinely absent from agentic deployments. The development reflects a broader market recognition that policy-layer agent governance is insufficient without technical enforcement at the network perimeter and identity plane.

Why it matters

  • ·The two-thirds governance gap cited by Zero Networks is not a vendor talking point in isolation: it aligns with findings from CSA and other researchers showing that enterprises are deploying agents faster than governance frameworks can keep up, leaving organizations exposed to lateral movement and credential abuse when an agent is manipulated or misconfigured.
  • ·Compliance teams relying solely on application-level controls or written policies to constrain agent behavior face a runtime enforcement gap -- if an agent's permissions are not enforced at the network and identity layers, policy documents provide no meaningful protection when an agent acts outside its intended scope, a failure mode already observed in recent agentic incidents.
  • ·Regulators including the Bank of England are already signaling bespoke agentic AI rules for financial services, and the emergence of a named principle like Least Agency in the OWASP Top 10 for Large Language Model Applications suggests that network-layer agent containment will become an expected baseline control, not an optional enhancement.

Governance controls affected

What to do now

  • Audit every production AI agent deployment to confirm whether network-layer and identity-layer access constraints exist beyond application-level policy controls.
  • Map each deployed agent's authorized system scope and compare actual network reachability against that scope to identify over-permissioned agents.
  • Incorporate the OWASP Least Agency principle into your agentic AI deployment readiness assessment criteria as a required technical control, not a recommended practice.
  • Review agent credential provisioning workflows to confirm that just-in-time or time-limited credential issuance is feasible for agents operating in sensitive environments.
  • Use the two-thirds governance gap statistic as a benchmark metric in your next board or audit committee AI risk report to frame urgency for agentic governance investment.

What to watch next

Compliance teams should monitor whether the OWASP Least Agency concept migrates from advisory guidance into regulatory text, particularly as the Bank of England and EU AI Act implementation bodies develop sector-specific agentic controls. The market entry of dedicated network-layer agent containment products signals that regulators and auditors will soon have a credible technical baseline to reference when evaluating whether an organization's agent controls are adequate. Growing vendor activity in non-human identity governance, illustrated by recent investment in agent identity platforms, suggests that agent credential lifecycle management will emerge as a standalone audit domain within the next 12 to 18 months.

Stay ahead of stories like this

Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.

Powered by Buttondown.

Related Coverage

Corporate Policy2026-07-28

Hush Security's $30M Series A Puts NHI Credential Governance and Agent Registries on the Enterprise Compliance Agenda

Tel Aviv-based Hush Security has closed a $30 million Series A round, bringing total funding to $41 million, to expand its machine access platform for AI agent governance. The platform registers AI agents in a central registry, enforces just-in-time scoped permissions at runtime, and maintains a full audit trail for each agent interaction. The raise signals growing market pressure on enterprise compliance teams to implement formal non-human identity controls as agentic deployments scale.

Research2026-07-24

Meta Sev-1 Agent Incident Exposes Authorization Failures That Standard Access Controls Were Not Built to Catch

A Sev-1 data exposure incident at Meta involved an internal AI agent making sensitive user and company data accessible to unauthorized engineers for approximately two hours. Research published by DeepInspect identifies absent or misapplied identity binding and access-control enforcement at the agent request layer as the root cause. The incident illustrates a systemic gap in how enterprises extend traditional access-control frameworks to cover AI agent operations.

Corporate Policy2026-07-30

Okta's $200M Permiso Deal Puts AI Agent Identity Governance on the Vendor Map

Okta has agreed to acquire Permiso Security for approximately $200 million in an almost all-cash transaction expected to close in fiscal Q3 2027. Permiso's platform monitors cloud environments for suspicious activity by users, applications, and AI agents after access is granted. The deal extends Okta's identity security capabilities into non-human and machine identity governance, a control gap that has grown sharply as autonomous AI agents proliferate in enterprise infrastructure.