Two-Thirds of Enterprises Lack Agent Governance Policies as Network-Layer Controls Emerge
What happened
Zero Networks announced Least Agency Enforcement, a network-security capability described in coverage by CSO Online that applies the emerging OWASP Top 10 for Large Language Model Applications Least Agency principle at the network and identity layers rather than relying solely on application-level controls. The product uses identity-based micro-segmentation, automated policy generation, and just-in-time multi-factor authentication to restrict AI agents to only the systems they are explicitly authorized to reach, blocking lateral movement if an agent is compromised or manipulated through prompt injection or similar attacks. The announcement is grounded in Zero Networks' own enterprise survey research, which found that approximately two-thirds of organizations currently deploying AI agents have not yet established governance policies for those agents. This data point lands at a moment when a series of documented agent incidents has demonstrated that identity and logging controls are routinely absent from agentic deployments. The development reflects a broader market recognition that policy-layer agent governance is insufficient without technical enforcement at the network perimeter and identity plane.
Why it matters
- ·The two-thirds governance gap cited by Zero Networks is not a vendor talking point in isolation: it aligns with findings from CSA and other researchers showing that enterprises are deploying agents faster than governance frameworks can keep up, leaving organizations exposed to lateral movement and credential abuse when an agent is manipulated or misconfigured.
- ·Compliance teams relying solely on application-level controls or written policies to constrain agent behavior face a runtime enforcement gap -- if an agent's permissions are not enforced at the network and identity layers, policy documents provide no meaningful protection when an agent acts outside its intended scope, a failure mode already observed in recent agentic incidents.
- ·Regulators including the Bank of England are already signaling bespoke agentic AI rules for financial services, and the emergence of a named principle like Least Agency in the OWASP Top 10 for Large Language Model Applications suggests that network-layer agent containment will become an expected baseline control, not an optional enhancement.
Governance controls affected
What to do now
- ☐Audit every production AI agent deployment to confirm whether network-layer and identity-layer access constraints exist beyond application-level policy controls.
- ☐Map each deployed agent's authorized system scope and compare actual network reachability against that scope to identify over-permissioned agents.
- ☐Incorporate the OWASP Least Agency principle into your agentic AI deployment readiness assessment criteria as a required technical control, not a recommended practice.
- ☐Review agent credential provisioning workflows to confirm that just-in-time or time-limited credential issuance is feasible for agents operating in sensitive environments.
- ☐Use the two-thirds governance gap statistic as a benchmark metric in your next board or audit committee AI risk report to frame urgency for agentic governance investment.
What to watch next
Compliance teams should monitor whether the OWASP Least Agency concept migrates from advisory guidance into regulatory text, particularly as the Bank of England and EU AI Act implementation bodies develop sector-specific agentic controls. The market entry of dedicated network-layer agent containment products signals that regulators and auditors will soon have a credible technical baseline to reference when evaluating whether an organization's agent controls are adequate. Growing vendor activity in non-human identity governance, illustrated by recent investment in agent identity platforms, suggests that agent credential lifecycle management will emerge as a standalone audit domain within the next 12 to 18 months.
Stay ahead of stories like this
Get every Global AI governance development like this one, plus the rest of the week's developments. Every Thursday.
