Scott Wueschinski
← All AI and Agentic POV

AI governance for teams that don't have a CISO yet

Most teams ship agents with shared API keys and no logging. Here is the minimum governance layer to build before you have a security org.

AI & Agentic POV AI Governance

· 4 min read · Source: Gravitee State of AI Agent Security 2026 Report ↗

Most teams I get dropped into do not have a CISO. They have a head of AI, a couple of platform engineers, a Slack channel, and four agents already touching production data. The security function is a future hire. The agents are a present-tense liability.

This is the gap nobody wants to name. The data names it anyway. The 2026 Gravitee survey of 900+ practitioners found that AI agents are no longer experimental, they are production infrastructure, and 80.9% of technical teams have moved past the planning phase into active testing or production. Governance did not come with them. Only 14.4% report all AI agents going live with full security or IT approval.

So the question is not whether you need governance before you have a security org. You already needed it last quarter. The question is what the minimum viable version looks like when the person who would normally own it does not exist yet.

The default state is already a breach waiting to happen

Start with the uncomfortable baseline. 88% of organizations confirmed or suspected security incidents this year. And the reason is not exotic. It is identity. Only 21.9% of teams treat AI agents as independent, identity-bearing entities, and 45.6% still rely on shared API keys for agent-to-agent authentication.

Shared keys are the original sin. When three agents authenticate with the same credential, you cannot tell which one did what, you cannot revoke one without breaking the others, and a single leak hands an attacker your entire surface. Worse, more than half of all agents operate without any security oversight or logging. You are running autonomous software that writes to production, and you have no record of what it touched.

This is where the Cost of Doing Nothing framing earns its keep. CODN is not a slogan. It is a ledger. Every week you run agents on shared keys with silent logs, you accrue a liability that compounds: more unattributed actions, more unrevocable access, more data you cannot prove stayed inside the walls. The bill does not disappear because you are early. It just goes unpaid until an incident forces settlement, usually at the worst possible time and at a multiple of what prevention cost.

The three-part floor you build this week

You do not need a platform, a framework committee, or a compliance consultant. You need a floor. Three parts.

First, auth scoping. Give every agent its own identity and short-lived, action-scoped credentials. This is the one the market has converged on. Agents acting inside a logged-in session need their own identity and short-lived, scoped credentials, so the audit log can tell agent from human. The payoff is concrete: with delegation, the agent acts under its own identity with an explicit scope claim recording what the user authorized, the delegation is time-bounded and action-scoped, and if the agent is compromised, the attacker has the agent’s scoped credentials, not the user’s full authorization. Blast radius becomes one task instead of your whole stack.

Second, audit trails. Not log collection. Traceability. Instrument prompt-to-action traceability: log the intent input, tool call, and resulting system change for every meaningful agent action. The record has to connect back to a human. A usable entry reads like Okta’s example, where the system logs the agent, acting on behalf of a named user, performing a specific action at a specific time, and the delegation remains auditable and revocable without affecting the user’s primary credentials. If your logs cannot answer who authorized this and what changed, they are theater.

Third, escalation. Write the boundary down before launch. Vague scope is not scope. The practitioner version is blunt: define what systems the agent can reach, what data it can read or write, what actions require no review versus which always do, so that ‘can read order history, cannot issue refunds over 50 dollars without approval, cannot access payment details’ is the actual scope. Then name a human. Not four hats on one person. Assign a named owner for every agent identity, including who defines the workflow, who approves its permission scope, and who can revoke it when behavior changes.

Governance people route around is not governance

The failure mode here is overcorrection. Lock it all down, and your engineers build around you. Gartner’s Max Goss put it plainly: without usable sanctioned tools, employees will likely go around the organization’s controls and start using shadow AI, which presents far greater risks.

That is the real argument for building the floor early. It is not about slowing anyone down. A floor lets you say yes faster, because you can trace, scope, and kill any agent on demand. The teams that win the next 18 months will not be the ones who hired a CISO first. They will be the ones who built the governance layer at three engineers and scaled it, instead of bolting it on after the first breach writes the policy for them.

Build the floor now. The CODN meter is already running.