Earlier this week I wrote about the control plane battle: the fight over who governs the infrastructure layer where AI agents act, remember, inherit permissions, and get stopped when something goes wrong.
The response prompted a follow-on question I hear constantly: if enterprises understand the risk, why isn’t the governance keeping pace?
The answer is not ignorance. The conversation has reached the boardroom. The funding has not reached the operating model.
THE BOARD-TO-BUDGET GAP
90% / 50%
Of enterprises have discussed AI governance at the board level. Only half have a dedicated budget and formal program to match.
That gap - between executive awareness and funded execution - is where the damage is happening. Boards are talking. CFOs are not allocating. Security teams are flagging risk while business units continue deploying. The organization has acknowledged the exposure without assigning the authority, budget, and staff required to control it.
A new DigiCert survey of 1,001 IT and cybersecurity leaders found that the incidents driving that damage are not coming primarily from model hallucinations or AI-generated code failures. They are coming from AI agents that were unauthorized or misconfigured. The infrastructure problem, not the intelligence problem.
“We would not allow an employee to operate without a verified identity. AI agents should be no different.”
- Amit Sinha, CEO, DigiCert
A parallel Spacelift report corroborates the finding at scale.
93% / 19%
Of organizations experienced AI-caused infrastructure incidents last year. Only 19% had a governance plan in place when those incidents occurred.
That is not a technology maturity problem. That is an accountability gap.
THE RISK IS AGENT AUTHORITY
The causal chain is straightforward: board discussion does not create control. Without a funded owner, there is no reliable agent inventory. Without an inventory, there is no consistent identity model, permission boundary, audit trail, or shutdown process. Without those controls, unauthorized or misconfigured agents become infrastructure risk.
A chatbot can be wrong and remain mostly contained. An agent that can send emails, modify documents, query databases, invoke tools, or execute workflows has a fundamentally different blast radius. The governance question is not whether you trust the model. It is whether the enterprise has infrastructure that enforces what the agent is and is not allowed to do - and proves it after the fact.
THE SHUTDOWN PROBLEM
The most striking data point in the current research corpus is not the incident rate. It is this:
35%
Of organizations admit they could not shut down a rogue AI agent if one emerged.
Not that they would struggle. That they could not do it.
Deploying autonomous systems without reliable shutdown capability is an operational liability that no enterprise risk framework would accept in any other technology context.
We accept it in AI because deployment pressure has outrun governance discipline.
“AI agents and non-human identities will explode across the enterprise, expanding exponentially and dwarfing human identities. Each agent will operate as a privileged super-human with OAuth tokens, API keys, and continuous access to previously siloed data sets.”
- Ev Kontsevoy, CEO, Teleport (RSAC 2026)
THE QUESTIONS ENTERPRISES MUST BE ASKING
For security, risk, and technology leaders evaluating agent infrastructure right now, the governance questions are operational, not theoretical:
· Who authorized this agent to act, and under what policy?
· What systems did it access, and what did it change?
· Can we reconstruct that sequence for an auditor if something goes wrong?
· How do we revoke access when an agent operates outside policy?
· If a rogue agent emerged today, who is responsible for stopping it - and do they have the tools to do so?
Those are not architecture-diagram questions. They are operating-control questions. If the answer depends on manual investigation, tribal knowledge, or a meeting across security, legal, model risk, enterprise architecture, and the business, the enterprise does not yet have governance. It has concern.
WHAT GOVERNANCE AS INFRASTRUCTURE MEANS
Governance as infrastructure means the controls are not advisory. They are embedded into the runtime environment where agents receive identity, inherit permissions, invoke tools, access data, trigger workflows, and create audit evidence.
The policy is not a document sitting behind the deployment. It is the operating boundary inside which the agent is allowed to act. Identity controls, permission boundaries, logging, intervention rights, and shutdown protocols must be enforced in the infrastructure layer, not trusted to model behavior or prompt instructions.
That is why the funding gap matters. Governance as infrastructure requires product ownership, engineering capacity, risk authority, security integration, audit design, and operational support. It is not a slide in a board packet. It is a funded control environment.
THE MARKET IS MOVING. THE OPERATING MODEL IS NOT.
The vendor market is already moving. ServiceNow, Microsoft, Teleport, identity governance providers, privileged access management vendors, cloud security platforms, and infrastructure automation tools are converging around a common pattern: agent identity, access governance, policy enforcement, runtime visibility, auditability, and revocation.
The tools are arriving. The harder question is whether enterprises will fund the operating model required to use them. Platform capability does not create accountability. A purchased control does not govern anything until someone owns it, operates it, tests it, and has the authority to stop the agent when the control fails.
This is where the conversation has decoupled. The enthusiasm for agentic capability has been allowed to move faster than the budget for agentic control. Approximately $1 is spent on AI security for every $735 spent on AI capability. That three-order-of-magnitude imbalance is not a market inefficiency. It is a deliberate organizational choice, made implicitly, quarter by quarter, in every budget cycle where governance got deferred.
Stanford’s 2026 AI Index found that security and risk is now the primary barrier to scaling agentic AI, cited by 62% of organizations - outranking technical limitations and regulatory uncertainty by 24 percentage points. The bottleneck is not model capability. It is governance.
“The model selection debate is fading. What enterprise technology leaders are arguing about in mid-2026 is harder: how to govern AI agents, how to prove financial returns, and whether existing architecture can survive the pace of change.”
- CIOnews, July 2026
WHAT CLOSING THE GAP REQUIRES
Closing the board-to-budget gap requires four organizational commitments that no vendor can provide:
· A named owner. Someone must be accountable for agent governance as a primary responsibility, not a collateral duty. The accountability cannot be diffused across security, legal, model risk, architecture, and business ownership without a single decision authority.
· A funded program. Board discussion without budget is performance. Governance requires dedicated headcount, tooling, engineering support, and a mandate that survives the next quarterly review.
· An agent inventory. You cannot govern what you cannot see. Every agent running in the enterprise - built internally, licensed externally, embedded in a vendor product, or provisioned by a business unit without IT involvement - must be catalogued, classified, and owned.
· Hard controls, not soft instructions. Policy lives in infrastructure, not in prompts. Identity controls, permission boundaries, audit trails, and shutdown protocols must be enforced at the platform layer, not trusted to agent behavior.
Models generate. Agents act. Governance must follow the action.
THE BOTTOM LINE
The control plane battle is real. But it will not be won by architecture diagrams, vendor announcements, or board-level concern. It will be won by organizations that fund governance as infrastructure: named ownership, agent inventory, enforceable permissions, auditability, and shutdown authority.
The regulatory clock is running. Most EU AI Act obligations governing high-risk AI systems take effect in 2026 and 2027, and U.S. sectoral regulators are applying existing supervisory frameworks to AI-enabled decisions now. Waiting for a new AI-specific rulebook is not a governance strategy.
The organizations that close the board-to-budget gap this year will be the ones that can scale agentic AI without absorbing the consequences. The ones that do not will keep generating incident statistics for next year’s surveys.
Right now, in most enterprises, the person accountable for stopping a rogue agent does not exist. That is the gap that matters most. And no platform can close it for them.
#####################
About the Author
Alan L. Paris, CAMS, is an Adjunct Professor and Advisory Board Member for the Strategic Artificial Intelligence (AI) Program at the University of San Francisco School of Management, and Chairman of the Board for the Strategic AI Program at the ZAI Institute. He previously served as Field CTO and Enterprise Architect at ServiceNow, leading AI strategy, agentic implementation, and platform architecture for marquee financial services accounts. He is the author of It’s Not About AI: A Complete Guide to ServiceNow Agentic AI Implementation, a practitioner-focused guide to designing and deploying agentic AI within complex organizations. Paris has addressed the U.S. Department of State and the Federal Reserve, chaired or presented at more than fifty-five industry conferences across North America, Europe, and Asia, and published more than seventy-five articles on artificial intelligence, anti-money laundering, enterprise risk management, and financial markets technology. He has been interviewed by media including CNN, the Wall Street Journal, and the Financial Times.
https://theparisgroupllc.com/
Connect on LinkedIn: linkedin.com/in/alanparis
#AgenticAI #AIGovernance #EnterpriseAI #IdentitySecurity #NonHumanIdentity #CIO #CISO #RiskManagement

