Security1 publisher2 min readPublished
Nearly half of surveyed organizations had an AI agent take an unapproved action in the past year
OneTrust's 2026 governance survey puts departmental or scaled AI use at 74% of respondents against 17% with governance embedded by design, and a third say staff reached for unapproved tools because the approved ones came too slowly.
The Watch · Security desk

What happened
- OneTrust's 2026 AI-Ready Governance Report puts departmental or scaled AI adoption at 74% of respondents, spanning individual teams, business functions and operating processes.
- Seventeen percent place themselves at the top maturity level, where governance is embedded by design; the rest describe their approach as reactive and fragmented, or defined but slow and manual.
- Organizations run an average of four governance activities, most commonly risk classification and impact assessments, followed by employee usage controls and policy documentation.
Compiled by The WatchSomething wrong?How this is made
Why it matters
- exposure When a third of organizations see staff route around slow approval channels, the security team's first record of a new data flow is an incident ticket, and the review runs on a tool already holding company data.
- decision Respondents name data loss, corruption or misclassification as both the likeliest incident and the one they are least prepared for. That leaves the data recovery owners holding the runbook for an agent acting outside its remit.
- contradiction Three-quarters of respondents are confident in the individual governance activities they were asked about, but 5% say accountability is defined across the whole AI lifecycle. The confidence figure does not show enforcement capability.
An unapproved action is an agent holding credentials and doing something in a live system that nobody signed off. Nearly half of respondents to the OneTrust 2026 AI-Ready Governance Report reported at least one of those in the past twelve months [6]. OneTrust did not say what the actions were, which systems they touched, or what any of them cost.
The route to those incidents sits in the same survey. A third of respondents say employees used unapproved AI tools because approved options or processes were not available quickly enough [8], and the report ties that to late discovery and reviews conducted after adoption [9]. Ninety-six percent say at least one AI initiative was slowed, paused, or complicated by governance, risk, or review requirements [10]. Both figures describe one gate, and the initiatives it slows most often are the autonomous and agentic workflows [7].
Encouragement of agents runs ahead of control of them. Eighty-seven percent of respondents say their organization encourages AI agent use [4]. Of that total, 47 points come with defined governance, oversight and controls, and 40 points come while governance and controls are still being built [5]. Divide 40 by 87 and 46% of everyone pushing agents is doing it without settled controls [18]. The distance between scaled adoption at 74% and governance embedded by design at 17% is 57 percentage points [19].
The figures are OneTrust's own, reported as percentages of respondents, and OneTrust does not give a respondent count [20]. The prescription in it comes from the company's Chief Innovation Officer, Blake Brannon [17], who said: "Governance has always relied on knowing in advance what a system will do. But AI is faster, there is far more of it, and the same request can be helpful in one context and harmful in another. Static rules worked for governance when a person made every decision. Now, judgment has to live in the runtime itself, deciding and enforcing in the moment AI acts, and standing apart from the tools it governs" [16].
What to watch
- Whether OneTrust publishes a respondent count and sampling method for the 2026 report.
- Whether any of the unapproved-action incidents surface as disclosed breaches with cost figures attached.
- Whether the 33% shadow-use figure moves as sanctioned agent platforms reach general availability.