August 25, 2026 · Issue 9 · 6 min read
Agents already reach Salesforce and SAP, and 5 percent of security leaders think they could contain one that turns
A piece published in Fortune on Monday makes a narrow point with a wide bill attached. Google's Agent Payments Protocol(opens in a new tab) can record the limits a user approved and carry that evidence between systems. What it cannot do is bind a specific charge to the specific instruction that produced it. The retailer has a record, the payment service has a record, the AI provider has a record, and each one is accurate. None of them links the transaction to the task. When a customer disputes a charge an agent made, there is no chain of evidence to resolve it with, and that is the most advanced agent payment plumbing currently shipping.
That gap is not theoretical, because the access is already granted. The 2026 CISO AI Risk Report(opens in a new tab) from Saviynt and Cybersecurity Insiders, a survey of 235 security and technology leaders in the United States and United Kingdom published in April, puts 71 percent of respondents saying AI tools already reach core systems like Salesforce and SAP, against 16 percent who say they govern that access effectively. Ninety-two percent lack complete visibility into AI identities. Eighty-six percent do not enforce access policies for them. Seventy-five percent have found unsanctioned AI tools running in production. Five percent are confident they could contain a compromised agent.
The scale numbers point the same direction. SAP LeanIX found 98 percent of companies(opens in a new tab) have deployed agents or plan to, while fewer than half have visibility into an inventory of what they are running and 13 percent believe they have the right governance for it. Gartner's projection in the same piece is more than 150,000 agents at the average global Fortune 500 firm by 2028. An estate that size with no inventory is not a governance problem in the abstract. It is an unbounded set of authenticated actors with production credentials.
The legal side is moving faster than the plumbing. Senator Mark Warner's AI AGENT Act(opens in a new tab) would place non-waivable duties on agent providers, including safeguarding data, avoiding self-dealing, and maintaining auditable records, with the FTC as principal enforcer. It directs NIST to identify or develop open protocols for scope-limited, verifiable consent delegation and revocation, and for auditing what an agent actually did. That instruction is the tell. The standards do not exist. NIST is still working through comments on a February 2026 concept paper on agent identity and permission.
The budget consequence is specific. Most 2026 AI budgets fund models, platform, and integration. Identity for non-human actors, task-level provenance, and log retention long enough to survive a dispute were priced as engineering hygiene, if they were priced at all. They are becoming the evidence a deployer produces when a regulator, a customer, or an auditor asks what the agent was authorized to do. The model vendor will not be holding that burden. The company that deployed the agent will.
Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.
The Alation incident belongs in this conversation rather than in the general breach column, and the reason is what the product does. A data catalog is where an enterprise records what data exists, who owns it, what it is classified as, and who may read it. That metadata is increasingly the input to agent permissioning. If an agent asks what it is allowed to touch, something like a catalog answers.
Alation reported degraded service on August 18, confirmed a cyberattack on August 20, described the activity as isolated to one system, and has not said whether anything was taken. That is a normal early disclosure posture. It is also, for a customer, an unanswerable question: an incident in the system that describes your data estate cannot be scoped from the outside. Roughly half the Fortune 1000 is in that position this week.
Three questions are worth putting in writing this quarter.
First, which systems can an agent reach today under a credential nobody reviews on a schedule. Not which systems it is approved for, which systems the credential actually opens. The gap between those two numbers is where the 71 percent and the 16 percent come from.
Second, how long agent action logs are retained, and whether they record the authorizing instruction alongside the action. If the log says an API call happened but not what task it was serving, it will not settle a dispute, and it will not satisfy the kind of recordkeeping duty the AI AGENT Act contemplates.
Third, what the vendor contract says about incident scoping for the systems that hold your metadata. Most software agreements were written for an outage. The question this week is different: when a vendor cannot characterize its own incident, who bears the cost of assuming the worst.
None of these require new spend to answer. They require someone to go get the numbers before a regulator asks for them.
Also worth knowing
- Google can track exactly how your agent spends your money, but not whether you approved it(opens in a new tab)
Fortune
Agent Payments Protocol records approved limits and moves evidence between systems, but nothing in those records ties a charge to the task the user gave. Disputes have no chain to resolve them with.
- 71 percent say AI tools reach core systems, 16 percent govern that access(opens in a new tab)
Saviynt
The 2026 CISO AI Risk Report also found 92 percent lack full visibility into AI identities and 5 percent are confident they could contain a compromised agent. Access was granted before control was.
- Agent sprawl is now a board-level governance issue(opens in a new tab)
SAP News Center
SAP LeanIX puts agent deployment or planning at 98 percent while fewer than half of firms can inventory what they run. Gartner projects over 150,000 agents per Fortune 500 firm by 2028.
- The federal AI AGENT Act would make agent recordkeeping a legal duty(opens in a new tab)
Davis Wright Tremaine
Warner's bill imposes non-waivable duties on agent providers, names the FTC as enforcer, and tasks NIST with building consent delegation and audit protocols that do not exist yet.
- AI data giant Alation confirms cyberattack(opens in a new tab)
TechCrunch
Alation serves over 500 companies including roughly half the Fortune 1000. It called the incident isolated but did not say whether data was taken, leaving customers unable to scope their own exposure.