Skip to content

August 25, 2026 · Issue 9 · 6 min read

Agents already reach Salesforce and SAP, and 5 percent of security leaders think they could contain one that turns

A piece published in Fortune on Monday makes a narrow point with a wide bill attached. Google's Agent Payments Protocol(opens in a new tab) can record the limits a user approved and carry that evidence between systems. What it cannot do is bind a specific charge to the specific instruction that produced it. The retailer has a record, the payment service has a record, the AI provider has a record, and each one is accurate. None of them links the transaction to the task. When a customer disputes a charge an agent made, there is no chain of evidence to resolve it with, and that is the most advanced agent payment plumbing currently shipping.

That gap is not theoretical, because the access is already granted. The 2026 CISO AI Risk Report(opens in a new tab) from Saviynt and Cybersecurity Insiders, a survey of 235 security and technology leaders in the United States and United Kingdom published in April, puts 71 percent of respondents saying AI tools already reach core systems like Salesforce and SAP, against 16 percent who say they govern that access effectively. Ninety-two percent lack complete visibility into AI identities. Eighty-six percent do not enforce access policies for them. Seventy-five percent have found unsanctioned AI tools running in production. Five percent are confident they could contain a compromised agent.

The scale numbers point the same direction. SAP LeanIX found 98 percent of companies(opens in a new tab) have deployed agents or plan to, while fewer than half have visibility into an inventory of what they are running and 13 percent believe they have the right governance for it. Gartner's projection in the same piece is more than 150,000 agents at the average global Fortune 500 firm by 2028. An estate that size with no inventory is not a governance problem in the abstract. It is an unbounded set of authenticated actors with production credentials.

The legal side is moving faster than the plumbing. Senator Mark Warner's AI AGENT Act(opens in a new tab) would place non-waivable duties on agent providers, including safeguarding data, avoiding self-dealing, and maintaining auditable records, with the FTC as principal enforcer. It directs NIST to identify or develop open protocols for scope-limited, verifiable consent delegation and revocation, and for auditing what an agent actually did. That instruction is the tell. The standards do not exist. NIST is still working through comments on a February 2026 concept paper on agent identity and permission.

The budget consequence is specific. Most 2026 AI budgets fund models, platform, and integration. Identity for non-human actors, task-level provenance, and log retention long enough to survive a dispute were priced as engineering hygiene, if they were priced at all. They are becoming the evidence a deployer produces when a regulator, a customer, or an auditor asks what the agent was authorized to do. The model vendor will not be holding that burden. The company that deployed the agent will.

Researched and drafted by an automated workflow, then reviewed and edited by a human editor before publication. Every source is linked. See how we use AI here.

The Alation incident belongs in this conversation rather than in the general breach column, and the reason is what the product does. A data catalog is where an enterprise records what data exists, who owns it, what it is classified as, and who may read it. That metadata is increasingly the input to agent permissioning. If an agent asks what it is allowed to touch, something like a catalog answers.

Alation reported degraded service on August 18, confirmed a cyberattack on August 20, described the activity as isolated to one system, and has not said whether anything was taken. That is a normal early disclosure posture. It is also, for a customer, an unanswerable question: an incident in the system that describes your data estate cannot be scoped from the outside. Roughly half the Fortune 1000 is in that position this week.

Three questions are worth putting in writing this quarter.

First, which systems can an agent reach today under a credential nobody reviews on a schedule. Not which systems it is approved for, which systems the credential actually opens. The gap between those two numbers is where the 71 percent and the 16 percent come from.

Second, how long agent action logs are retained, and whether they record the authorizing instruction alongside the action. If the log says an API call happened but not what task it was serving, it will not settle a dispute, and it will not satisfy the kind of recordkeeping duty the AI AGENT Act contemplates.

Third, what the vendor contract says about incident scoping for the systems that hold your metadata. Most software agreements were written for an outage. The question this week is different: when a vendor cannot characterize its own incident, who bears the cost of assuming the worst.

None of these require new spend to answer. They require someone to go get the numbers before a regulator asks for them.

Also worth knowing