If we had $1 for everyone who said, “You can’t govern/manage/secure something you can’t see”, we could retire wealthy.
On one hand, it’s somewhat befuddling how often people may need that reminder. In reality, it is not that they don’t know that happy mantra, it’s that they struggle to gain the requisite visibility into … everything in their IT and OT environments.
Queue artificial intelligence and AI agents. Even if you thought you had full visibility into your environment, Surprise! Everything you knew just flew out the window.
TL;DR: Most organizations can’t count the number of agents they have in production. IDC research (sponsored by GuidePoint Security) found fewer than 1 in 5 organizations run continuous discovery on their agents.
AI agents are in production at massive scale. They are executing tasks, accessing data, making decisions and chaining actions together at machine speed. They can even launch and orchestrate new AI agents without human intervention.
At the same time, most organizations can’t confidently tell you how many agents they have.
Why? Because they’re simply showing up. Everywhere. They’re being rolled out across every industry from manufacturing and supply chains to healthcare, financial services and even government services. And, let’s face it, Shadow AI thinks shadow IT is quaint.
Make no mistake. Agentic AI is an operations problem and the question at the center of it returns to the deceptively simple (and utterly overused): how do you govern something you can’t see? ($1 please ;-))
Did you know fewer than 1 in 5 organizations run continuous discovery on their AI agents. Just over 1 in 4 have fully automated governance for them. Those data points are in IDC’s Worldwide IAM Security Survey (May 2026, n=860) and represent a snapshot of where we are today.
IDC’s new qualitative research, which was sponsored by GuidePoint Security, (“Managing Agentic AI Through the Identity Control Plane: What Organizations Should Look For”) surfaced six new pain points that security and identity leaders described in their own words. Every one of them starts with AI:
The Unexpected Consensus
Perhaps the most interesting detail in the report. No matter how mature the organization is in its AI adoption, every participant is heading to the same destination: a purpose-built, distinctly governed identity class for every agent.
As Laura Babbili said in her blog, “Agentic AI Security: Key Findings from New IDC Research on the Identity Control Plane”, it takes three control planes govern agentic AI: identity (who may act), data (what an agent may touch) and runtime (what it may do in the moment). Data and runtime controls both depend on knowing which agent is acting. But it’s impossible to enforce least privilege, audit actions or contain an incident for an agent that doesn’t have its own identity. Therefore, identity is the control plane upon which both data and runtime rely.
Organizations in the IDC study modeled agents in different ways. Some treat agents as a distinct identity type. Others reuse service accounts or application identities, even if those models don’t exactly fit. And others skip the issue altogether and their agents run using the invoking user’s credentials. This variation doesn’t deviate from the above-stated consensus. Rather, the IDC report shows it as an indicator of how far along they are on the AI maturity curve. IDC defines a four-stage maturity model for agentic AI as:
Today, most organizations are sitting somewhere around stages 1 or 2. But their destination is codified in the security frameworks they’re measured against: Every agent needs a named human sponsor and managed lifecycle.
This is also where you’ll see frameworks such as OWASP NHI Top 10 and Agentic Applications Top 10 converge.
Note that both start with the same prerequisite: an agent that has its own scoped identity. Now, the expectation is threefold:
There are other relevant frameworks in play with AI.
Don’t believe me? Abused non-human identities are now effectively tied with phishing as the leading entry point in confirmed identity incidents. AI agents are the least covered identity type in NHI management programs. It is time for that to change.
Given this data, there are at least four critical capability areas to address with your supply chain. These are the questions to put in front of your vendors as part of your standard decision-making process:
And one filter that cuts across all four: provable, no-lock-in solutions that meet you where you are on the maturity curve.
When they say AI is operating at machine speed, it’s no joke. Which means, you can’t solve everything at once, but you absolutely need to get started. One step at a time. Here are a few immediate actions we recommend.
The maturity curve is a roadmap, not a finish line. Start where you are. The organizations that are furthest along didn’t wait for perfection. Afterall, you eat the [proverbial] elephant one bite at a time.
Start with visibility and ownership, then build governance around what you find.
For more details, we invite you to read the full IDC whitepaper: “Managing Agentic AI Through the Identity Control Plane: What Organizations Should Look For” (September 2026, #US54897326), sponsored by GuidePoint Security.
Director, Offer Marketing
GuidePoint Security
