Is anyone's security policy actually ready for AI agents, or are we all just pretending?
Employees everywhere are quietly using AI agents that browse, write code, and move data on their behalf. Most of them never asked IT.
Meanwhile, most security policies still read like it is 2023. Humans using tools. Nothing about semi-autonomous agents acting on someone's behalf.
Gartner just named agentic AI oversight the top cybersecurity trend for 2026. The advice is to inventory every agent, sanctioned or not, and govern each one. Sounds great on paper.
So, honest question. Has your org actually updated its policies for this? Or is everyone just hoping nothing breaks before the next audit?