Right now, inside a mid-sized financial services company somewhere, an AI agent is pulling a customer's account history from three internal systems and deciding what happens next. There's a decent chance nobody is watching it happen in real time.
That's not a hypothetical. It's the working baseline described in Gravitee's State of AI Agent Security 2026 report, and it's the clearest picture yet of a gap that's opened up faster than most companies have noticed.
The number that matters: the average enterprise AI agent fleet roughly doubled between December 2025 and April 2026. Monitoring coverage over that same window barely moved.
The Fleet Doubled. The Oversight Didn't.
Gravitee surveyed 750 senior technology leaders across the UK and US in two waves, December 2025 and April 2026. Two numbers from that survey tell the whole story on their own:
- The average enterprise's AI agent fleet roughly doubled in just four months
- Monitoring coverage over that same period barely moved
That gap shows up in the incident data too:
- 54% of organizations have experienced or suspected an AI agent security or data privacy incident in the past year
- 67.3% of telecom companies report incidents, the highest of any sector
- 54.7% of financial services companies report the same
Cross-referencing more than 200 open-text survey responses across both waves, Gravitee's researchers identified six failure patterns showing up again and again:
- Excessive permissions - the most consistently reported failure across both waves. Agents deployed with access well beyond what their task requires, often inherited from a shared service account instead of a scoped one
- Data retention and privacy violations - agents holding onto or exposing sensitive information longer than the task ever needed
- Prompt injection and adversarial manipulation - inputs specifically crafted to hijack an agent's instructions
- Shadow AI - agents deployed by individual teams entirely outside IT's knowledge or governance
- Third-party vendor opacity - not knowing what an embedded AI feature inside a purchased tool actually has access to, or how it was evaluated before shipping
- Confidently wrong outputs - the newest pattern to emerge, and the hardest to catch: not an obviously broken response, but a plausible, well-formatted, wrong one that goes on to shape a real financial, clinical, or compliance decision
One more detail worth sitting with: confirmed incident rates actually dropped between the two survey waves, from 59.3% down to 34.9%. The report's read isn't that security genuinely improved while the agent fleet doubled and monitoring stayed flat, it's that more incidents are simply going undetected, not fewer are happening.
Confidence Is Rising Faster Than Verification
A separate June 2026 survey of enterprise leaders, run by VentureBeat's VB Pulse, found something almost paradoxical:
- Half of enterprises have deployed an AI agent or LLM feature that passed their own internal evaluations and still went on to cause a customer-facing failure, one in four of those companies more than once
- 66% already allow some production deployment without human review, or are actively building toward that within the next 12 months
- Only 5% say they fully trust the automated evaluations meant to justify that decision
- Larger enterprises (2,500+ employees) are adopting zero-human-review deployment faster, not more cautiously, at 70% versus 64% for smaller companies, despite also reporting more customer-facing failures once they do
Why does confidence keep outrunning verification?
Researchers studying human oversight point to a specific mechanism: automation complacency. The more reliable a system appears to be, the less vigilant the humans watching it become, until the oversight exists on paper without actually functioning day to day. It's the same failure pattern documented in aviation and industrial safety literature for decades, just showing up now in a much newer context.
How Far Autonomy Has Actually Come
Not every "AI agent" means the same thing, and that ambiguity is part of why the trust gap is so hard to close. Researchers tracking the field describe autonomy as a ladder, and most enterprise deployments today are sitting on the first two rungs, not the top ones headlines tend to imply:
| Stage | What it actually does | Where it stands in 2026 |
|---|---|---|
| Task execution | Carries out a specific task using tool access, one job at a time | Today's frontier for most production deployments |
| Plan, execute, adapt | Handles a multi-step workflow, consulting a human at defined decision points |
That gap between where the technology actually is and where the marketing language implies it is matters. A company confident it's operating at "plan, execute, adapt" while its actual controls were only ever built for simple task execution is exactly the kind of mismatch that shows up later as an incident report.
The Regulation Caught Up Two Days Ago
This isn't only a research finding anymore, it's now a legal one in a major market. The EU AI Act's Article 14, which mandates demonstrable human oversight capabilities for high-risk AI systems, became enforceable on August 2, 2026.
In the US, similar pressure is building through existing frameworks:
- NIST's AI Risk Management Framework and its more recent IR 8596 guidance both call for structured human-in-the-loop checks
- The CFPB already requires explainability for AI-driven credit decisions under existing law
The common thread across all of it: regulators are no longer satisfied with a human being loosely "available" somewhere in the process. What they're actually asking companies to demonstrate is three specific things, together, not just one:
- Context - the human reviewing a decision has the information they'd actually need to catch a problem
- Authority - that person can genuinely override or stop the agent, not just watch it
- Rationale - there's a documented reason for the decision that was made, or the decision not to intervene
Miss any one of the three, and "human in the loop" becomes a phrase on a compliance slide rather than something that functions under real pressure.
The trust gap in five numbers:
| Metric | Figure |
|---|---|
| Agent fleet growth, Dec 2025 to Apr 2026 | ~2x |
| Organizations with a suspected agent incident in 12 months | 54% |
| Enterprises moving toward zero-human review | 66% |
What Real Oversight Actually Looks Like
That last point is where most companies are quietly failing, according to researchers at Strata who study agentic identity and oversight design.
Their core observation:
Most organizations confuse presence with practice. They assign someone to be "in the loop" without ever training that person on what to approve, when to escalate, or how to recognize the early signs of automation complacency in themselves. A named reviewer on an org chart isn't the same thing as a reviewer who's actually equipped to catch a bad decision under time pressure, any more than a pilot is ready for an emergency because they technically sat in the cockpit once.
The practical fix isn't more approval steps everywhere, it's calibrated risk tiers:
- Low-stakes actions (drafting an internal summary, categorizing an incoming document) can reasonably run with minimal oversight
- Financial transactions, customer-facing communications, code deployment, and anything touching access control or data deletion need real friction: consistency checks, rollback paths, and a human escalation point that's actually been rehearsed
The org-chart mismatch:
McKinsey's research on what it calls "the agentic organization" found that 100% of surveyed companies now have agentic AI somewhere on their 2026 roadmap, while 89% are still running on the same industrial-age org structures built for a world without autonomous software making decisions. Only 1% have moved to the kind of decentralized structure the researchers argue agentic AI actually requires.
That mismatch, cutting-edge technology bolted onto organizational structures never designed to govern it, is arguably the real story underneath every statistic in this piece.
A schematic version of this same idea, the autonomy ladder with the two lower rungs lit and the upper two dimmed, is rendered directly above as an illustrative diagram.
The Bottom Line
Nobody serious is arguing AI agents should be pulled back to zero autonomy. The productivity case for delegating routine decisions is real, and it's why adoption is accelerating so fast in the first place.
The actual argument is narrower and harder to ignore: autonomy that outpaces verifiable oversight isn't a productivity story, it's a liability sitting quietly on the balance sheet until the first bad decision surfaces it.
- The organizations treating "human in the loop" as trained, practiced, and tiered by risk are building something durable
- The ones treating it as a checkbox are the ones the next incident report will be about