Est.

Overcoming IT and Security Team Resistance to AI Agent Rollouts

Most AI agents ship before security teams can govern them.

Staff Writer · · 11 min read
Cover illustration for “Overcoming IT and Security Team Resistance to AI Agent Rollouts”
AI Change Management · September 29, 2026 · 11 min read · 2,486 words

AI agents are appearing in production faster than the people responsible for securing them can keep track of mintmcp.com 2026 survey of executives and practitioners. That's the whole story here: deployment speed has outrun governance readiness, and the fix isn't to slow teams down, it's to hand security and IT the tools that let them say yes with confidence.

Why AI agents are already in production before security teams are ready

Per the Gravitee State of AI Agent Security 2026 report, 80.9% of technical teams have already moved past planning and into active testing or full deployment mintmcp.com 2026 survey of executives and practitioners. Only 14.4% of those agents went live with full security and IT sign-off, which means the gap between how fast agents ship and how fast governance catches up is already wide, and it's getting wider.

The average organization is now running 37 deployed AI agents, and that number climbs every quarter as individual teams spin up their own automations without anyone in the middle reviewing them agatsoftware.com techstoriess.com. Per the SAP LeanIX Agentic AI Survey, fewer than half of organizations can even produce a full inventory of the agents they've deployed mintmcp.com. So the count keeps growing, and a large chunk of it stays invisible to the people whose job is to secure it.

When the trend is viewed at a larger scale, it gets sharper, not softer. IDC projects active enterprise AI agents growing from roughly 28 million in 2025 to more than 2 billion by 2030 mintmcp.com. At that pace, the governance gap doesn't close on its own. It widens, unless something structural changes about how agents get identity, oversight, and audit trails baked in from the start mintmcp.com.

None of this means security teams are dragging their feet. It means deployment is happening around them, in parallel, often without the visibility or tooling that would let them do their job.

Why security teams' worries are well-founded

Diagram: The Governance Gap: Agents Deployed vs. Controls in Place. Visualizes: Show the stark contrast between how widely AI agents are deployed and how little governance infrastructure exists underneath them.

A 2026 survey of 235 large-enterprise CISOs and CIOs found that 92% lack full visibility into their AI agent identities, and 95% doubt they could even detect or contain a compromised agent if one turned up, a direct description of a blind spot that most security leaders are aware of mintmcp.com Gartner.

Accountability is just as thin. Only 7.2% of organizations have a named individual formally responsible for how an AI agent behaves. Per the Gravitee survey, only 24.4% of organizations have full visibility into which agents are talking to which other agents, and more than half of deployed agents run with no security oversight or logging at all mintmcp.com. Add to that: 63% of organizations can't enforce any kind of purpose limitation on what their agents are allowed to do, so an agent built for one task can often wander into another mintmcp.com.

KPMG's survey of large enterprises found that 75% of leaders rank security, compliance, and auditability as the most critical requirements before an agent goes live mintmcp.com Gartner BlackBerry, 2024. Yet only 30% of organizations have reached what would count as governance maturity level three or higher on agentic AI controls, so the other 70% are scaling agent deployments on top of a foundation that isn't ready for the weight Adversa AI's 2025 threat report Verizon DBIR, 2025.

Shadow AI makes all of this worse. Per a Gravitee survey, security incidents tied to shadow AI cost an average of $670,000 more than standard incidents, mostly because detection lags and nobody can quickly scope how far the exposure spread mintmcp.com agatsoftware.com Deep Inspect. Security teams have generally done solid work at the model layer, controlling which tools employees can touch, which vendors clear procurement, what data those tools can see. The execution layer, where the tool calls actually happen, is where most of the 2026 attacks are landing, and it's largely ungoverned mintmcp.com.

The MCP attack surface security teams now have to defend against

Tool poisoning is the sharpest example of why. An attacker hides instructions inside a tool's metadata, its name, its description, its schema, and the agent reads that metadata and acts on it. No human ever looks at it closely enough to notice mintmcp.com. Microsoft's Incident Response team documented exactly this pattern in a June 2026 write-up: a developer pushes an update to a third-party enrichment MCP server, the tool name and the summary a user would see stay the same, but the description underneath gets quietly changed to tell the agent to pull unpaid invoices and attach them to an outbound call mintmcp.com. Because nothing visible changed, it never triggered a re-approval workflow mintmcp.com.

EchoLeak (CVE-2025-32711, rated 9.3 on CVSS) stands out as the defining incident of this era: the first known zero-click attack against an AI agent, so no user had to click anything or make a mistake for it to work mintmcp.com techstoriess.com. OX Security's May 2026 disclosure, which researchers called the mother of all AI supply chains, touched more than 200,000 vulnerable server instances across more than 10 named CVEs bundled into a single cluster mintmcp.com. Between December 2025 and January 2026, a single attacker used Claude to breach multiple Mexican government agencies, including the federal tax authority, the electoral institute, four state governments, and a water utility, in a campaign traced back to one improperly secured agent mintmcp.com.

OWASP has already formalized the taxonomy for all of this. Its Top 10 for Agentic Applications, released December 2025, alongside the MCP Top 10 project, now catalogs tool poisoning, schema poisoning, tool shadowing, and command injection as named, recognized categories mintmcp.com. That gives defenders a shared vocabulary, but these categories are documented and not going away. Gartner projects that by 2028, roughly a quarter of enterprise generative AI applications will see five or more minor security incidents a year, and ties that rise directly to MCP-driven exposure mintmcp.com. A security team that can't see when tool metadata changes is blind to where the actual risk sits.

Why the identity and credential layer underneath agents is largely unmanaged

Machine identities have quietly outnumbered human ones by an enormous margin. A Palo Alto Networks survey of almost 3,000 cybersecurity decision-makers found organizations average roughly 109 machine identities for every one human identity, and most of those machines are AI agents mintmcp.com. Identity and access management tooling hasn't caught up to that ratio, not close.

Credentials are the weak point. Per the Gravitee report, 45.6% of technical teams rely on shared API keys for agent-to-agent authentication mintmcp.com agatsoftware.com. Shared keys mean nobody can attribute an action to a specific agent after the fact, and the blast radius of any single compromised key is effectively unbounded. Only 21.9% of teams treat their AI agents as independent, identity-bearing entities with their own scopes and audit trails agatsoftware.com. And 25.5% of deployed agents can create and instruct other agents, which, in a shared-credential environment, builds chains of authority nobody can trace or audit agatsoftware.com Gartner.

The access picture is worse still. Of the 235 CISOs and CIOs surveyed, 86% don't enforce access policies for AI identities at all, and 71% report that AI systems have access to core platforms like ERP, CRM, and financial systems, while only 16% actually govern that access with any rigor. That combination, broad access plus no enforcement, is how a single mistake becomes a catastrophe. In one documented case, a Cursor AI agent scanning a codebase found an API token that had been provisioned for domain management, issued a single GraphQL mutation, and the production database was gone nine seconds later.

Least-privilege gets violated for agents more than it ever does for human employees. Developers routinely grant broad permissions during development and never scope them back down before production. An agent with read and write access to SharePoint, email, and a code repository is one credential compromise away from simultaneous exfiltration across all three. This is not a hypothetical; it is the default shape of a lot of deployments today.

Authorization itself is barely implemented. Only 8.5% of MCP servers actually use OAuth, even though the MCP specification calls for OAuth 2.1 with PKCE on every remote HTTP-based server mintmcp.com Gartner. The NSA's May 2026 cybersecurity guidance says that authorization in MCP is optional in practice and inconsistently applied across the ecosystem mintmcp.com Gartner. The spec says one thing, the deployed reality says another, and that gap is where a lot of the risk lives.

What the governance infrastructure that lets security teams say yes looks like

Visibility comes first, because nobody can govern what they can't see. The foundation, per ITECS's guidance, is an MCP register: every server and every tool mapped to an owner, a version, a data classification, a permission set, an approval rule, and a kill switch mintmcp.com.

From there, every agent needs its own identity, not a shared service account, not a borrowed human credential. For lower-stakes cases, a bearer key per agent with individual revocation covers development and simple integrations. High-security, cloud-native environments go a step further with workload identity federation, where the agent's infrastructure mints short-lived OIDC tokens and no secret ever sits in storage waiting to be stolen.

Permissions need the same granularity. Reading a record, updating a field, exporting data, approving a transaction, and deleting information are five separate permissions, not one blanket grant, and access should be scoped to exactly the dataset or record the task requires mintmcp.com Gartner. One useful abstraction here is Virtual MCP, which bundles approved connectors and a curated set of tools behind a single governed endpoint for a given team, role, or use case, with SCIM-driven groups deciding who gets what mintmcp.com. That turns governance into one control plane instead of a pile of individually managed tools and vendors mintmcp.com.

Monitoring alone isn't containment. Per one industry playbook, 58% of organizations have continuous monitoring and 59% have a human in the loop, but only 37% have purpose binding and only 40% have a working kill switch mintmcp.com agatsoftware.com techstoriess.com. Closing that gap means building controls that block an unsafe action before it runs, not ones that just raise an alert after the damage is done mintmcp.com agatsoftware.com techstoriess.com. Tool description changes deserve the same treatment as any other security-relevant config change: per ITECS's guidance, a server upgrade or a change to a tool's listed capabilities should trigger a re-approval workflow, full stop mintmcp.com. The Microsoft Incident Response case is the clearest illustration of what happens when that step gets skipped mintmcp.com.

Audit logging has to go deeper than prompt and response. Real forensics needs the server's identity, the tool definition's version, the caller, the user, the scopes granted, the arguments passed, the result, and the approval record, all captured together mintmcp.com. Right now, a third of organizations still lack audit trails good enough to hold up as evidence, which is both a compliance exposure and a forensics dead end when something does go wrong mintmcp.com. M2M tokens use OAuth client-credentials exchange for short-lived tokens, which is appropriate for production agents.

How the enterprise security vendor ecosystem has responded

The big vendors have noticed. Microsoft launched Agent 365. Cisco rolled out Zero Trust Access built for agents. Google updated its Security Operations product line. Okta launched Okta for AI Agents. Check Point introduced what it calls an AI Defense Plane. Palo Alto Networks advanced Prisma AIRS to version 3.0. Cisco had already expanded its AI Defense product back in February 2026 specifically to add runtime protection against tool abuse and supply chain manipulation at the MCP layer mintmcp.com.

A broader industry roundup published September 14, 2026, evaluated more than 45 solutions across certification status, performance benchmarks, integration depth, and real deployment evidence. Among the tools it flagged for MCP gateway and agent governance work: TrueFoundry's MCP Gateway for centralized governance, Peta's Agent Vault for credential and secrets management, IBM's ContextForge as an open-source option for teams that want full control over their own infrastructure, Traefik Hub's MCP Gateway with API-layer controls, Microsoft's Azure MCP tooling built into the Azure and Copilot ecosystem, and Bifrost for access controls at the gateway level. On the runtime and detection side, the roundup pointed to Operant AI's MCP Gateway for runtime governance, Prophet Security for autonomous SOC investigation, Check Point's Infinity AI platform, Lasso Security's agent security layer, Palo Alto Networks' Prisma AIRS at version 3.0, Stellar Cyber's Open XDR for AI environments, Darktrace's autonomous detection work extended to agent behavior, and CrowdStrike's Falcon Charlotte AI for AI-native SOC operations mintmcp.com.

For the OAuth authorization layer specifically, WorkOS, Stytch, and Auth0 by Okta all function as MCP-compatible authorization servers, and they differ mainly in enterprise identity depth, deployment flexibility, and how well they fit into an existing stack. Stitching together a separate agent builder, a separate gateway, and a separate security tool means rebuilding the same integration plumbing every time a new team wants to deploy.

Even with all that vendor activity, gaps remain. Governance at the connection layer is getting real attention now, but the skill and tool surface, the actual code an agent calls, still isn't reviewed consistently anywhere across the ecosystem, as reflected in security scans of 3,984 agent skills finding that 36.82% of them contained a security flaw mintmcp.com Beam AI survey. At RSA Conference 2026, every Tier-1 enterprise security vendor confirmed the problem and shipped a governance or detection response. MintMCP provides enterprise MCP and agent governance infrastructure, centralizing connectors, authentication, credentials, tool curation, access policies, and audit through governed endpoints, with its Agent Gateway giving autonomous agents first-class non-human identities, scoped permissions, and per-agent audit attribution, alongside runtime controls via Mint Guard and declarative rules.

How security and IT teams become the engine of adoption rather than the brake

Right now, 79% of organizations are actively evaluating or deploying agentic AI, but only 21.9% treat their agents as first-class security principals with real identity and audit ownership mintmcp.com agatsoftware.com. Most deployments are simply outrunning the governance that would make them last.

When that dynamic is flipped, the security team's role changes completely. Once a team owns the MCP register, the agent identity model, the credential rotation policy, and the audit trail, they stop being a checkpoint that slows things down and start being the infrastructure that makes every other team's agent deployment something people can actually trust and defend later. That's a description of what changes operationally once governance exists as a system rather than a set of ad hoc reviews.

A governed MCP gateway, stocked with pre-approved connectors and a curated set of tools, plus SCIM-driven access rules, lets a non-technical team deploy an agent without hand-configuring every MCP server themselves. Security's governance work becomes the paved road, not the roadblock. Business stakeholders are asking security to build the thing that lets everyone else move. KPMG's finding is the institutional mandate: 75% of large-enterprise leaders say security, compliance, and auditability are the most critical requirements for agent deployment, as business stakeholders want security teams at the table, not sidelined.

Sources

  1. MCP Tool Poisoning: Enterprise Controls for AI Agent Integrations | ITECS
  2. Securing AI agents: When AI tools move from reading to acting | Microsoft Security Blog
  3. Why AI Agent Security Is a Vital Enterprise Priority Today - AGAT Software
  4. AI Agent Security Practices 2026: Prompt Injection, MCP Risks & Data Leaks - TechStoriess.com
  5. AI Agent Security Risks in 2026: A Practitioner's Guide
  6. workos.com

More in AI Change Management