Tool · AI governance

Can you name every agent running in your company?

A CTO told us this: “My CFO created a mini agent, it sorta works. My HR person created another mini agent. I have twenty of those running around.” Nine questions below. Five carry a published benchmark, four have none.

The agent inventory check is nine questions about the AI agents already running in your company. Five carry a benchmark from a survey of 445 practitioners. Four have no published figure anywhere, and those are the ones a review board asks. You answer in the page and nothing is stored.

Where the published numbers come from

One survey: Cloud Security Alliance, Enterprise AI Security Starts with AI Agents. 445 practitioners, fieldwork September and November 2025, commissioned by Zenity.

  • The figures answer different survey questions, so this page never combines them into a score.
  • Three are the share who could answer yes, worked out by subtraction. Marked, because they are our arithmetic and not a number the survey printed.

9 questions

1. Can you list every AI agent running in your company right now?

54% are running between 1 and 100 agents nobody sanctioned.

2. Does every agent have a named owner?

15% can say who owns most of their agents.

3. Have your agents stayed within the permissions you intended?

53% have had an AI agent exceed its intended permissions.

4. Have you gone the past 12 months without a security incident involving an agent?

47% had a security incident involving an AI agent in the past year.

5. Are you prepared for the AI regulation that applies to you?

13% describe themselves as highly prepared.

6. For each agent, can you say which systems it is allowed to write to?

No published benchmark. Nobody has surveyed this.

7. If an agent acted outside its scope today, would somebody notice the same day?

No published benchmark. Nobody has surveyed this.

8. Is the person who signed off on an agent’s output independent of the person who built it?

No published benchmark. Nobody has surveyed this.

9. If a customer or a regulator challenged one agent decision, could you show the reasoning behind it?

No published benchmark. Nobody has surveyed this.

Nothing is stored and nothing is sent. Cloud Security Alliance, Enterprise AI Security Starts with AI Agents. 445 practitioners, fieldwork September and November 2025. Commissioned by Zenity.

Why some of these carry no number

We looked for survey data on agent validation and audit readiness and found none. Questions 6 to 9 are the ones a review board asks, and there is no benchmark to sit them against. That is the gap.

When this check will not help you

Anyone with nothing in production. These questions grade agents that are running. If the work is still a demo, there is nothing to inventory.

Does this check store my answers?

No. The nine answers stay in your browser, and in the page address if you choose to copy the link. Nothing is written to a server and Perform receives none of it.

Copy my results gives you the nine answers with the published figure beside each one and a link back to this exact result. Share the tool gives a clean link with none of your answers in it.

What counts as a gap?

A no and a not sure both count. A review board treats a question you cannot answer the same way it treats a negative answer, because neither one gives it anything to rely on.

QuestionsNine
With a published benchmarkFive
With no benchmark anywhereFour
Where it runsIn your browser
What reaches PerformNothing
Benchmark sourceCloud Security Alliance, Enterprise AI Security Starts with AI Agents. 445 practitioners, fieldwork September and November 2025.
Start with a conversation

Bring the list you could not finish.