Tool · AI governance
Can you name every agent running in your company?
A CTO told us this: “My CFO created a mini agent, it sorta works. My HR person created another mini agent. I have twenty of those running around.” 9 questions below. On five, your answer sits next to what 445 practitioners told the Cloud Security Alliance. On the other four, no public number exists.
Where the published numbers come from
Every benchmark on this page is from one survey: the Cloud Security Alliance State of AI and Security Survey, April 2026, 445 practitioners, sponsored by Zenity. Each figure answers a different question in that survey, so they do not add up to a single score and this page does not build one.
9 questions
54% are running between 1 and 100 agents nobody sanctioned.
15% can say who owns most of their agents.
53% have had an AI agent exceed its intended permissions.
47% had a security incident involving an AI agent in the past year.
13% describe themselves as highly prepared.
No published benchmark. Nobody has surveyed this.
No published benchmark. Nobody has surveyed this.
No published benchmark. Nobody has surveyed this.
No published benchmark. Nobody has surveyed this.
Nothing is stored and nothing is sent. Cloud Security Alliance, State of AI and Security Survey, April 2026. 445 practitioners. Sponsored by Zenity.
Why some of these carry no number
We looked for survey data on agent validation and audit readiness and found none. The closest public proxies are the 13% who describe themselves as highly prepared for AI regulation and the 15% who can name an owner for most of their agents.
Questions 6 to 9 are the ones a review board asks. There is no benchmark to sit them against. That is the gap.
When this check will not help you
Anyone with nothing in production. These questions grade agents that are running. If the work is still a demo, there is nothing to inventory.
Bring the list you could not finish.