RSAC 2026 Proved the Industry Agrees on the Problem — Now Comes the Hard Part
100% of organizations have agentic AI on their roadmap, but 63% can't enforce purpose limits on them.
RSAC 2026 revealed a rare industry consensus: securing AI agents is the paramount challenge. Major players like Cisco, CrowdStrike, and Palo Alto Networks all announced new capabilities focused on agent discovery and policy enforcement, with Nvidia even introducing infrastructure-level constraints via its OpenShell runtime. This unified front confirms the findings of the Kiteworks 2026 Data Security Report, which found that 100% of surveyed organizations have agentic AI on their roadmap. The industry has successfully diagnosed the problem.
Yet, a dangerous implementation gap persists. The same Kiteworks report shows that while discovery tools are proliferating, critical containment controls are missing. A staggering 63% of organizations cannot enforce purpose limitations on their AI agents, 60% cannot terminate a misbehaving agent, and 55% cannot isolate AI systems from their networks. This creates a 15-20 point gap between governance (monitoring) and containment (stopping). Furthermore, 33% of organizations lack evidence-quality audit trails, complicating compliance with regulations like HIPAA and PCI. The conversation has shifted from 'if' agents are a risk to 'how' to govern their actions on sensitive data without building a separate stack for every AI platform.
- 100% of organizations surveyed have agentic AI initiatives, driving a wave of vendor tools for agent discovery and monitoring.
- A critical 15-20 point governance gap exists: 63% of orgs can't limit agent purpose and 60% lack kill switches, despite 33% planning autonomous workflows.
- Compliance is a major hurdle, with 33% lacking audit trails and 61% having fragmented logs, making it hard to prove regulated data is handled properly.
Why It Matters
As autonomous AI agents handle sensitive data, the lack of enforceable controls creates massive compliance and operational risk for enterprises.