AI Agent Adoption Outpaces Security Governance in Software Engineering
A new report reveals a dangerous gap between engineering teams' confidence in AI agents and their actual resilience against security events.
Engineering teams are deploying agentic AI into production at a pace that far exceeds their ability to secure it. A research report from Harness reveals a systemic disconnect between perceived safety and actual resilience, leaving many enterprises vulnerable to production failures and security breaches.
The data shows a stark reality: 87% of engineering teams experienced an agent-related security event over the last year. Despite this, overconfidence remains rampant. While 75% of respondents believe their agents are secure "end to end," that specific group suffered security incidents at a rate of 88%—nearly identical to the general population. This lack of alignment between perception and reality is compounded by a rise in instability, with 58% of teams reporting an increase in production-related incidents since deploying agents.
The Governance Gap
This trend mirrors the early eras of cloud and mobile development, where the rush to adopt new technology outpaced the creation of necessary governance frameworks. However, AI agents introduce a unique variable: non-deterministic behavior. Keith Mann, Field CTO and Head of Research at Harness, notes that a control working during testing can still fail in production because an agent does not behave the same way every time.
This variability has left teams without the necessary safety nets. Only 19% of teams have implemented a "gate" to prevent production-impacting failures, even though 74% of respondents believe such failures could be caught through testing. Similarly, only about one-third of teams possess a "kill switch" to rapidly shut down a misbehaving agent, despite 76% of teams believing they could disable an agent in under 15 minutes.
Why It Matters
For the software industry, this gap creates a high-risk environment where overconfidence masks critical vulnerabilities. When engineers believe a system is secure without having the tools to verify that security or stop a failure in real-time, the potential for catastrophic production outages increases. As enterprises scale these agentic workflows, the absence of rapid-response mechanisms means that a single errant agent could cause widespread damage before a human can intervene.
What's Next
Industry leaders are now facing a period of retrospective correction. Trevor Stuart, SVP and General Manager at Harness, observes that teams who moved quickly to release agents are now "circling back" to determine how to govern systems already in the wild. The focus is expected to shift toward implementing rigorous verification tools and mandatory deployment gates to bridge the gap between confidence and actual security. For now, Harness Research concludes that confidence in agent security has almost no relationship to actual resilience.