Pathlock warns of widening AI governance gap in firms
Thu, 30th Jul 2026 (Today)
Pathlock has published research pointing to what it describes as a widening AI governance gap in large organisations. The study found that 23% of respondents had already experienced at least one AI incident that required investigation and remediation.
The findings also suggest broader uncertainty over the use of AI agents in business systems. More than half of organisations surveyed said they were not confident they knew all the AI agents operating in their environments, while 31% were unsure whether any incidents had occurred at all.
Pathlock's report focuses on AI agents used in core business functions such as finance, procurement and human resources. It argues that companies are moving beyond using AI for analysis and summarisation and are instead giving software agents authority to carry out tasks traditionally handled by employees.
Among the organisations surveyed, 38% said AI agents were allowed to create and modify business records, while 28% said agents could approve transactions. Another 35% said AI agents could execute workflows across multiple systems, and 36% said they had embedded or were implementing AI agents in finance and accounting.
The research also highlighted direct access to underlying systems. A quarter of respondents said AI agents were allowed to access backend databases directly, raising the possibility that changes could be made outside the usual checks built into business applications.
Control concerns
The report argues that governance arrangements have not kept pace with the spread of AI agents. It found that 79% of organisations had no dedicated AI governance team or officer, 52% could not verify actions carried out by AI agents across business systems, and 48% could not trace AI activity end to end across systems.
That lack of visibility appears most acute when something goes wrong. Only 13% of respondents said they could investigate a flagged AI-driven action in real time, while 18% said they could complete an investigation within hours. Nearly a quarter said they could not reliably investigate such an incident at all.
The survey was based on responses from 286 IT, compliance and security decision-makers across North America, Asia-Pacific and EMEA. Respondents came from sectors including manufacturing, financial services, technology, healthcare and government.
Pathlock describes AI agents as the fastest-growing category of non-human identities inside organisations. Unlike conventional service accounts, these agents can make contextual decisions and carry out multi-step processes across connected applications.
That distinction matters because the actions described in the report affect financial controls and record integrity, two areas where organisations have typically relied on segregation of duties, approval chains and application-level logic to prevent errors and misconduct.
Chris Radkowski, GRC expert at Pathlock, commented on the shift in governance demands. "Three forces are converging - the explosion of identities, increasingly interconnected business applications, and AI agents that can now execute business processes autonomously at machine speed. Together, they're transforming governance from an IT discipline into a business imperative. As AI agents begin influencing financial outcomes, governance becomes a matter of business risk, financial integrity, and regulatory compliance," Radkowski said.
Investigation gap
The report suggests the challenge is no longer limited to deciding which systems an AI agent can access. It now also involves reconstructing what an agent actually did after access was granted, especially when actions span multiple systems and data sources.
Susan Stapleton, GRC expert at Pathlock, said the issue marked a shift from older access-control models. "For decades, governance focused on controlling who could access a system. AI agents introduce a different challenge: understanding what actually happened after access was granted. The organizations best prepared for AI will be those that can verify, trace, investigate, and explain AI-driven actions in real time across their entire business application landscape, regardless of how many data sources must be correlated to reconstruct the full picture," Stapleton said.
The findings add to a growing debate over how companies should govern autonomous software in operational settings, particularly where systems touch payments, supplier data, employee records and other business-critical information. Pathlock's survey suggests many organisations are already allowing AI agents into those workflows before establishing clear oversight structures.