AI Agents Are Entering Production. Governance Isn't Keeping Up.
Published: July 2026
The biggest shift in enterprise software this year isn't a new model. It's AI agents shipping as features inside tools your teams already use. Atlassian now embeds Rovo agents in Jira: they can be assigned work items, mentioned in comments, and wired into workflows like any teammate. Other vendors are following the same pattern.
Most AI governance programs were built to track projects — systems somebody deliberately proposed, funded, and built. Agents don't arrive that way. They arrive in a product update. If your governance process starts with an intake form, it never sees them.
Agents are arriving as features, not projects
Gartner projects that roughly 40% of enterprise applications will include embedded AI agents by the end of 2026, up from under 5% in 2025. That growth is not happening through procurement reviews. It happens when a vendor flips a switch.
Jira is the concrete example. In 2026, Atlassian shipped agents that take assignments, respond when mentioned in comments, and run inside workflows. A team that enables one has, in practice, deployed an AI system that reads project data and takes actions — without anyone filing a request with the governance team.
Multiply that across your SaaS stack and the question stops being "should we adopt agents?" It becomes "how many are we already running, and who is accountable for each one?" Picture a hypothetical but familiar scene: a compliance lead asks engineering how many AI agents can touch customer data. Nobody can answer — because nobody has counted.
An audit log is not portfolio governance
When agent features ship, vendors point to per-action audit logs — and logs do matter. But a log answers a forensic question: what did this agent do, on which item, at what time? Governance answers a portfolio question: how many agents do we run across all our tools, which are high-risk, who owns each one, and when was each last reviewed?
The difference shows up the first time leadership asks about exposure. Suppose your board asks: "how many agents can modify customer-facing records, and who signed off on each?" A stack of activity logs from six vendors does not answer that. An inventory with owners and risk bands answers it in one page.
Logs are evidence for incidents. Registers are evidence for accountability. You need both — and most organizations currently have only the first.
The new risk surface: autonomy, tool access, delegation
Agents differ from the AI systems most registers were designed around in three ways, and each changes how you score risk:
- Autonomy. A copilot suggests; a human commits. An agent acts — closes the ticket, updates the field, triggers the workflow — without per-step approval. Errors compound before anyone looks.
- Tool access. An agent's blast radius is its permission set, not its model quality. An agent with write access to production workflows is a different risk class from one that only summarizes, even on the same underlying model.
- Delegation. Work gets assigned to agents, agents trigger automations, automations invoke other agents. When something goes wrong three hops in, "who is accountable?" has no obvious answer unless you decided it in advance.
Where the agent runs matters too. Atlassian's Forge platform, for example, runs its LLMs inside Atlassian's environment with no data egress — a materially different data-exposure profile from an agent that sends your content to a third-party API. Risk scoring should capture that distinction, not flatten it.
Gartner's other number — and the regulators
The adoption projection has a companion warning: Gartner has cautioned that over 40% of agentic AI projects may be cancelled by 2027, citing cost, unclear business value, and weak risk controls. Two of those are business problems. The third — weak risk controls — is the one a governance program directly fixes, and it tends to kill projects late, after real money is spent.
Regulation is moving in parallel. The Council of the EU gave final approval to the AI Act simplification package on 29 June 2026; high-risk obligations are now deferred to 2 December 2027 for standalone systems and 2 August 2028 for AI embedded in products, while obligations for general-purpose AI models have applied since August 2025. In the US, the Colorado AI Act took effect on 30 June 2026, with duties around algorithmic discrimination, risk-management programs, and impact assessments. The deferral buys time to build an inventory — it is not permission to skip one. If your agents touch decisions about people, the EU AI Act's risk classes are the map to start with.
Govern agents like any other AI system
The good news: you don't need a new discipline. Agents are AI systems. The same four moves that govern a model govern an agent:
- Inventory them. Agents leave traces where work happens — assignments, comments, automation rules, labels in Jira or Azure DevOps. Start from a project export, not from a survey nobody answers.
- Score the risk. Rate autonomy level, permission scope, and the data classes each agent touches. A standard AI risk register handles agents fine — note autonomy and tool access in the description and score accordingly.
- Assign a named owner. A person, not a team. The delegation chains above are exactly why: someone must be answerable before the incident, not after.
- Set review dates. Agents change when vendors update them. A register without review dates is a snapshot, and agents make snapshots stale faster than any other AI system.
This maps cleanly onto the NIST AI RMF's four functions — Govern, Map, Measure, Manage — and onto ISO/IEC 42001's expectation of a managed AI-system inventory. If you already run NIST AI RMF mapping on your project data, agents slot into the same structure.
Where to start this week
You can do the first pass with data you already have:
- Export the projects where agents operate — Jira, Azure DevOps, or any tracker via CSV.
- Run AI-system discovery on the export: agent activity, AI features, and AI-related work items surface together.
- Review the risk-scored register, assign owners, set review dates.
- Generate a board-ready governance report so leadership sees the portfolio, not the logs.
Jira teams can run the whole loop inside their own tenant with the AI Governance Hub app for Jira Cloud — built on Forge, with no data egress (details in our Trust Center). One clarification we always make: the output is governance evidence and executive analysis to support your review and readiness — not legal certification or compliance advice.
Frequently asked
What is AI agent governance? Treating every agent as an inventoried AI system: a register entry with a risk score, a named owner, and a review date — on top of, not instead of, the vendor's activity logs.
Is an agent's audit log enough for frameworks like ISO 42001 or the NIST AI RMF? No. Logs evidence individual actions, while these frameworks expect an organization-level inventory, risk treatment, and accountable ownership across all AI systems, agents included.
How do I find the AI agents already running in my tools? Start from project exports — agents leave traces in assignments, comments, and automation rules in tools like Jira and Azure DevOps, and discovery tooling can flag them automatically.
See what a governed agent portfolio looks like on your own data: upload a Jira, Azure DevOps, or CSV export and get a free governance preview — AI discovery, a risk-scored register, and a governance score — no credit card required. Start your free preview, with founding pricing from ₹199 when you want the full board-ready report.