48% of Your AI Agents Are Running Unmonitored — The Governance Gap Nobody Owns

48% of Your AI Agents Are Running Unmonitored — The Governance Gap Nobody Owns

Nearly half of deployed AI agents run without oversight, and almost no one owns the problem. Here's why agent governance is the next managed service line, plus a self-assessment SMEs can use today.

Tony Brown
By Tony Brown ·

A finance team at a Midlands wholesaler asked an AI agent to reconcile supplier invoices last spring. It did the job well for weeks. Then one supplier changed its bank details in an email, the agent updated the payment record without flagging it, and £14,000 went to a fraudster. No human saw the change until the real supplier chased for payment. When the directors asked who was supposed to be watching the agent, the answer was silence. IT thought finance owned it. Finance thought IT owned it. Nobody did.

That gap — the space between deploying an agent and actually governing it — has become one of the most expensive blind spots in UK business. And the numbers from September 2026 make it hard to look away.

A dimly lit operations room with monitoring dashboards showing system activity

The data nobody wants to read

Across organisations now running AI agents in production, only 9.5% secure more than 81% of the agents they've deployed. Read that again. Fewer than one in ten businesses can say most of their agents are properly monitored, permissioned and logged. The rest have agents making decisions, moving data and triggering actions with little or no oversight.

The average sits at roughly 48% of agents running unmonitored — nearly half. These aren't chatbots answering FAQs. They're agents with access to email, CRM records, payment systems, code repositories and internal documents. They act on their own. They chain tasks together. And in most companies, no one is checking what they do between the moment they're switched on and the moment something goes wrong.

The governance side is worse. Just 7.2% of organisations have named, formal accountability for their AI agents — a person or role who owns the risk, the review process and the shutdown authority. For everyone else, it's the finance-and-IT standoff from that wholesaler story, repeated at scale.

This is what happens when a technology arrives faster than the habits needed to manage it. Agents got easy to deploy long before anyone worked out who should be responsible for them.

Why this happened so quickly

A few years ago, adding an AI capability meant a project. Budget, sign-off, a vendor, a rollout plan. That friction created natural checkpoints. Someone had to think about security and ownership because the process forced them to.

Agents removed the friction. A team lead can now stand up an agent from a SaaS tool in an afternoon, connect it to a mailbox or a spreadsheet, and have it working before lunch. Marketing has one drafting campaigns. Sales has one qualifying leads. Ops has one triaging tickets. Each is useful. Each was set up in isolation. And none went through anything resembling a review.

The result is sprawl. Most SMEs we speak to genuinely don't know how many agents are running inside their business, let alone what those agents can touch. When we run a discovery, the count is almost always higher than the client expected — and a chunk of them belong to people who've since left the company.

That's the real risk. Not the headline-grabbing rogue AI, but the quiet, forgotten agent with live credentials, an inbox connection and no one watching it.

The governance gap is a service, not a policy document

Here's where most advice falls flat. The standard response to a governance gap is to write a policy. Circulate a PDF, tick a box, move on. But agents don't read policies. They act, constantly, in real time. Governing them needs the same thing you'd apply to any part of your live infrastructure: discovery, monitoring, permissions, logging, alerting and a clear owner.

That sounds a lot like managed IT — because it is. This is why we think agent governance is naturally an MSP responsibility, not another internal job nobody has time for. The tools, the monitoring discipline and the round-the-clock attention already exist in a well-run managed service. Pointing them at agents is a logical extension, not a reinvention.

We've started calling it governance-as-a-service, and in practice it covers five things:

  • Discovery and inventory. Find every agent running across the business, what it connects to, and who created it. You can't govern what you can't see.
  • Permission scoping. Cut each agent's access down to only what it needs. That invoice agent shouldn't be able to change bank details without a human check.
  • Continuous monitoring. Watch what agents actually do, not what they were supposed to do. Flag anomalies the way you'd flag a suspicious login.
  • Audit logging. Keep a record of every action, so when something goes wrong you can answer 'what happened and when' in minutes, not weeks.
  • Named accountability. Assign a clear owner and an escalation path, even if that owner is your MSP working to your rules.

None of this is exotic. It's the same operational hygiene you already expect for servers, laptops and networks, applied to a category of software that behaves more autonomously than anything before it.

A governance-maturity self-assessment you can run this week

Before you buy anything from anyone — us included — find out where you stand. Answer these honestly.

  1. Can you list every AI agent running in your business right now? If the answer is 'roughly' or 'no', you're already in the 48%.
  2. Do you know what data and systems each agent can access? Not what it's meant to touch — what it can touch.
  3. Is anyone monitoring agent activity as it happens? A dashboard someone checks monthly doesn't count.
  4. If an agent did something harmful today, would you know within an hour? Or would you find out when a customer or supplier told you?
  5. Is there a named person accountable for agent risk? Someone with the authority to switch one off.
  6. Do agents belonging to former employees still have live access? Check. It's usually a yes.

Score a point for each clear, confident 'yes'.

  • 5–6: You're in rare company. Focus on keeping it tight as you scale.
  • 3–4: You've made a start but have real exposure. Prioritise monitoring and offboarding.
  • 0–2: You're where most SMEs are. This is urgent, not aspirational.

Most businesses land at 0–2 and are surprised by it, because individual agents felt harmless when they were set up. The risk lives in the aggregate.

Getting ahead of it

The firms that come out of this well won't be the ones with the most agents or the fanciest tools. They'll be the ones who decided, early, that autonomous software deserves the same oversight as everything else that touches their money and their customers.

If your self-assessment score worried you, that's a useful outcome — it means you now know something you didn't yesterday. The next step is a discovery exercise to see exactly what's running and where the exposure sits. We can run that for you, or point you at the right questions to run it yourself.

Either way, don't let the answer to 'who owns the agents?' stay silence. That silence has already cost businesses more than they'd like to admit.

Request a no obligation callback