A Vendor Just Launched AI Agent Governance and Disclosed, in the Same Document, That Two-Thirds of Enterprises Have No Standards Governing How Agents Access Their Data

Posted on August 15, 2026

0


A governed surface is not the same thing as a governed estate.

First of two. The follow-up asks whether an AI repatriation is coming, and why it will be harder than the cloud version was.


On 14 August, Box announced Agent Security and Governance — a suite covering prompt injection detection, agent guardrails, activity oversight, and audit trails with session governance. All enforced at the content layer, applying to agents running inside Box and to agents connecting from Claude, ChatGPT, Copilot and Gemini through their MCP server.

I want to say something positive about it first, because it is warranted and because the point I am going to make does not depend on the product being weak.

Classification-based access control at the content layer is the best answer anyone in this category has shipped.

Most AI governance products constrain the agent’s behaviour — what it may do, what it may not do, what patterns to block. Box constrains the material instead. A file classified Confidential can be made unreachable to an agent regardless of which agent asks, how the request is phrased, or whether the user running it could open that file manually.

That distinction matters. A rule about behaviour has to anticipate the behaviour. A rule about the material does not.


Then read the fourth paragraph from the end

In the same announcement, promoting a webinar:

Only 39% of organizations report comprehensive visibility across sanctioned and unsanctioned AI use, and only 34% have standards governing how agents access company data.

Those are Box’s numbers, in Box’s launch material, which means they are the favourable framing of a market they are selling into.

Six in ten organizations lack comprehensive visibility across sanctioned and unsanctioned AI use. Two-thirds have no standards governing how agents access company data.

Read those precisely, because the precise version is the stronger one. The 39% is a share of organizations reporting comprehensive visibility. It is not a measure of how much agent activity is sanctioned versus unsanctioned — nobody has that number, which is rather the point.

What it establishes is this: on Box’s own numbers, most enterprises cannot establish how much of what is actually running lies outside the sanctioned path.

That is more unsettling than a proportion would be, because the unknown is the point.

And the suite governs content that lives in Box.

I am not making a point about Box specifically. A content-layer product necessarily governs the content and agent interactions visible at that layer. Other products monitor other layers — network telemetry, endpoint, browser, API gateways, identity. None of them should be assumed to deliver complete visibility without evidence that they do, and on these numbers most organizations do not have that evidence.


What is on the other side of that boundary

An employee builds something in a low-code tool. It reads a spreadsheet that never touched the content platform, calls an API, writes to a system of record. Nobody registered it. No admin configured it. It does not appear in any inventory because no inventory reaches it.

This is not hypothetical and it is not new behaviour. It is the same thing that produced shadow spreadsheets — and before that, off-contract purchasing.

The precedent worth studying is maverick spend. When front-line buyers went around the sanctioned catalogue, the standard reading was non-compliance. It was not. They were getting the job done under incentives that made compliance costly, and the workaround was the rational move.

Two things made maverick spend manageable anyway. It left evidence — a purchase order, an invoice, a payment, all countable. And it had friction — you needed a supplier, a price, an approval to route around.

A shadow agent has neither. It leaves nothing in the spend record, and building one requires a login and an afternoon.

The bypass got cheaper while the detection got harder.


The line in the announcement that should have been the headline

Buried in a section on access governance, Box’s own VP of Product Management for Security and Compliance recounts internal incidents at two frontier AI labs in which containment failed at gaps the evaluation environment had not anticipated. I am relaying Box’s account of those incidents rather than independently verifying them; the underlying disclosures are the labs’ own to confirm.

His phrasing:

Every layer of containment held right up until it did not, at the one gap none of the humans had thought to check.

That is the most honest sentence in the document and it is the limit of every control written before deployment.

A guardrail is a rule about a failure you can conceive. You cannot write the rule for a failure your model gives you no reason to imagine.

There are three places to get one, and each has a problem.

  • Your own model of the operation. The same model the agent reasons from — so it bounds the failures you had already anticipated, which are the ones you would have caught anyway.
  • Other organizations’ failures. Industry frameworks, regulatory requirements, vendor defaults. Generic by construction, protecting against what happened somewhere else.
  • Observed failures in your own deployment. The only source matched to your actual conditions — and it requires the failure to have happened first.

The industry has quietly resolved this by treating pre-deployment guardrails as the primary control. They are a starting position that will be wrong in ways nobody can enumerate in advance. And on Box’s account, two frontier AI labs — with the deepest expertise available anywhere on this — encountered it in their own infrastructure.


The failure mode this creates

Session governance produces exactly the artifact a CISO wants. Every agent request evaluated. Every session logged. A content-aware audit trail showing which documents were accessed, which were denied, which external share was paused for approval.

That is genuinely useful, and it will report zero incidents on the governed surface.

It will report nothing at all from the ungoverned one — because the instrument that reports is the instrument that was pointed.

So the belief being held is we are governed, and the evidence supports only the part we can see is governed. Nobody has to be careless for that gap to open. The market selects for what can be bought, demonstrated to an auditor, and deployed without first knowing your own operation. A control that meets all three tests is what exists. Understanding your own agent estate meets none of them, and nobody can sell it to you.


What I would do first

Not policy. Census.

Before any governance decision, the question is what has already been built here that nobody registered.

In practice that means going and looking: unsanctioned API calls, low-code and no-code automations, browser extensions with data access, scheduled scripts nobody owns, and content pipelines that never touch the sanctioned platform. Not a survey asking people what they use. A trace of what is actually running.

Most organizations do not know, and on Box’s own numbers six in ten do not have the visibility to find out.

That number is the finding — the same way the off-contract numbers were the finding, and not a compliance problem.

And it produces the question worth putting to any vendor in this category, including the good ones:

What in this architecture would go off for a fire you did not plan for?

If the answer is nothing, you have doors and no detector.


I put a version of this to Box directly in the comments on their announcement. The classification-layer work deserves the credit I have given it here. The visibility numbers deserve more attention than a webinar promotion line.

Jon Hansen, FCIPS — Procurement Insights | Hansen Models™ | Independent. Unsponsored. Archive-based.

Related: AI Guardrails in 2026 Are What We Called Centrally Established Objectives in 1998. Governance Isn’t That Complicated. — 13 August 2026

-30-


Bonus section — Fourteen years. The instruments changed. The gap did not.

Shadow agents are not a new phenomenon. They are the current form of a measured, documented gap that has been widening for at least fourteen years, and every wave of technology has produced the same three responses.

Here is the record.


2012 — the devices arrive before the policy

I published twice in January 2012 on mobile devices, personal use, and what it was doing to end-user adoption of corporate buying solutions.

The first asked whether employee use of mobile devices personally increases end user adoption of corporate buying solutions, on 25 January. The second, six days later, went from mobile business intelligence to synchronized execution.

BYOD was the debate of the moment. Organizations encouraged it because it was cheaper and people preferred their own devices, then spent the following decade building mobile device management, containerization and access control to re-govern what they had deliberately decentralized.

Encourage first, govern after, at greater cost than the original saving.


2015 — Cisco measures the gap for the first time

Cisco’s Cloud Consumption Service collected actual usage data from customer networks — millions of users, across the United States, Europe, Canada and Australia, from January 2013 to July 2015. Not a survey. Network telemetry.

IT departments estimated their companies were using an average of 51 cloud services. The measured reality was 730.

That figure comes from Shadow IT and the CIO Dilemma, published on the Cisco blog in August 2015.

Three things in that report matter more than the headline number.

The multiple was accelerating. A year earlier it was 7x. Six months earlier, 10x. At time of writing, 15x. Cisco predicted 20x by the end of that calendar year.

It was universal. Almost no difference in the multiples by industry or by geography.

And the cost was invisible. Cisco’s customer research put the true cost of public cloud at four to eight times the provider’s sticker price, once integration, security authorization, network work, vendor management and service catalogue work were counted.

Cisco’s own closing question, in 2015:

How can you get to where you want to go if you don’t know where you are to begin with?

That is the census argument, published by a vendor, eleven years ago.


2018 — Symantec measures it again. The prediction was low.

Symantec’s Shadow Data Report drew on twelve months of anonymized CASB telemetry through February 2018: over 22,000 cloud apps and services, 758 million documents, 1.4 billion emails and attachments.

The average enterprise uses 1,516 cloud apps — 40 times what they typically think. Up 23% from 1,232 in the previous report.

Cisco predicted 20x. Three years later the measured figure was 40x.

⚠ And the methodology note makes it a conservative reading. Symantec states plainly that because many of its customers had already mitigated their cloud application risks, the numbers in the report may be lower than what you would find without a cloud security programme in place.

Forty times, among organizations already trying.


2022 — the self-reported number, which is itself evidence

Forrester Consulting, commissioned by Airtable, surveyed more than a thousand workers in September 2022.

The average large business uses 367 software apps and systems to get work done. Workers spend 2.4 hours a day — nearly a third of the working week — finding the data and information required to do their jobs. Companies with disconnected work methods show a 24% productivity drop.

The findings were reported by CIO Dive in December 2022.

Airtable sells consolidation, so read the framing accordingly.

But notice where 367 sits. Cisco found IT estimating 51 against a measured 730. Symantec measured 1,516 against a belief of roughly 38. Ask people what they use and you get 367. Measure it and you get four times that. The survey number is not a contradiction of the telemetry. It is another instance of the same gap.

And read the 2.4 hours properly. It is not a productivity statistic. It is the measured daily cost of an organization not knowing where its own information lives — recorded four years before anyone had an agent to govern.


2023 — the claim that it was over

I published on user adoption, AI chatbots, and the supposed end of maverick spend, vendor rationalization and change management.

The post was User Adoption and the Rise of the AI Chatbots: The End of Maverick Spend, Vendor Rationalization and Change Management, 26 October 2023.


2026 — Box discloses the current number

Only 39% of organizations report comprehensive visibility across sanctioned and unsanctioned AI use. Only 34% have standards governing how agents access company data.

Different instrument. Different technology era. Same finding.


So how did they deal with it?

Three answers, tried in sequence, across every wave.

1. Prohibit

Ban the unsanctioned tool. Mandate the catalogue. Require the approved platform.

This produced maverick spend, and the numbers were not marginal. When I presented to the Power Transmission Distributors Association in 2005, the off-contract figures for the sector were the story of the room — and the reading that mattered was that front-line buyers were not being insubordinate. They knew what they needed to get the job done and the sanctioned route cost them the outcome they were measured on.

Prohibition does not remove the behaviour. It removes the evidence of the behaviour.

2. Concede and integrate

If people will not come to the system, bring the system to where the people already are.

This is what SAP and Microsoft attempted with Project Mendocino, announced in 2005 and shipped as Duet — embedding SAP functionality inside Microsoft Office so that users working in Outlook and Excel could touch enterprise processes without leaving the tools they actually used.

It was an intelligent response and it deserves credit. It was also an admission. The enterprise system had lost the argument about where work happens, and the answer was to follow the work rather than to understand why it had gone there.

Which is why the spreadsheet never died. Every technology era has announced the end of the spreadsheet, and every technology era has been wrong, because the spreadsheet is not a tool preference. It is what people build when the sanctioned system does not fit the shape of the job.

Shadow agents are the same object with execution rights.

3. Govern what you can see

Rationalize the vendor list. Consolidate the platforms. Install a cloud access security broker. Deploy a hybrid strategy. Apply classification at the content layer.

Each of these is real work and some of it is very good work. All of it shares a boundary: it governs the registered estate.

And on Cisco’s numbers in 2015, and Symantec’s in 2018, and Box’s in 2026, the registered estate has never been the whole estate, and nobody has ever known by how much.


What none of them did first

Cisco named the right first step in 2015 — assess what is actually running before deciding how to govern it. It was sold as a product, which is why it reads as a recommendation rather than a discipline, but the instinct was correct.

Eleven years later, six in ten organizations still cannot see across sanctioned and unsanctioned use.

The instruments improved every single time. The gap widened every single time.

Which is the strongest available argument that the gap is not an instrumentation problem.


Sources in this section are vendor-commissioned or vendor-collected in every case — Cisco, Symantec, Airtable and Box each sell into the problem they are measuring. That is worth stating plainly. It is also the reason the numbers are conservative: each was published by a party with an interest in appearing to have the answer.


After you read this post, be sure to read the follow-up: What Does Cloud Repatriation and AI Repatriation Have in Common, and How Are They Different?

Posted in: Commentary