New Harness Report Reveals Enterprise Confidence in AI Agents Isn’t Backed by Real Controls

Harness today released The State of Agent DLC 2026, a new report showing that enterprise confidence in AI agents exceeds the controls organizations have in place to test, secure, and govern them. This lack of control presents a significant risk for enterprises deploying AI agents. 

AI agents don’t behave like deterministic software — the same agent can produce different outputs from one run to the next. That means they need controls built for that variability. Most organizations are still relying on controls built for deterministic software, and the report finds that gap is already showing up in production incidents, security breaches, and blown budgets.

Most Enterprises Trust Their AI Agents, Few Can Control Them

Ask organizations if they trust their AI agents, and most say yes. Ask a more specific question — do you have a tool that tells you every agent running in your environment, or a way to shut one off the moment it misbehaves — and the answer is often no. That gap holds across every domain the survey covered: testing, security, inventory, cost, and rollback. Confidence lands in the mid-70s of those surveyed in each case, but the control that would back it up is in place for less than half of organizations, and in some cases fewer than one in five.

  • Organizations don’t have full visibility into what’s actually running. 77% are confident they have a complete inventory of every agent, MCP server, and LLM in their environment, but only 44% run active discovery tooling to verify it.
  • Most can’t confirm testing would catch a failure before it ships. 74% are confident their testing would catch a production-impacting failure, but only 19% have a gate that automatically blocks every bad release.
  • If something does go wrong, most organizations couldn’t stop it fast enough. 76% believe they could disable a misbehaving agent in under 15 minutes, but only 33% have an instant kill switch in place.
  • Confidence in agent security has almost no relationship to actual resilience. 75% say their agents are secure end to end, but that group had security incidents at almost the same rate (88%) as the overall respondent population (87%).
  • Visibility into the budget isn’t helping spend control. 74% say they have a complete picture of true spend per agent, while 60% still overran their budget last quarter.

What the Confidence Gap Is Already Costing Organizations

The confidence gap shows up fastest in how changes actually get shipped. Most organizations are routing AI agent changes through pipelines built for code, without adjusting how those changes get tested, approved, or tracked.

  • There’s no real system for managing agent changes. 42% run prompt edits through the same pipeline as a code change, while just 34% have a dedicated configuration system for AI behavior.
  • Without dedicated tooling, organizations default to routing agent changes through code pipelines, inconsistently. Just 53% of agent-related changes go through any standard pipeline before production, and 37% run less than half of theirs through one.
  • With no consistent pipeline in place, whether to trust a given change comes down to judgment. More than 4 in 10 organizations decide case by case whether to trust a change, and among those that do promote agent changes to production, only 58% check every change against a fixed, repeatable standard.
  • Incidents are only climbing in number as agents scale. 58% of organizations report an increase in production incidents per 100 changes since deploying AI agents, and roughly 7 in 8 had at least one tangible agent-related issue this year.

How Organizations Are Closing the Confidence Gap

The report points to a consistent pattern among organizations closing this gap, and Harness recommends the same sequence to the teams it works with directly:

  • Treat the agent lifecycle as its own discipline. Build evals, security, inventory, and rollback specifically for agent behavior, rather than routing agent changes through the same pipeline built for non-deterministic software. 
  • Replace ad hoc reviews with a fixed, repeatable standard. Every change promoted to production should be checked against the same standard, whether that check is automated or manual.
  • Adopt progressive rollout for agents, not just manual gates. Techniques like canary and blue/green deployment limit exposure, but remain far less common for agent changes than for code changes.

To learn more, download the full State of Agent DLC 2026 report here: https://www.harness.io/state-of-agent-dlc-2026

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading