Ask a company whether it trusts the AI agents running in its systems and most will say yes. Ask two follow-ups instead (which agents are running right now, and can you shut one down the moment it misbehaves?) and the answers get a lot less confident.
That's the pattern in The State of Agent DLC 2026, a report from Harness based on a survey of 700 engineers and engineering leaders at large enterprises in the US, UK, France, Germany, and India, run by Sapio Research in July 2026. Harness sells tooling in this area, so read its conclusions with that in mind. Still, the central finding is easy to believe: confidence sits in the mid-70s across every area the survey covered, while the controls that would justify it are far less common.
Why agents need a different kind of oversight
Traditional software does the same thing every time you run it. An AI agent can produce a different result from one run to the next. That variability is much of the reason to use one, and also why the checks most teams already have, such as a test suite that passes or fails, don't quite fit.
What the numbers say
Here is how confidence compares with what companies actually have in place:
- Inventory: 77% are confident they have a complete list of every agent running in their environment, but only 44% run tools to verify it.
- Testing: 74% trust their testing to catch a failure before it reaches production, while 19% have an automatic system that blocks a bad release.
- Shutdown: 76% believe they could disable a misbehaving agent in under 15 minutes, and 33% have a kill switch ready.
- Security: 75% say their agents are secure end to end, yet that group reported security incidents at almost the same rate (88%) as everyone else (87%).
- Cost: 74% say they know what each agent costs, and 60% still went over budget last quarter.
The security line deserves a second look. Feeling secure told you nothing about whether an incident had happened.
Where the process breaks
Most companies still send agent changes, such as prompt edits and configuration tweaks, through the same pipelines they use for ordinary code. Only 34% have a system built specifically for managing agent changes. In practice, that means a one-line prompt edit can reach production with less scrutiny than a small bug fix would get.
What companies further ahead do differently
The report describes a few habits among organizations that are closing the gap. They treat agents as their own category, with separate testing, security checks, inventory, and rollback plans, instead of reusing the code pipeline. They replace case-by-case reviews with one standard that every change must pass before going live, whether a tool or a person does the checking. And they release gradually, using canary releases, where a change goes to a small group first, rather than pushing every update to everyone at once.
If you run agents and want a starting point of our own, begin with a plain list: every agent, who owns it, what it can touch, and who can turn it off. It takes an afternoon, and it closes the first two gaps before you buy anything.
Confidence needs evidence
None of these gaps is dramatic on its own. A missing inventory or an untested prompt change rarely causes trouble until the day it does, and by then the company is looking for answers it should have had beforehand. The businesses best prepared will be the ones that built visibility, testing, and a working shutdown process before they needed them.
If you're planning to bring AI into your workflows, we can help you build the platform and integrations with these controls in mind. Get in touch and tell us what you're trying to automate.
Source: Harness, "New Harness Report Reveals Enterprise Confidence in AI Agents Isn't Backed by Real Controls," September 10, 2026, based on a survey of 700 technology professionals conducted by Sapio Research. Full report.
