The Agentic AI Governance Gap: What RSAC 2026 Revealed
As a security expert, I’ve spent years attending the annual RSA Conference (RSAC) to stay ahead of the curve on emerging threats and trends. This year was no exception. Walking the floor, talking to vendors, and listening to security leaders at the Kiteworks booth, I noticed something striking – the industry has finally reached a consensus on the urgent need for agentic AI governance.
The Agentic AI Governance Gap
Vendor after vendor, conversation after conversation, the same word kept surfacing: agents. Cisco announced MCP policy enforcement and agent discovery, while CrowdStrike launched AI agent discovery across endpoints, SaaS, and cloud. Palo Alto Networks introduced Prisma AIRS 3.0 to secure the full agentic AI lifecycle. BeyondTrust rolled out endpoint privilege enforcement for AI coworkers. The Cloud Security Alliance established an entirely new foundation – CSAI – with a stated mission of securing the agentic control plane. Even Nvidia weighed in, explaining that its OpenShell runtime enforces constraints at the infrastructure level rather than at the model layer.
The Industry’s Diagnosis
The industry has arrived at a shared diagnosis: the question that kept coming up in our booth conversations was sharper – Where does governance actually belong? The floor confirmed what our research already showed: when we published the Kiteworks 2026 Data Security, Compliance & Risk Forecast Report last December, the headline finding felt almost too stark – 100% of organizations surveyed have agentic AI on their roadmap. Zero exceptions.
The Numbers Behind the Gap
Walking the RSAC floor, that number no longer surprises anyone. What surprised the people I spoke with were the numbers underneath it: sixty-three percent of organizations cannot enforce purpose limitations on their AI agents, sixty percent cannot terminate an agent that’s misbehaving, and fifty-five percent cannot isolate AI systems from their broader networks. These aren’t obscure technical gaps – they’re the basic containment controls that prevent an autonomous system from exceeding its authorized scope.
The Gap in Governance
That’s the gap I kept hearing practitioners describe in different words at the booth: we can observe our agents, but we can’t stop them. Our Forecast quantifies it as a 15–20 point gap between governance controls (monitoring, human-in-the-loop) and containment controls (purpose-binding, kill switches, network isolation). The industry has invested in watching. It hasn’t invested in stopping.
Discovery is Necessary – But Not Sufficient
Several of the strongest RSAC announcements targeted the discovery problem. Astrix introduced four-method AI agent discovery, while CrowdStrike extended shadow AI detection from endpoints to SaaS and cloud. Nudge Security announced AI agent discovery at the point of creation. Snyk launched Agent Security to surface shadow AI across development pipelines. BeyondTrust’s Phantom Labs published research showing that most enterprises run shadow AI agents with privileged access invisible to security teams. This matters – you cannot govern what you cannot see. But discovery alone doesn’t close the governance gap – it illuminates it.
The Audit Trail: The Infrastructure Nobody Talks About
Here’s something you won’t find in the RSAC keynotes: 33% of organizations lack evidence-quality audit trails entirely, and 61% have fragmented logs scattered across disconnected systems. Our research consistently shows that audit trail quality is the single strongest predictor of AI governance maturity. Organizations without audit trails are half as likely to have AI training data recovery, 20 points behind on purpose binding, and 26 points behind on human-in-the-loop controls.
The Architectural Bet: Data Layer, Not Model Layer
The RSAC announcements revealed a strategic fork in the industry’s approach to AI governance. Some vendors are securing at the model or runtime layer – through prompt filtering, agent sandboxing, and behavioral guardrails. Others, including Kiteworks, are enforcing governance at the data layer. Nvidia’s description of OpenShell – applying security at the environment level rather than the model or application layer – signals that this architectural principle is gaining traction beyond our own positioning.
The Data Layer: A More Durable Approach
Our bet is that data-layer governance will prove more durable. Model prompts can be bypassed. Agent runtimes will evolve. But data access controls – identity verification, ABAC policy enforcement, FIPS 140-3 encryption, and tamper-evident audit logging – operate independently of whatever model or framework is making the request. That’s why Kiteworks Compliant AI enforces all four checkpoints at the data access layer via the open Model Context Protocol standard, ensuring governance remains consistent regardless of which AI platform an organization adopts today or migrates to tomorrow.
What I’m Taking Home from San Francisco
RSAC 2026 confirmed three things. First, the industry has reached consensus that agentic AI governance is an urgent, unsolved problem – the sheer density of agent-focused announcements from Cisco, CrowdStrike, Palo Alto, BeyondTrust, Wiz, and dozens of others makes that unmistakable. Second, discovery and runtime protection are outpacing the foundational infrastructure – audit trails, centralized gateways, and containment controls. Third, the industry is shifting towards data-layer governance as the more durable approach to securing AI systems.
The agentic AI governance gap is real, and it’s not going away anytime soon. But by focusing on data-layer governance, organizations can ensure that their AI systems are secure, compliant, and transparent – regardless of which AI platform they adopt today or migrate to tomorrow.







