77% claim an AI agent inventory. 44% have the tooling
A Harness survey of 700 enterprises finds AI agent confidence running far ahead of controls: no discovery, no kill switch, no release gate. Here's the fix list.
Ask an engineering leader whether they know every AI agent running in production and 77% will say yes. Ask whether anything on the network could actually find one they forgot about, and the number drops to 44%. That gap — confidence without the control that would justify it — is the whole finding of Harness's new report, and it is the cheapest problem on this list to fix before it becomes yours.
What actually happened
Harness published "The State of Agent DLC 2026" on September 10. Sapio Research fielded it in July 2026 across 700 technology professionals in the US, UK, France, Germany and India, all at companies with 1,000+ employees, 100+ developers and $100M+ in revenue. These are not scrappy startups winging it.
The survey asked about confidence and then about the mechanism behind it. Five domains, same shape every time:
- Inventory. 77% confident they have a complete list of every agent, MCP server and LLM in production. 44% run active discovery tooling. Harness puts the residual at 41% of the whole sample confidently declaring no shadow AI with nothing in place that could detect it.
- Testing. 74% confident testing catches production failures. 19% have automatic release gates that block a bad build.
- Rollback. 76% believe they can disable a misbehaving agent within 15 minutes. 33% have an instant kill switch.
- Security. 75% say their agents are secure end to end. 88% of that confident group reported security incidents anyway — worse than the 87% sample average.
- Cost. 74% claim complete spend visibility. 60% overran budget last quarter.
One number frames the rest: 58% report more production incidents since deploying AI agents, and only 53% of agent changes pass through a standard pipeline before reaching production.
Why this matters for your business
Enterprises with a hundred developers are describing a control gap you can close in an afternoon, because you have six agents and they have six hundred. Use the advantage.
Write the inventory down today. One file in the repo: every agent, what model it calls, which credentials it holds, who owns it, what it costs. If you cannot produce that list from memory, you already have shadow AI — you just have less of it than they do.
Give every agent an off switch before it ships. A feature flag, an env var, a revocable key. Not a vendor dashboard you have never logged into. "We think we could stop it in 15 minutes" is not an answer during the incident.
Put agent changes through the same pipeline as code. Prompts are configuration, and configuration that skips review is how 53% happens. If a prompt edit can reach production without a diff and an approval, that is your next outage.
Cap the spend at the key. Per-agent budget, hard ceiling, alert at 50%. The 60% who overran had visibility. Visibility is not a limit.
Key takeaways
- Harness's State of Agent DLC 2026 surveyed 700 enterprise tech professionals via Sapio Research in July 2026
- 77% claim a complete agent inventory; only 44% run active discovery tooling
- 74% trust their testing; only 19% have automatic gates that block a bad release
- 76% think they can kill a misbehaving agent in 15 minutes; 33% have an instant kill switch
- 75% call their agents secure, yet 88% of that group had security incidents — above the 87% average
- 58% report more production incidents since deploying agents, and only 53% of agent changes go through a standard pipeline
Small fleet, real controls — that combination is still available to you. We build agent workflows with an inventory, a kill switch and a per-agent budget on day one, not after the first surprise invoice. See how we build them, or have us audit what you're already running.
Sources: Harness press release, Harness — The AI Agent Confidence Gap.
- #ai-agents
- #governance
- #shadow-ai
- #automation
- #ai-costs
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Nvidia weighs $10B anchor stake in Anthropic's IPO
Reuters reports Nvidia is in talks to anchor Anthropic's IPO with up to $10 billion at a ~$2 trillion valuation. What a supplier-turned-shareholder means for your AI contracts.
Read itSenate AI duty of care draft: model releases get a veto
Thune, Cruz and Klobuchar are drafting a federal AI duty of care with power to block unsafe model releases and preempt state law. What it means for your stack.
Read it