Agents have hit the mainstream in software engineering, but security and governance practices aren’t evolving fast enough
itpro.com Sep 11, 2026

Agents have hit the mainstream in software engineering, but security and governance practices aren’t evolving fast enough

AI-summarised brief · reviewed before publication

Agentic AI tools are entering mainstream software development, yet security and governance have not kept pace, according to a Harness study. The survey found 87 % of engineering teams experienced at least one agent‑related security incident in the past year. Researchers attribute the problem to limited visibility, weak controls and a culture of overconfidence that leads engineers to ignore risky actions. While 77 % of respondents believe they maintain a complete inventory of agents, MCP servers and large language models, only 44 % can actually verify it. Likewise, 75 % claim end‑to‑end agent security, yet that group reported incidents at nearly the same 88 % rate as the overall sample. Keith Mann, Harness’s field CTO, likened the gap to early mobile and cloud security challenges.

💡 Why It Matters

  • · Overconfidence blinds teams to real vulnerabilities, turning the promise of AI‑driven coding into a hidden attack surface.