Agents have hit the mainstream in software engineering, but security and governance practices aren’t evolving fast enough
AI-summarised brief · reviewed before publication
Agentic AI tools are entering mainstream software development, yet security and governance have not kept pace, according to a Harness study. The survey found 87 % of engineering teams experienced at least one agent‑related security incident in the past year. Researchers attribute the problem to limited visibility, weak controls and a culture of overconfidence that leads engineers to ignore risky actions. While 77 % of respondents believe they maintain a complete inventory of agents, MCP servers and large language models, only 44 % can actually verify it. Likewise, 75 % claim end‑to‑end agent security, yet that group reported incidents at nearly the same 88 % rate as the overall sample. Keith Mann, Harness’s field CTO, likened the gap to early mobile and cloud security challenges.
💡 Why It Matters
- · Overconfidence blinds teams to real vulnerabilities, turning the promise of AI‑driven coding into a hidden attack surface.