New Harness Report Reveals Enterprise Confidence in AI Agents Isn’t Backed by Real Controls
SAN FRANCISCO, Sept. 10, 2026
Press Release Disclaimer: This is a press release distributed through the XPR Media network. It has not been independently verified by our newsroom.

![]()
New Harness Report Reveals Enterprise Confidence in AI Agents Isn’t Backed by Real Controls
PR Newswire
SAN FRANCISCO, Sept. 10, 2026
A survey of 700 engineering leaders finds enterprise confidence in AI agents outpaces the testing, security, and governance controls organizations have in place
SAN FRANCISCO, Sept. 10, 2026 /PRNewswire/ — Harness, the platform for the autonomous SDLC, today released The State of Agent DLC 2026, a new report showing that enterprise confidence in AI agents exceeds the controls organizations have in place to test, secure, and govern them. This lack of control presents a significant risk for enterprises deploying AI agents.
AI agents don’t behave like deterministic software — the same agent can produce different outputs from one run to the next. That means they need controls built for that variability. Most organizations are still relying on controls built for deterministic software, and the report finds that gap is already showing up in production incidents, security breaches, and blown budgets.
Most Enterprises Trust Their AI Agents, Few Can Control Them
Ask organizations if they trust their AI agents, and most say yes. Ask a more specific question — do you have a tool that tells you every agent running in your environment, or a way to shut one off the moment it misbehaves — and the answer is often no. That gap holds across every domain the survey covered: testing, security, inventory, cost, and rollback. Confidence lands in the mid-70s of those surveyed in each case, but the control that would back it up is in place for less than half of organizations, and in some cases fewer than one in five.
- Organizations don’t have full visibility into what’s actually running. 77% are confident they have a complete inventory of every agent, MCP server, and LLM in their environment, but only 44% run active discovery tooling to verify it.
- Most can’t confirm testing would catch a failure before it ships. 74% are confident their testing would catch a production-impacting failure, but only 19% have a gate that automatically blocks every bad release.
- If something does go wrong, most organizations couldn’t stop it fast enough. 76% believe they could disable a misbehaving agent in under 15 minutes, but only 33% have an instant kill switch in place.
- Confidence in agent security has almost no relationship to actual resilience. 75% say their agents are secure end to end, but that group had security incidents at almost the same rate (88%) as the overall respondent population (87%).
- Visibility into the budget isn’t helping spend control. 74% say they have a complete picture of true spend per agent, while 60% still overran their budget last quarter.
“What caught our attention is how consistent this pattern is,” said Keith Mann, Field CTO and Head of Research at Harness. “Cloud and mobile both went through a phase where confidence outran governance, but eventually the controls caught up because the underlying systems stayed predictable once you built the guardrail. Agents don’t hold still in the same way. A control that worked in testing can still miss something in production because an agent doesn’t behave the same way every time. That’s why closing this gap takes real verification. Organizations need to test whether a control actually holds up against an agent’s variability, not assume it does because the control exists.”
What the Confidence Gap Is Already Costing Organizations
The confidence gap shows up fastest in how changes actually get shipped. Most organizations are routing AI agent changes through pipelines built for code, without adjusting how those changes get tested, approved, or tracked.
- There’s no real system for managing agent changes. 42% run prompt edits through the same pipeline as a code change, while just 34% have a dedicated configuration system for AI behavior.
- Without dedicated tooling, organizations default to routing agent changes through code pipelines, inconsistently. Just 53% of agent-related changes go through any standard pipeline before production, and 37% run less than half of theirs through one.
- With no consistent pipeline in place, whether to trust a given change comes down to judgment. More than 4 in 10 organizations decide case by case whether to trust a change, and among those that do promote agent changes to production, only 58% check every change against a fixed, repeatable standard.
- Incidents are only climbing in number as agents scale. 58% of organizations report an increase in production incidents per 100 changes since deploying AI agents, and roughly 7 in 8 had at least one tangible agent-related issue this year.
“The truths we found in the report are the same ones we’re hearing in daily conversations with customers,” said Trevor Stuart, SVP and General Manager at Harness. “Teams moved fast to build and release agents, and are now circling back to ask how to actually govern what they’ve already shipped. The teams furthest ahead have already adopted a governed orchestration engine for agent changes, instead of waiting for an incident to force the question.”
How Organizations Are Closing the Confidence Gap
The report points to a consistent pattern among organizations closing this gap, and Harness recommends the same sequence to the teams it works with directly:
- Treat the agent lifecycle as its own discipline. Build evals, security, inventory, and rollback specifically for agent behavior, rather than routing agent changes through the same pipeline built for deterministic software.
- Replace ad hoc reviews with a fixed, repeatable standard. Every change promoted to production should be checked against the same standard, whether that check is automated or manual.
- Adopt progressive rollout for agents, not just manual gates. Techniques like canary and blue/green deployment limit exposure, but remain far less common for agent changes than for code changes.
To learn more, download the full State of Agent DLC 2026 report here: https://www.harness.io/state-of-agent-dlc-2026.
About the Research
This report is based on a survey of 700 technology professionals at large enterprises in the United States, United Kingdom, France, Germany, and India, conducted by Sapio Research in July 2026 on behalf of Harness. Respondents were screened for organizations with 1,000 or more employees, 100 or more developers, and annual revenue above $100 million, working in software engineering, IT operations or infrastructure, or technology leadership. Participation required that the organization had already deployed AI agents in production, in pilot, or at least in a live proof of concept, so the figures reflect how far committed adopters have progressed rather than how widespread adoption is across enterprises generally.
About Harness
Harness is the AI Software Delivery Platform™ company, enabling engineering teams to build, test, and deliver software faster and more securely. Powered by Harness AI and the Software Delivery Knowledge Graph, the platform brings intelligent automation to every stage of the software delivery lifecycle after code — removing toil and freeing developers from manual, repetitive work. Companies like United Airlines, Morningstar, and Choice Hotels use Harness to accelerate releases by up to 75%, cut cloud costs by 60%, and achieve 10x efficiency across DevOps. Based in San Francisco, Harness is backed by Goldman Sachs, Menlo Ventures, IVP, Unusual Ventures, and Citi Ventures.
View original content to download multimedia:https://www.prnewswire.com/news-releases/new-harness-report-reveals-enterprise-confidence-in-ai-agents-isnt-backed-by-real-controls-302875476.html
SOURCE Harness



