AgenticSafe Reports
Audit & Compliance AI Agent Governance - Board Oversight Briefing
Executive Summary
Quarterly posture for the Audit & Risk Committee - business context, trends, and required actions.
During Q2 2026 (reporting window ending 08 July 2026), the organization observed 10 distinct AI agents across seven LLM gateway and tracing platforms. Compared with Q1 2026, the estate grew by 2 agents (8 to 10). Five agents are enterprise-governed (built or approved internally); five operate from outside our direct control (3 under partner contracts, 2 with no contract on file).
Third-party exposure increased over the quarter: unregistered 'shadow' agents rose from 1 in Q1 2026 to 2 in Q2 2026 (+1). These agents were discovered in production logs but never passed through procurement or security onboarding. Neither shadow agent has been assigned a security classification yet, meaning we cannot state whether their behavior is acceptable, requires monitoring, or should be blocked.
Visibility into the estate improved materially: monitoring coverage reached 7 of 7 platforms in Q2 2026, up from 5 in Q1 2026. We can now see agent traffic on every major gateway (LiteLLM, Portkey, Cloudflare, OpenTelemetry, Helicone, Langfuse, LangSmith). However, log data is loaded on a batch schedule; as of 08 July 2026, no agent showed activity in the trailing 24 hours, so 'active vs dormant' signals may reflect ingest timing rather than actual business usage.
Governance processes have not kept pace with discovery. Three partner agents remain properly registered, but the two shadow agents lack identity verification, contractual cover, and security review. Remediation requires: (1) completing the security-classification workflow described in Appendix A so each log event receives a clear verdict; (2) issuing a registration policy requiring external agents to be declared before production use; (3) increasing ingest frequency so the board receives timely activity signals.
Agent Estate Dashboard
Current = Q2 2026 snapshot. Prior = Q1 2026 board baseline. Trend shows direction between the two quarters.
| Metric | Definition | Q2 2026 | Q1 2026 | Trend | Why it matters |
|---|---|---|---|---|---|
| Distinct AI agents | Unique agent identities company-wide (deduplicated across platforms). | 10 | 8 | Up | +2 vs Q1 2026; discovery finding new identities. |
| Shadow agents | External agents with no contract or onboarding record. | 2 | 1 | Up | Rose 1->2; register or remove. |
| Partner agents | External agents with declared partner identity on file. | 3 | 3 | Flat | Stable; no new partner registrations. |
| Active (24h)* | Agents with log activity in the past 24 hours. | 0/12 | 4/10 | Down | *Data-freshness caveat: batch is ~36 days old, so all agents read as inactive. Not evidence of zero usage - see note below. |
| Platform coverage | Gateways and tracers feeding discovery data. | 7/7 | 5/7 | Up | Full coverage; gap is classification. |
| External activity | Log lines from outside the organization. | 35% | 28% | Up | +7 pts; review third-party use. |
| Unclassified events | Log lines without cleared/blocked/review verdict. | 280 | 180 | Up | 100% pending; see Appendix A workflow. |
* The activity data was loaded in a single quarterly batch that is now ~36 days old. Because the "active in 24 hours" test measures the trailing day, every agent currently reads as inactive. This is a data-collection timing effect, not evidence that AI agents stopped operating.
Governance Spotlight
Every agent in scope falls into one of three governance categories. Enterprise-governed agents are built or explicitly approved by our teams. Partner agents are external but registered. Shadow agents appeared in production logs without registration; they represent the highest oversight gap.
Identity assurance levels (what Status means)
| Assurance level | Plain-language meaning for directors |
|---|---|
| Managed | Built and operated by our own teams; identity confirmed through internal controls. |
| Verified | External partner agent whose identity was checked against a contract or allow-list. |
| Declared | Partner agent that self-identified; we recorded the claim but have not independently verified it. |
| Unverified | Agent found in logs with no registration, contract, or identity check on file. |
Shadow agents - required remediation steps
- Step 1 - Identify owner: determine which business unit triggered each agent.
- Step 2 - Register or retire: add a partner registration record, or disable if unauthorized.
- Step 3 - Security review: complete the Appendix A workflow (cleared / monitor / block).
- Step 4 - Report back: record the decision so next quarter's pack shows a verdict.
| Agent (business description) | Activity | Assurance | Required action |
|---|---|---|---|
| External research assistant (OpenAI-compatible) | 2 events; 36d idle | Unverified | Register owner; Appendix A review; record verdict |
| Automated web data collection agent (MCP tools) | 1 events; 36d idle | Unverified | Register owner; Appendix A review; record verdict |
Appendix A - Security classification in Discovery
All 280 observed events are currently unreviewed (no verdict recorded). A security review assigns each a plain-language outcome:
| Verdict | What it means | Board-report impact |
|---|---|---|
| Cleared | Analyst confirms acceptable use; no action needed. | Backlog decreases; posture improves. |
| Under review | SOC investigating; agent may continue with monitoring. | Shown as an active investigation. |
| Blocked | Unacceptable risk; agent disabled at the gateway. | Shadow agent marked for removal. |
| Pending (today) | No analyst verdict recorded yet - default for all events. | Board cannot assess acceptable risk. |
Worked example (plain language)
An external 'research assistant' agent appears in our logs and a safety filter flags one request. Today it is 'pending' (risk unknown) and counts toward the review backlog. After a security analyst reviews it, the outcome is CLEARED (behaviour acceptable - no action) or BLOCKED (agent disabled and removed). Next quarter's pack then shows a clear verdict instead of 'pending'.
Recommended Q3 operationalization roadmap
| Step | Action |
|---|---|
| Review queue | Assign analysts to the unreviewed activity backlog |
| Service level | 10 business days to a first verdict |
| Integration | Automatic feed from Security tools into Discovery |
| Cadence | Weekly data loads for fresh activity signals |
| History | Save quarterly snapshots for accurate trends |
Glossary: Shadow agent = external AI found in logs without registration. Partner agent = external AI with a declared vendor identity. SOC = Security Operations Center (the team that reviews security alerts). Program approvals and budget decisions are presented in the CISO executive pack.