OneTrust Finds Firms Boost AI Governance Amid Incidents
A new report from security vendor OneTrust reveals that enterprises are accelerating AI deployments despite experiencing security incidents, shifting their focus toward real-time governance.

A new report from AI data privacy and security vendor OneTrust reveals that enterprises are refusing to slow down their artificial intelligence deployments, even after experiencing significant AI-related setbacks over the past year. These issues include intellectual property exposure and autonomous AI agents deleting or improperly using corporate data. Rather than pausing their rollouts, organizations are aggressively moving forward, driven by intense pressure from board members to transform operations and avoid disruption by competitors.
According to Blake Brannon, OneTrust's chief innovation officer, this rapid adoption is fundamentally changing how companies approach security. Brannon notes that within the next two years, most organizations will have more active AI agents than human employees. Because traditional corporate governance processes were designed for human-driven or deterministic software systems and often took weeks to execute, they are entirely inadequate for autonomous agents. Modern security frameworks must now evaluate and authorize actions in seconds to keep pace with citizen developers building custom agents.
To address these risks, Brannon advocates for an architectural shift toward independent governing harnesses that remain completely separate from the AI models they monitor. Because models can potentially bypass their own internal guardrails, practitioners cannot rely on self-regulation. An external harness acts as an unbiased safety system, similar to an emergency brake, allowing human oversight when an agent attempts a destructive action.
For IT and security practitioners, this approach simplifies the management of highly fragmented environments where different departments use various model providers. Instead of trying to govern the internal reasoning of every individual model, organizations should focus their control policies on the fixed points where AI systems interact with enterprise data. This means applying guardrails specifically when an agent attempts to read a database, send an email, or delete a record, ensuring compliance without stalling innovation.
This is our own summary of reporting by AI Business



