
Key Takeaways
- Coding agents running on developer machines already represent one of the fastest-growing unmanaged attack surfaces in the enterprise.
- The right board frame for coding agent risk is blast radius, not breach probability: corrupted pipelines and backdoored code can cause irreversible harm.
- 47% of organizations have already experienced an AI agent security incident; only 15% are highly confident in their ability to detect and respond to one.
- Governance starts with inventory: you can't apply controls to agents you don't know about, including the ones IT never formally provisioned.
- SOC 2, ISO 27001, NIST AI RMF, and the EU AI Act are all moving toward requiring behavioral evidence for AI systems, not just access logs.
Claude Code, Cursor, GitHub Copilot, and Gemini CLI are running on developer machines across your enterprise right now. They're browsing the web, writing to your filesystem, committing code to your repositories, and calling external APIs under the identity of your engineers. Most security teams have no visibility into any of it.
This isn't a future problem. According to Zenity's research, 47% of security and IT professionals have already experienced a security incident involving an AI agent in the past 12 months. Only 15% say they're highly confident in their ability to detect and respond to one. The tooling gap is structural, not a configuration problem.
For CISOs, this piece covers three things: how to frame the risk at the board level, where governance starts, and what the regulatory direction requires.
The Board Frame: Blast Radius, Not Breach Probability
Coding agent risk isn't well captured by probability-of-breach framing. The more useful frame is blast radius.
A developer's coding agent with access to source repositories, CI/CD pipelines, and cloud credentials doesn't need to be compromised for long to cause irreversible harm. Corrupted pipelines, backdoored pull requests, and exfiltrated credential stores are the outcomes. Unlike most security incidents, some of them can't be fully remediated after the fact. A malicious commit that makes it to production before it's caught isn't just a security event. It's an operational continuity problem and potentially a software integrity problem with downstream liability implications.
The board conversation that lands is one about operational continuity and software integrity, not just data loss. Coding agents don't just read data. They write code that gets deployed, they modify configurations that control production systems, and they operate under legitimate developer identities that make their actions hard to distinguish from normal development activity in any audit log.
Governance Starts With Inventory
Before any other intervention, CISOs need a complete picture of coding agents in use across the organization. Which tools are deployed, under which approval modes, with which MCP servers connected, and which deployments IT never formally sanctioned.
The inventory challenge for coding agents includes shadow deployments. Developers install and configure coding agents independently, add Model Context Protocol (MCP) server integrations without IT review, and enable plugins from public marketplaces. A comprehensive inventory requires active scanning of developer endpoints, repository configurations, and MCP server registries, not just reviewing what IT formally provisioned.
Every agent in the inventory should have a named business owner: a specific individual accountable for the agent's configuration, behavior, and compliance with enterprise security policy. When an incident occurs, there should be no ambiguity about who owns the remediation. The 31% of organizations that have AI agent governance policies that are formally documented and adopted are the ones that can answer that question without scrambling.
Accountability Structure Before an Incident Forces It
When an incident occurs, the questions that follow are immediate and specific: who owned this agent, what was it authorized to do, and what did it actually do? If those questions require manual reconstruction under incident pressure, the accountability structure isn't in place.
The five-stage lifecycle framework that makes inventory actionable covers discovery, provisioning with security review, runtime monitoring and behavioral detection, periodic re-attestation, and formal retirement with token revocation and audit trail preservation. Each stage has a security event associated with it. Treating agent decommissioning as a formal security event, not an informal deletion, is part of building the accountability structure that survives an incident.
The Regulatory Direction
The regulatory landscape for agentic AI is moving faster than most compliance programs are tracking.
SOC 2 Type II assessments increasingly require evidence that controls apply to automated systems, not just human users. ISO 27001 information security requirements extend to all information-processing systems, including agents. The NIST AI Risk Management Framework (AI RMF) provides a structured approach to AI risk across the full system lifecycle and is increasingly referenced in audits. The EU AI Act, in force since 2024, imposes transparency, human oversight, and audit-trail obligations for high-risk systems, a framework that will increasingly apply to enterprise agentic deployments.
The regulatory direction is clear: 'authorization was granted' is no longer a sufficient compliance answer. Auditors will increasingly ask not just 'what permissions did the agent have?' but 'what did the agent actually do, and how do you know that what it did was appropriate?' Answering the second question requires intent observability, the capability to show not just the sequence of actions but the decision context behind them.
Organizations building that capability now will be able to answer the question when auditors ask it. Those who aren't will be reconstructing it under audit pressure.
Get the full governance framework, threat model, and detection playbook → Download The Ultimate Guide to Securing Coding Agents
Related blog posts

Coalition Chaos
I've tracked eighteen initiatives across a dozen countries, five months, and several issues being worked seven...

The Identity Surface You're Not Watching: Three Layers of Coding Agent Risk
There's a widespread assumption in enterprise security that identity is a problem IAM programs know how to solve....

A Safer Future with Agents
We built agents to act on their own. We're somehow surprised when they do. Two weeks ago, OpenAI ran a cyber eval...
Secure Your Agents
We’d love to chat with you about how your team can secure and govern AI Agents everywhere.
Get a Demo