Box Survey Finds Agent Adoption Outpacing Content Governance
The deployment-before-governance pattern identified here is a live risk for APS agencies standing up AI agents against internal systems.
Key points
- A vendor-commissioned survey of 1,640 IT decision-makers found AI agent adoption outpacing access controls and content governance.
- 49% of respondents reported an AI-related data-exposure incident; only 34% had formal standards governing agent data access.
- Survey is vendor-sponsored, self-reported, and unweighted - findings are directionally useful but cannot be generalised.
Implications for Australian agencies
- Consider Agencies evaluating or piloting AI agents could assess whether existing access controls, permission inheritance, and audit logging are in place before broadening agent access to internal content.
- Monitor Governance and risk teams may want to monitor emerging enterprise patterns around agentic AI deployment, as these will likely inform future APS policy guidance on AI agents.
Implications are AI-generated. Starting points, not advice — see methodology for how they're framed.
View original source
Copied.
Appeared in:
Weekly digest, 3 August 2026
"Box Survey Finds Agent Adoption Outpacing Content Governance"
Source: Let's Data Science – AI Governance
Published: 3 August 2026
URL: https://letsdatascience.com/news/box-survey-finds-agent-adoption-outpacing-content-governance-e6e20e68
Box's 2026 State of AI in the Enterprise report, based on a Harris Poll survey of 1,640 IT decision-makers across four countries, finds a significant gap between AI agent adoption and the content controls needed to operate them safely. While 83% of respondents said their organisations were running AI agents, only 36% had connected agents to trusted internal content across many use cases, and only 34% had formal standards governing agent data access. Nearly half reported an AI-related data-exposure incident. The findings are vendor-commissioned and self-reported, limiting generalisation, but the pattern - deployment ahead of identity, permission, provenance, and audit controls - is a recognised risk for any enterprise deploying agentic AI, including government agencies.
Implications for Australian agencies:
- [Consider] Agencies evaluating or piloting AI agents could assess whether existing access controls, permission inheritance, and audit logging are in place before broadening agent access to internal content.
- [Monitor] Governance and risk teams may want to monitor emerging enterprise patterns around agentic AI deployment, as these will likely inform future APS policy guidance on AI agents.
Retrieved from SIMS, 16 September 2026.