AI headlines for business this week (Oct 2, 2026)
Microsoft open-sources agent governance tooling, EMA finds most firms cannot contain rogue agents quickly, Forbes warns about agents already inside your stack, and MCP security moves from experiment to procurement checklist.
Early October and the security conversation caught up to the hype: enterprises are shipping agents faster than they can inventory them, and vendors are finally selling detection and kill switches, not just another chat UI.
The deep dive unpacks the Cequence/EMA numbers on detection gaps and what to fix before you add a fifth production agent.
1. Microsoft Agent Governance Toolkit: open-source controls for any framework
Microsoft published the Agent Governance Toolkit on GitHub: policy enforcement, zero-trust identity, execution sandboxing, and SRE-style kill switches aimed at autonomous agents. It maps to the OWASP Agentic AI Top 10, NIST AI RMF, EU AI Act evidence export, and SOC 2 control narratives. The pitch is one install, any agent framework, with runtime audit trails and a command denylist before tools run.
Why it matters for business: if you build in-house agents on Azure or hybrid stacks, this is a credible starting kit for security reviews. It does not replace a control plane in front of SAP or Salesforce, but it gives engineering a shared vocabulary with your CISO.
Microsoft Agent Governance Toolkit
2. Cequence/EMA: 65% report AI incidents, most cannot contain fast
New Enterprise Management Associates research for Cequence Security finds 65% of enterprises surveyed have experienced an AI-related security incident. Only 32% can detect and contain an out-of-scope agent action within minutes using automation. Nearly 55% need hours and manual steps. Worse: 46% cannot easily produce a complete 30-day audit trail for a specific agent, and 47% cannot reliably inventory every deployed agent.
Why it matters for business: this is the gap between "we have an AI policy" and "we can prove what happened." If your incident response plan assumes SIEM logs from last Tuesday, agentic workflows will embarrass you. Detection and containment belong in the execution path.
Security Info Watch: agentic AI detection gaps
3. Forbes: govern the agents already inside your enterprise
A Forbes Technology Council piece (Sep 3) argues traditional DLP, SASE, and CASB tools were not built for autonomous agents that call APIs and tools on their own. Connector sprawl through chatbots is creating a governance crisis. New platforms like NemoClaw target dispatching agents across corporate infrastructure with sandboxing, but sandboxing alone does not answer which data an agent may read or which tools it may invoke.
Why it matters for business: your risk is not only the agent you approved in a pilot. It is the copilot plugin, the Zapier workflow, and the intern's browser extension that all have credentials. Governance starts with inventory, then purpose-bound permissions per task.
Forbes: govern agents already inside your enterprise
4. MCP security moves from experiment to procurement
The Model Context Protocol is becoming the default way agents reach enterprise tools, but security teams are now asking hard questions: who registered each MCP server, what scopes does it hold, and can we revoke access without redeploying the agent? Vendors like Boomi expose governed MCP tool catalogs; gateways sit in front of tool calls to score risk before execution. Gravitee's 2026 survey still shows most agents operate with limited oversight, which makes MCP sprawl a live audit finding.
Why it matters for business: add MCP servers to your software inventory with the same rigor as OAuth apps. Require owner, data classification, and a decommission plan before production.
AGAT: AI agent security in 2026
5. Agent decommissioning becomes a security discipline
EMA's report flags agent decommissioning alongside discovery and runtime enforcement. Teams retire employees and rotate API keys, but leave agent credentials and scheduled jobs running. Security reviews now ask: when we shut down a pilot, did we revoke tool access, delete secrets, and archive audit logs? Treat retired agents like retired service accounts.
Why it matters for business: schedule a quarterly "agent offboarding" the same way you offboard contractors. Unknown dormant agents are how stale tokens become breaches.
What I would do this week
- Run an agent inventory: name, owner, tools, last active date.
- Time-box your containment drill: can you stop one agent in under 15 minutes?
- List every MCP server and who approved it.
- Read the deep dive on detection gaps before your next leadership update.
Next post is the long read on why detection gaps are your biggest AI risk. Want blog updates? Join the notify list.
Matt Potter · Swift Media