On October 8, 2026, Optro, the governance software company formerly known as AuditBoard, released a survey of more than 400 governance, risk, and compliance professionals at companies in the United States and Europe. Matt Kelly of Radical Compliance reported the findings the same day. Twenty-five percent of respondents had experienced a control failure involving an AI agent. Thirty percent had watched an agent take an action no one intended. Forty-five percent said they know or suspect that agents were deployed in their company without formal approval or review.

A Board Cannot Oversee an Inventory It Does Not Have

The forty-five percent is the number that matters most, because of what an unapproved agent lacks. It has no named owner, no defined scope, and no condition under which anyone is told to stop it. Every later oversight question depends on a list of what is running. A company that suspects agents it has not listed cannot answer who owns them, what they may do without a person, or what they did last quarter.

The sample is practitioners reached by a software vendor, so it reads as a signal and not a census. The signal is still specific: the people closest to the controls are describing agents that arrived through the side door.

The Failure the Board Is Asking About Has Already Happened Elsewhere

One in three respondents said employees had acted on an inaccurate AI decision or action. One in four had a control failure. These are not forecasts of what agents might do. They are reports of what agents did, inside companies that mostly believed their controls were adequate.

Delaware's Caremark standard asks whether directors consciously ignored red flags. Industry survey data is not a red flag inside a particular company. It does, however, make "we had no reason to ask" a harder sentence to defend when a quarter of the market is reporting the failure.

Authority Was Granted Faster Than It Could Be Governed

Guru Sethupathy of Optro put the remedy in a single line: agent authority should match an organization's ability to govern it. Who sets that match is the question. Under the Governance Boundary Principle, management manages the agents and the board owns the standard that decides how much authority an agent may be given. A board that leaves the standard to whoever deployed the tool has handed its own decision to the people who gain from a faster rollout.

The survey adds a mechanism. Ninety-six percent said workflows should adapt to what AI can do, but only nine percent had redesigned a workflow around agents. The rest placed an agent inside a process built for people, where the control quietly assumed a person would catch the error. The agent removed the person and kept the process. Kelly's own observation points to who knows where that breaks: the employees running those workflows every day, who rarely reach the boardroom.

Action Point

Before the next audit committee meeting, ask management for two things. First, a list of every AI agent in production, with a named owner, what it can do without a person, and how many on the list were never formally approved. Second, the log of every unintended action in the past twelve months. Then ask to hear from two people who run the affected workflows, without their managers in the room.

A board that builds this inventory now leaves its successors a company that can say what its agents are doing, and the inventory is not built in response to litigation or an examiner's letter.