
Box launched AI agent governance with content-layer controls. Its own data shows 66% of enterprises have no rules for how agents access company data — a gap that mirrors 15 years of shadow IT patterns.
On August 14, Box announced Agent Security and Governance, a suite covering prompt injection detection, agent guardrails, activity oversight, and audit trails. The product enforces controls at the content layer, applying to agents running inside Box and to those connecting from Claude, ChatGPT, Copilot, and Gemini through their MCP server.
Classification-based access control at the content layer is a strong approach. A file classified Confidential can be made unreachable to an agent regardless of how the request is phrased or whether the user running it could open that file manually. A rule about the material does not require anticipating every behaviour.
The same announcement contained a more troubling number. According to Box's own launch materials, only 39% of organizations report comprehensive visibility across sanctioned and unsanctioned AI use. Only 34% have standards governing how agents access company data.
Those are Box's numbers, in Box's launch material, which means they are the favourable framing of a market they are selling into. Six in ten organizations lack comprehensive visibility. Two-thirds have no standards for agent data access.
The 39% is a share of organizations reporting comprehensive visibility. It is not a measure of how much agent activity is sanctioned versus unsanctioned. Nobody has that number, which is the point. On Box's own data, most enterprises cannot establish how much of what is actually running lies outside the sanctioned path.
Industry commentator Jon Hansen, who published the analysis this article draws on, noted that the gap mirrors patterns from earlier technology waves. In 2015, Cisco's Cloud Consumption Service collected network telemetry from millions of users across multiple countries. IT departments estimated their companies were using an average of 51 cloud services. The measured reality was 730.
By 2018, Symantec's Shadow Data Report found the average enterprise uses 1,516 cloud apps – 40 times what they typically think. The methodology note made the reading conservative: many of its customers had already mitigated cloud application risks, so the numbers may be lower than what you would find without a cloud security programme in place.
"The bypass got cheaper while the detection got harder," Hansen wrote. He pointed out that a shadow agent leaves nothing in the spend record, and building one requires a login and an afternoon.
Box's product governs content that lives in Box. Other products monitor other layers – network telemetry, endpoint, browser, API gateways, identity. None of them should be assumed to deliver complete visibility without evidence that they do. On these numbers, most organizations do not have that evidence.
Buried in a section on access governance, Box's own VP of Product Management for Security and Compliance recounted internal incidents at two frontier AI labs in which containment failed at gaps the evaluation environment had not anticipated. Every layer of containment held until the one gap none of the humans had thought to check.
"A guardrail is a rule about a failure you can conceive," Hansen wrote. "You cannot write the rule for a failure your model gives you no reason to imagine."
Session governance produces exactly the artifact a CISO wants. Every agent request evaluated. Every session logged. A content-aware audit trail showing which documents were accessed, which were denied, which external share was paused for approval. That is genuinely useful, and it will report zero incidents on the governed surface. It will report nothing at all from the ungoverned one.
Before any governance decision, the question is what has already been built here that nobody registered. Unsanctioned API calls, low-code and no-code automations, browser extensions with data access, scheduled scripts nobody owns, and content pipelines that never touch the sanctioned platform. Not a survey asking people what they use. A trace of what is actually running.
The risk is immediate. Enterprises that assume their governance covers the full estate face exposure from shadow agents. The gap is not an instrumentation problem – the instruments improved every time, and the gap widened every time.
For investors in enterprise software companies, the data point matters. Microsoft and SAP have both invested in embedding AI into their platforms. Microsoft's MSFT stock page shows an Alpha Score of 71, while SAP SE scores 53. If enterprises cannot govern what they have, the value of those platforms may be undermined by the same shadow adoption patterns that plagued earlier cloud deployments.
Hansen concluded that the first step, as Cisco recommended in 2015, is to assess what is actually running before deciding how to govern it. Eleven years later, six in ten organizations still cannot see the full picture.
Drafted by a large language model from the source reporting linked above, then screened by automated publishing checks. It is not read by a journalist before publication. Some articles cite our Alpha Score. Verify prices and figures against the original source. Educational coverage, not personalized advice.