← Back to news 03.07.2026

Everyone is building compliance agents now. The interesting question is who controls them

Within a few weeks, Vanta, Drata and ServiceNow all unveiled AI agents for compliance. At the same time, Gartner expects four in ten companies to scale their autonomous agents back by 2027. A story about a race, an old pattern in new clothes, and three questions to answer before your first agent goes live.

June set a pace in the compliance market that you would normally expect from consumer apps. On June 2, Vanta unveiled its "Agent for Risk", bringing internal and third-party risk into one view, and shortly afterwards became a Leader in the Forrester Wave for GRC platforms at its first attempt. On June 10, Drata declared the governance of AI agents the "fourth dimension of trust" and launched a product for it. And at the end of the month, ServiceNow and Accenture announced joint services to migrate legacy risk platforms wholesale to agentic AI. Put the announcements side by side and the pattern is clear: autonomy is the new selling point.

The counter-math

Almost at the same time, in late May, Gartner published a strikingly sober forecast: by 2027, around 40 percent of companies will downgrade or switch off their autonomous AI agents, because governance gaps usually only become visible after something has gone wrong in production. According to 451 Research, 67 percent of GRC buyers also consider vendors' autonomy promises overblown. That makes for a strange picture: the industry sells autonomy, and most buyers do not believe it. Probably rightly so. Because an agent that makes compliance decisions is itself a governance case.

A familiar pattern in new clothes

Earlier this week we wrote about the server that was in no inventory and was the way into the network for exactly that reason. AI agents repeat this pattern in fast forward: an agent gets access rights, works away quietly and appears in no register. Drata now calls this shadow AI and builds sensors just to find foreign agents in your own house. So the new product category is governance of AI, not governance by AI. That the agent vendors themselves invented it is a nice bit of irony.

Three questions before the first agent goes live

  • Is it in the inventory? Which agents are running at all, under which identity, with which permissions? An agent nobody registered is the new forgotten test machine.
  • Does it read or does it act? Access and autonomy are two separate decisions. An agent may know a lot and still be allowed very little.
  • Is the access open or locked in? Does the AI work through an open standard you can inspect, log and replace? Or through a closed platform whose inner workings you buy along, whether you want to or not?

Why we reversed the order

At isidaten we took the opposite route: controlled access first, autonomy second. Our MCP server now exposes practically the entire platform to AI clients, tenant-scoped, from risks through audits and policies to suppliers and firewall rules. The AI can already access and assist today; a human still gives the impulse. We build autonomous assistance on top of this foundation, not in front of it. That sounds less spectacular than an agent doing the audit alone at night. It just has one advantage: it still works if Gartner turns out to be right. What AI access via MCP looks like in practice is on the module page, or directly in a demo.

Questions about this update?

Talk to us – we are happy to show you this feature in a demo.