Whitepaper · BS-WP-2026-001

From Autonomy to Accountability

A zero-trust operating model for AI agents in production. Where prompts end and enforcement begins, and how to keep an agent's reasoning and its authority in separate layers.

Download the PDF

July 2026 · Prepared by BitSentry · Free, no email required

  1. 01  Untracked Agents

    82%

    82% of teams discovered agents in their environment that nobody had tracked.

    Cloud Security Alliance (2026)

  2. 02  Excess Access

    74%

    74% report agents with more access than their tasks require.

    Cloud Security Alliance (2026)

  3. 03  Attribution Gap

    68%

    68% cannot clearly separate agent activity from human activity.

    Cloud Security Alliance (2026)

  4. 04  Autonomous Actions

    8 in 10

    Roughly 8 in 10 say agents have already taken consequential autonomous actions.

    Kore.ai Agent Productivity Index (2026)

Self-reported survey data. Full sources, methodology, and limitations are covered in the report.

What's inside

13 sections, fully sourced

Two public incident case studies, the seven layers where agent control actually lives, the BitSentry execution model, and the metrics an auditor would ask for. The full report is in the PDF.

  1. 01 Executive summary
  2. 02 An ordinary incident, resolved by software
  3. 03 From recommendation to execution
  4. 04 Permissions accumulate quietly
  5. 05 Two deletions, and what they teach
  6. 06 Where prompts end and enforcement begins
  7. 07 Zero trust for software that acts
  8. 08 BitSentry: separating reasoning from authority
  9. 09 Procedure over improvisation
  10. 10 How to evaluate a controlled deployment
  11. 11 Bounded autonomy is the practical goal
  12. 12 Methodology and limitations
  13. 13 References
Get the full report

PDF, free, no email required.

See the trust layer in your own stack

Bring us one recurring incident. We will turn it into an approved runbook and show you the audit trail behind every run.