Whitepaper · BS-WP-2026-001
From Autonomy
to Accountability
A zero-trust operating model for AI agents in production. Where prompts end and enforcement begins, and how to keep an agent's reasoning and its authority in separate layers.
July 2026 · Prepared by BitSentry · Free, no email required
-
01 Untracked Agents
82%
82% of teams discovered agents in their environment that nobody had tracked.
Cloud Security Alliance (2026)
-
02 Excess Access
74%
74% report agents with more access than their tasks require.
Cloud Security Alliance (2026)
-
03 Attribution Gap
68%
68% cannot clearly separate agent activity from human activity.
Cloud Security Alliance (2026)
-
04 Autonomous Actions
8 in 10
Roughly 8 in 10 say agents have already taken consequential autonomous actions.
Kore.ai Agent Productivity Index (2026)
Self-reported survey data. Full sources, methodology, and limitations are covered in the report.
What's inside
13 sections, fully sourced
Two public incident case studies, the seven layers where agent control actually lives, the BitSentry execution model, and the metrics an auditor would ask for. The full report is in the PDF.
- 01 Executive summary
- 02 An ordinary incident, resolved by software
- 03 From recommendation to execution
- 04 Permissions accumulate quietly
- 05 Two deletions, and what they teach
- 06 Where prompts end and enforcement begins
- 07 Zero trust for software that acts
- 08 BitSentry: separating reasoning from authority
- 09 Procedure over improvisation
- 10 How to evaluate a controlled deployment
- 11 Bounded autonomy is the practical goal
- 12 Methodology and limitations
- 13 References
PDF, free, no email required.
See the trust layer in your own stack
Bring us one recurring incident. We will turn it into an approved runbook and show you the audit trail behind every run.