Most companies believe they have their AI agents under control, but the numbers tell a different story. A new survey shows that while 91.8% of technology leaders are confident in their visibility into these systems, the actual average monitoring coverage sits at just 52%. That mismatch is exactly the problem EnforceAuth is trying to solve with Evidence IQ, a new evidence layer for AI agent security announced today from San Diego.
A new record that shows why an AI agent was allowed to do what it did, who authorized it and what changed after
SAN DIEGO, CA, UNITED STATES, October 8, 2026 /EINPresswire.com/ — EnforceAuth, the AI Security Fabric, today announced Evidence IQ, a new evidence layer for AI agent security. It records the authorization decisions made for AI agents as tamper-evident evidence, so a company can show why an agent was allowed to act, whose authority it acted under, and what changed afterward.
Key facts
– 91.8% of 750 surveyed technology leaders said they were confident in their visibility into AI agents. Mean monitoring coverage was 52% (Gravitee, April 2026).
– Evidence IQ records authorization decisions for AI agents as tamper-evident evidence that can be reconstructed and replayed.
"AI safety controls what an agent says. AI security controls what it is allowed to do," said Mark Rogge, founder and CEO of EnforceAuth. "An agent can be polite, pass every content guardrail and still move data it should never touch. Polite AI is not secure AI. Authorization has always asked whether a request is allowed right now. Evidence IQ answers the question auditors and regulators now ask: why did we say yes?"
Enterprises believe they are covered. In Gravitee's April 2026 survey, mean monitoring coverage of deployed agents was 52%, and 54% of organizations had experienced or suspected an AI agent security or data privacy incident in the past 12 months.
That gap is where AI safety stops and AI security starts. EnforceAuth calls it the Authorization Gap: the distance between what an agent is permitted to do and what it should be allowed to do given everything around it.
Consider an illustrative agent that reads a customer record, pulls financial data, queries HR information, downloads 4,000 customer records and calls an unfamiliar external API. Judged one request at a time, every step can pass. Together, they look like data theft.
What Evidence IQ does
– Rebuilds any past decision: identity, delegation chain, data classification, prior behavior, risk signals and the exact policy rule that fired.
– Traces authority to a human: authority can narrow from agent to agent. It can never grow.
– Tests policy against history: replay a proposed policy on real past decisions before it goes live.
– Reacts after ALLOW: when context changes, access is re-evaluated immediately: deny, step up, revoke or quarantine.
Evidence IQ is not a SIEM, an identity provider or a policy engine and does not claim to be the only runtime authorization control. Its focus is the evidence: what was decided, why, and whether it can be proven later. SIEM and behavior analytics alert, and people act later. Policy engines evaluate rules but not the history behind them. Evidence IQ records the decision with that context and can act on it.
Decisions are evaluated locally at the enforcement point, with no live graph lookup in the request path. Evidence IQ includes Authorization Context Intelligence and is part of the EnforceAuth platform. It works with existing identity providers, IGA, SIEM and AI agent frameworks, and runs in SaaS, customer cloud, on-premises, hybrid and air-gapped environments. It governs the next action. It cannot undo one already completed, so it works best with short-lived credentials and enforcement at the tool gateway.
NIST's National Cybersecurity Center of Excellence published a concept paper in February 2026 on identity and authorization for AI agents. EU AI Act obligations for high-risk systems, including logging and human oversight, apply from Dec. 2, 2027. DORA has applied to EU financial entities since January 2025.
Availability: Evidence IQ will be available by the end of the fourth quarter of 2026.
Resources: Read the AI agent security paper: https://enforceauth.com/blog/authorization-context-intelligence-white-paper
Request a technical briefing: https://enforceauth.com/contact
Next week, EnforceAuth publishes its Regulatory Evidence Crosswalk.
Mark Rogge
EnforceAuth
+1 612-868-7193
Visit us on social media:
LinkedIn
Why it matters: As regulators like the EU AI Act and DORA tighten requirements for logging and human oversight of AI systems, the ability to prove why an agent acted is becoming as critical as preventing the action itself. Without tamper-evident authorization records, organizations risk being unable to defend their AI agents’ decisions in audits or after an incident, turning a technical gap into a compliance and liability crisis.




