Threat Research

Three in Four CIOs Can't See Their Agents in Real Time. The Failure They Fear Lives in That Blind Spot.

Two numbers from Dataiku's survey of 600 CIOs describe one blind spot: ~41% fear a data or privacy failure most, and ~75% can't fully monitor their agents in real time. The failure they fear lives on the agent-to-tool wire — the layer platform governance can't see across a multi-provider estate.

CheckedAgent

·

Key takeaways

  • In Dataiku's survey of ~600 large-enterprise CIOs, ~75% cannot fully monitor their AI agents in production in real time — while ~87% already have agents embedded in business-critical workflows.

  • The failure CIOs fear most — data/privacy, named by ~41% as the likeliest AI-crisis trigger — happens at the agent-to-tool layer, exactly the layer most cannot watch in real time.

  • Consolidating onto one governance platform can't close it: ~81% of these CIOs expect 2+ LLM providers in 2026, so agent activity crosses platforms, clouds, and third-party MCP tools by default.

  • Platform governance watches the inside of a platform; the missing visibility sits at the wire — the agent-to-tool traffic between platforms. Watching the wire closes the runtime tool-call part of the gap (not model explainability or platform telemetry).

  • With ~70% of CIOs expecting AI audit requirements within a year, real-time wire inspection written to a tamper-evident record is what makes 'we monitor our agents' auditable.

Two numbers from Dataiku's survey of 600 large-enterprise CIOs, taken together, describe a single problem more sharply than either does alone. In the same research, 41% of CIOs named data or privacy failure as the single most likely trigger of an AI-related crisis — the outcome they fear most. And roughly 75% admitted they cannot fully monitor their AI agents in production in real time.

Read those side by side and the question writes itself. The failure CIOs are most afraid of is the one they can least see coming. Three in four cannot watch their agents in real time, and the thing they are most worried those agents will do is exactly the kind of thing that would happen in the window they cannot watch. The interesting question is not whether the gap is real — the CIOs themselves report it — but where the failure they fear actually happens, and whether that is where anyone is looking.




Left: around 41% of CIOs fear a data or privacy failure most. Centre: an arrow to the bidirectional agent-to-tool wire, where such failures happen. Right: a shaded blind spot over that same wire, where around 75% cannot monitor agents in real time. The feared failure and the blind spot converge on the same layer. Source: Dataiku / Harris Poll.

The failure CIOs fear most lives on the agent-to-tool wire — the exact layer three in four can't watch in real time.




Two numbers, one gap

It is worth grounding the figures before building on them. They come from research Dataiku conducted with The Harris Poll across roughly 600 CIOs at large enterprises, spanning nine markets, in late 2025. This is commissioned research from a company that sells AI-governance tooling, so the framing has a commercial tilt and the numbers are best read as directional rather than as neutral benchmarks. But the direction has been corroborated widely, and the specific figures that matter here are hard to wave away.

Alongside the 75% monitoring gap and the 41% data-privacy fear, the survey found that around 87% of these CIOs already have AI agents embedded in business-critical workflows. That is the detail that turns the gap from uncomfortable to urgent. If agents were confined to experiments and side projects, limited real-time visibility would be a tolerable gap to close later. But the agents are already load-bearing — inside the workflows the business depends on — and most of the leaders responsible for them concede they cannot see, in the moment, what those agents are doing. Adoption is in production; observability is not.

Where the failure actually happens

To close a visibility gap you have to know which layer it lives on, and this is where most of the conversation goes wrong. "Monitoring an agent" gets pictured as a dashboard of prompts and responses, or a model-level explainability view. Those are useful, but they are not where a data or privacy failure occurs.

A data or privacy failure in an agent happens at the moment the agent touches a tool. It reads a record it should not have surfaced, or a document it retrieves carries a planted instruction that steers it toward compiling and sending data outward, or a tool response returns far more than the request asked for and the agent acts on all of it. Each of these lives in the agent-to-tool traffic — the requests an agent sends to its tools and, crucially, the responses that come back. That traffic is precisely the layer most organisations have no real-time instrumentation for. The model dashboard does not see it; the identity system does not judge it; the audit log, if there is one, records the outcome long after the fact. The 75% figure is, in practical terms, a statement about that specific blind spot.

Why platform governance doesn't close it

The reflexive answer to a monitoring gap is to consolidate: put the agents, the tools, and the telemetry inside one governance platform where everything can be watched together. It is a coherent answer, and it is the answer a governance-platform vendor is naturally inclined to give. It also has a structural limit the same survey exposes.

Around 81% of these CIOs expect to run more than one large-language-model provider in 2026. Their agents already span multiple platforms, multiple clouds, and a growing set of third-party tools reached over open protocols like MCP. A platform that monitors what happens inside itself cannot, by construction, see the tool calls an agent makes to everything outside itself — and "outside itself" is where a rising share of agent activity now lives. Platform-internal telemetry is real and worth having, but it covers the inside of one box. The 75% gap is largely made of everything between the boxes.

Picture the shape of it. An agent orchestrated on one vendor's platform calls a model hosted on a second, then reaches out over MCP to a third-party tool that neither vendor operates — a document store, a CRM, a search service. The governance platform can log that its agent initiated something; it cannot see what the third-party tool sent back, because that exchange happens on a connection it does not sit on. If the response carried a sensitive record or a planted instruction, the failure has already entered the agent's context before anything the platform can observe. Multiply that across the tool ecosystem a production agent touches and the monitoring gap is not an edge case — it is the normal operating condition of a multi-provider deployment.




Three boxes — an orchestration platform holding the agent, a second provider hosting the model, and a third-party tool reached over MCP. A dashed boundary marks what platform governance can see, drawn only around the first box. The tool's response, carrying a sensitive record or planted instruction, returns on a connection outside that boundary, marked as the unseen wire.

Platform governance watches inside one box. In a multi-provider estate, the agent's tool calls cross between boxes — where the monitoring gap lives.




That is the layer distinction worth taking away: platform governance watches the platform; the missing visibility sits at the wire, on the agent-to-tool traffic that crosses between platforms. For the roughly four in five CIOs already committed to a multi-provider future, a single-platform monitoring story does not reach the place the failure happens.

For completeness, Dataiku itself now ships MCP connectors and an agent-management capability — it is a governance platform moving to meet this demand, not a runtime proxy on the wire. That is a real and reasonable product direction; it is simply a different layer from the one this post is about, and naming the difference is the point rather than a criticism.

The layer you can actually close

So what does close the part of the gap that lives on the wire? Watching the wire itself — inspecting the agent-to-tool traffic in real time, in both directions, wherever the agent runs and whatever platform it runs on.

This is the layer CheckedAgent is built for. CheckedAgent is an inline Agent Detection and Response proxy that sits on the connection between an agent and the tools it calls and inspects every message in both directions, classifying each ALLOW, QUARANTINE, or BLOCK in real time — and correlating each tool response with the request that prompted it, so a clean request followed by a data-leaking or poisoned response is caught as one event rather than missed as two unrelated ones. Because it sits on the wire rather than inside a single platform, it gives the same real-time visibility across a multi-provider, multi-cloud estate without forcing everything onto one governance platform first.

It is worth being precise about scope, because overclaiming here would be its own kind of dishonesty. This does not close the entire 75% gap. It closes the part of it that is runtime tool-call visibility — the layer where the feared data and privacy failures actually happen. Model-level explainability and platform-level operational telemetry are separate problems with separate owners; watching the wire is the piece most organisations are missing entirely, and it is the piece that maps directly onto the failure CIOs said they fear most.

The clock the CIOs are already watching

There is one more figure worth pairing with the monitoring gap. Around 70% of the surveyed CIOs expect formal audit requirements for AI within the next year. Whatever the exact timing, that is the regulatory direction they themselves anticipate — and it changes what "monitoring" has to mean. It is no longer enough to observe agent behaviour in the moment; the observation has to be recorded as evidence that survives scrutiny. Real-time inspection of agent-to-tool traffic, written to a tamper-evident record, is what turns "we monitor our agents" from an assertion into something an auditor can actually check. It also sits squarely in the direction the EU AI Act's record-keeping expectations are pushing as its high-risk record-keeping obligations approach — deferred to 2 December 2027 by the Digital Omnibus, but coming nonetheless, and not a compliance guarantee so much as plainly the way the wind is blowing.

The question for your next AI risk review

Dataiku's headline is the 75%. The useful takeaway is a question to bring to the next AI risk review, and it is a specific one: where is our agent-to-tool traffic visible in real time — across every platform and provider our agents actually use?

If the honest answer is "inside our main AI platform, and nowhere else," then the four-in-five multi-provider future the same CIOs describe is already outrunning the monitoring. The failure they fear most lives in exactly that unwatched space, on the wire between the agent and its tools. Closing the part of the gap that can be closed starts with instrumenting the layer the dashboard never showed them.

CheckedAgent is an Agent Detection & Response (ADR) platform for MCP and agent-to-tool traffic: an inline proxy that inspects the messages between AI agents and their tools in both directions, classifying every one ALLOW / QUARANTINE / BLOCK in real time. It complements platform-level governance and identity controls; it does not replace them.

— Request a demo

Every Agent action.
Checked.

30-minute walkthrough with a security engineer — not a sales rep. We'll show the full pipeline, run your suspected attack patterns through it, and answer the questions your auditor is already asking.