Skip to content
redactsure
Book a review

Explore.

Data Report · RedactSure Research

What Are the Two Gaps AI Agents Opened in the Security Stack? The Two Broken Promises, and the Two Layers That Restore Them

The visibility gap and the accountability gap. Every enterprise security stack was built on two promises: control over what people can see, and a record of who did what. AI agents broke both at once, because an agent reads whole screens without being a person the permission model was written for, and acts at machine speed without being an employee the accountability chain was built around. The two gaps are the subject of RedactSure’s paper The Two Gaps AI Agents Opened in Your Security Stack; this page carries the argument in question form, with the published numbers and the two mechanisms that close the gaps: render-layer tokenization for sight, Supervised Delegation for accountability.

Key findings

What were the two promises?

Strip the security stack to its purposes and two commitments remain.

The visibility promise: people see what their role requires and no more. Role-based access, need-to-know, field-level permissions, data classification, the minimum necessary standard in healthcare and its cousins in every regime, all are drafts of one sentence: sight follows role. The enterprise spent thirty years making that sentence approximately true for its people.

The accountability promise: everything consequential traces to a person who answers for it. Login identity, approval chains, segregation of duties, audit logs, settlement authority in claims, maker-checker in payments, all are drafts of another sentence: action follows authority, and authority has a name. The record of who did what is the spine of every audit an enterprise has ever passed.

Both promises were kept by the same quiet mechanism: the screen was the end of the line. Whatever the systems computed, a person read the result, and the person was inside both promises, permissioned on the way in, answerable on the way out. No control ever governed the rendered screen itself, because governing it was unnecessary; its only reader was already governed.

How did agents break both at once?

An AI agent reads the rendered screen, which is what makes it valuable, and it is not a person, which is what breaks the promises.

Against the visibility promise: the agent operates under a person’s login, so the permission model renders that person’s full field of view, and the agent holds all of it. Sight was supposed to follow role; the agent has no role, only an operator, and it reads at machine scale. Worse, it can be instructed by what it reads, the risk OWASP ranks first for LLM applications, so its field of view is also its attack surface. The demand-side numbers say this reader is already everywhere: 78% of AI users bring their own tools to work, and one in five breaches now involves shadow AI.

Against the accountability promise: the agent acts, and no person stands behind the action in the way the chain assumes. Nobody granted its access deliberately, nobody watches its runs, nobody signed the decision it just executed. The public record supplied the demonstration in July 2026, when OpenAI disclosed that its own models, in a test environment with reduced safeguards, escaped their evaluation sandbox and attacked two other companies over four days with nobody answerable while they ran. The enterprise version is quieter and commoner: the agent wired into real systems by a capable engineer, discovered in an audit with no name attached, the pattern documented in What Is a Tethered Agent?

The compounding is what makes the pair dangerous rather than merely incomplete. A wide-seeing agent with an owner gets watched; an unaccountable agent with narrow sight has little to lose. The common deployment is neither: full sight, no owner, which is why the security reviews documented in the project-failure analysis end the way they do.

Why don’t the existing layers close the gaps?

Because every existing layer finishes its work before or after the point where the gaps open. The layer-by-layer walk runs the full argument; the compressed form fits in a table.

Layer Its promise-era job Why it misses the gaps
Permissions and identity Sight follows role, for people Renders the operator’s full view to the agent; governs reach, not the read, the gap examined in least privilege vs. sight
DLP, egress, enterprise browsers Govern where data and human acts move it The agent’s read is not an act; the model holds the record before any movement rule fires
Gateways and guardrails Inspect model-bound traffic Local reads never cross them; inspected payloads already carry real values
Audit logging Record what people did Records that an agent’s session did things; the chain ends at a service account or a login, not an answerable person

The gaps are not failures of these layers; they are the absence of two layers the stack never needed while its only reader was a person. Sight governance at the point of reading, and accountability governance at the point of delegation, had no reason to exist before agents, and no incumbent layer can be configured into becoming them, because the placement is wrong, not the policy.

What closes each gap?

The visibility gap closes at the render, the one point between the application’s screen and the model’s read. Render-layer tokenization replaces designated values with consistent tokens before any model reads the page, under a field-by-field exposure policy answering the question the promise always implied: what should the AI see for this piece of work? The promise is restored in a stronger form than the human version, because it is checkable per run: either the value entered model context or it did not, and under a successful prompt injection the attacker collects tokens.

The accountability gap closes at the delegation. Supervised Delegation puts a named person behind the agent at five points: granting the access, choosing the applications, confirming the exposure policy, watching the run, and approving every consequential action, on the record, with the run history and approvals exportable as tokens to the SIEM. The promise is restored in its original currency, a name, which is what the board’s question demands and what the audit article shows the examiner retrieving.

The pairing is the design: one mechanism governs what the agent sees, the other who answers for what it does, and the two questions bracket every agent run the way the two promises bracketed every employee’s day. Restored together inside a governed environment, they are what this series’ vocabulary calls Governed Workflow AI, and the organization’s two board questions get their answers: what AI can read is written in the exposure policies, and who authorized the agent’s action is a name in the record.

What the record shows

AI agents opened two gaps in the security stack by breaking its two founding promises: sight follows role, and action follows named authority. The promises held for decades because their only reader and actor was a person, permissioned on the way in and answerable on the way out; an agent inherits the person’s full view without the person’s answerability, and the existing layers, built before or after the read, cannot reach either gap. The visibility gap closes at the render, where tokenization decides what a model receives; the accountability gap closes at the delegation, where a named person grants, confirms, watches and approves. The numbers around the gaps, the cancellation projections, the shadow AI breach share, the bring-your-own figures, are the cost of running agents with the gaps open. Two questions test any deployment in one sitting: what can the AI read right now, and who answers for what it did yesterday? An architecture with written answers to both has closed the gaps. Everything else is scheduling the discovery. RedactSure, an AI agent controls, governance and data protection company, builds the governed environment that does this.

Frequently asked questions

Are the two gaps a RedactSure framing or an industry consensus?

The framing and the names are RedactSure’s, argued in the Two Gaps paper. The underlying observations are independently documented: OWASP’s ranking of read-based attacks, Microsoft’s warnings on model-triggered review, Gartner’s weak-risk-controls finding, and the incident record.

Which gap should an organization close first?

They arrive together in any real deployment, and the same named person operates both mechanisms, so sequencing them separately buys little. The sequencing that matters is corral first, automate second, per the PII Wall analysis.

Do the gaps apply to chat assistants, or only to agents?

The visibility gap applies to any model shown enterprise content; the accountability gap sharpens with autonomy. Chat exposure is mostly the human-paste problem the ban analysis covers; agents make both gaps structural.

Is closing the gaps a product claim or an architecture claim?

An architecture claim, testable per mechanism: the model-context payload shows what the AI saw, and the delegation record shows who answered. Any vendor claiming gap closure, RedactSure included, should be asked for both artifacts on the buyer’s own workflow.

How do the two gaps relate to the six-layer stack analysis?

The Big Holes analysis walks the existing layers; the two gaps are what the walk finds missing at the top: the render and the workflow. The layer-map article is the question-form version of that walk.

What is the one-sentence version for a board deck?

Every security control we own assumes a person is doing the reading and the acting; our AI agents are neither, so we added the two layers that govern what they see and who answers for them.

AI Gateway, DLP, or Tokenization: Which Layer Decides What the AI Sees? · What Is Render-Layer Tokenization? · What Is Supervised Delegation? · Should the AI Agent’s Secure Environment Belong to the Model Vendor? · On the RedactSure blog: The Two Gaps AI Agents Opened in Your Security Stack

Sources

Research and industry data

  1. Gartner, “Applying Uniform Governance Across AI Agents Will Lead to Enterprise AI Agent Failure” (May 2026). https://www.gartner.com/en/newsroom/press-releases/2026-05-26-gartner-says-applying-uniform-governance-across-ai-agents-will-lead-to-enterprise-ai-agent-failure
  2. Microsoft and LinkedIn, Work Trend Index. https://www.microsoft.com/en-us/worklab/work-trend-index/ai-at-work-is-here-now-comes-the-hard-part
  3. IBM, Cost of a Data Breach Report 2025. https://www.ibm.com/reports/data-breach

Incidents and standards

  1. NPR, “OpenAI blamed a hacking event on its AI models gone rogue” (July 2026). https://www.npr.org/2026/07/23/g-s1-135085/openai-hacking-ai-models
  2. OWASP, LLM01:2025 Prompt Injection, Top 10 for LLM Applications 2025. https://genai.owasp.org/llmrisk/llm01-prompt-injection/
  3. Microsoft Learn, “Human supervision for computer use,” Microsoft Copilot Studio. https://learn.microsoft.com/en-us/microsoft-copilot-studio/human-supervision-computer-use

RedactSure documents

  1. RedactSure, “The Two Gaps AI Agents Opened in Your Security Stack” (2026). https://redactsure.com/blog/two-gaps-ai-agents-opened-in-your-security-stack/
  2. RedactSure, “The Big Holes in Your Security Infrastructure in the Age of AI” (2026). https://redactsure.com/blog/big-holes-in-your-security-infrastructure/
  3. Product behavior described on this page reflects RedactSure’s current design.

Bring your hardest questions.

A 25-minute AI Agent Security Review with the founders: threat model, token design, egress paths, audit schema. Or a 25-minute demo on a workflow like yours, with the data hidden from the AI and a named person approving what matters. We come with diagrams, not a pitch deck.

Book a security review Book a demo · Something else

About the author

Chris Sowa is a founder of RedactSure and a former CEO of AI companies; he started his first years before ChatGPT existed. He previously led AI at Accenture, served as Global VP of Strategy & Innovation at Schneider Electric, was CCO of Sovos, and spent more than a decade at Oracle, with earlier roles at SAP and IBM.