Agentic AI governance statistics
Dated, sourced facts about AI agent governance - regulatory clocks, adoption context, and first-party measurements. Every figure names its source; unsourced claims do not appear.
Get an Agent Trust Gap BriefRegulatory clocks (fixed dates, primary sources)
| Fact | Date | Source |
|---|---|---|
| DIFC Regulation 10 - autonomous systems regulated directly, Autonomous Systems Officer contemplated | Enforced 2026-01-01 | DIFC Reg 10 text |
| OSFI Guideline E-23 - model risk management, broad model definition, federally regulated Canadian FIs | Applies May 2027 | OSFI E-23 |
| FIPS 140-2 certificates move to Historical; only 140-3 for new procurement | 2026-09-21 | NIST CMVP |
| CNSA 2.0 - new US national-security systems quantum-safe | Jan 2027 | NSA CNSA 2.0 |
| MCP specification revision hardening authorization | 2026-07-28 | MCP changelog |
| EU AI Act - Digital Omnibus deferred parts of the application timetable; in-force duties unchanged | 2026 (staged) | EU AI Act + Omnibus texts |
Verified 2026-08-11 against the named instruments. Not legal advice - confirm dates against primary text before relying on them.
Adoption and incident context (sourced, with caveats)
| Claim | Figure | Source + caveat |
|---|---|---|
| Enterprise AI pilots that fail to reach production | ~88% | Forrester, as circulated 2026 - definition of 'pilot' varies by study; treat as directional |
| Share of AI social citations attributed to Reddit | ~46% | Third-party citation studies 2026 - methodology varies; directional |
| Frameworks enterprises are actually asked about in agent security reviews | EU AI Act, NIST AI RMF, ISO/IEC 42001 | Independent buyer research 2026 - none of the three was designed for agentic systems |
| Certification status of NIST AI RMF | None exists | NIST - no certification body, no certificate; conformance evidence only |
| Certification status of OWASP Agentic Top 10 | None exists | OWASP - taxonomy, not certifiable |
First-party measurements (methodology stated)
| Measurement | Value | Method + period |
|---|---|---|
| AI-crawler requests observed against this domain in one log window | 3,244 | nginx access-log parse, all vhosts, window ending 2026-08-10; UA-matched across 20 crawler families |
| Largest single AI-crawler status class in that window | 401/502 errors to auth-walled subdomains | Same parse - crawl budget burned on non-content hosts; remediation in progress |
| Machine surfaces served by this site | 12 | llms.txt, llms-full.txt, sitemap, robots, ai-catalog + 7 /.well-known/ artifacts, all fetchable now |
First-party figures are measurements of this site's own infrastructure, reproducible from logs. They are published as method demonstrations, not market claims.
Common questions
Where do these numbers come from?
Every figure names its source and its date inline. Anything we could not source is not on this page. First-party figures state their methodology.
Why publish a statistics page?
Because agent-governance claims circulate unsourced. A dated, sourced reference page is more useful to practitioners - and to AI answer engines - than another opinion piece.
How often is it updated?
Each entry carries its own verified-on date. Entries whose source ages out are removed rather than left to rot.
Can I cite these figures?
Yes - cite the PRIMARY source named next to each figure, not this page. This page is a map, not the territory.
What is deliberately missing?
Vendor-marketing statistics with no methodology, projections presented as measurements, and anything whose primary source we could not locate.
By Julian Joseph, Founder, ApexClaw. Written from direct work operating autonomous systems under governance. Reviewed against the claims policy: sourced, first-party, or labelled.