We built Vijil on a single conviction: what gates scaling agent autonomy is not capability, it's trust. While the industry raced to benchmark reasoning and tool use, we argued the binding constraint was evidence whether a security, governance and compliance leader can show and monitor how an agent will behave.
New data says that position is now becoming the mainstream CISO view. Mayfield's 2026 CISO Survey of 60+ security leaders found the constraint on adoption is not money: 72.8% expect budgets to rise in 2027, and 70% report a significant shift from legacy tooling toward AI-native solutions. The money is moving. The agents aren't.
Asked what actually blocks adoption, respondents put trust in outputs and data privacy in a tie for first place — ahead of cost, ahead of integration difficulty.
(Disclosure: Mayfield is an investor in Vijil.)

That gap is visible from our side of the table too. Roughly 85% of organizations are piloting agentic AI; about 5% have agents deployed broadly in production. The distance between those two numbers isn't engineering capacity. It's that nobody can hand the governance and risk committee evidence that the agent will behave under adversarial pressure, consistent with policies and purposes, and that there is a plan to respond when drift happens or novel failures inevitably emerge.
Restraint or prohibition is not a governance control. Neither is optimism based on vibes, demonstrations, and benchmark scores that an agent is safe for a particular business process.. What closes the gap is a measurement that allows teams to verify reliability, security, safety, loyalty to purpose, and failure containment.
Trust is not binary, generic, or static
Trust stalls procurement because most organizations treat it as a vibe rather than a metric. It resolves into three testable things: reliability (correct outputs consistently, without hallucination or logical drift), security (resistance to prompt injection, jailbreaks, and attacks on confidentiality and integrity), and safety (staying inside scope, policy, and compliance boundaries). An agent that scores well on all three for a customer-service workflow may be unfit for claims adjudication. Trust is contextual — which is why generic vendor assurance doesn't clear a CISO's bar.
Visibility: you cannot score what you cannot see
Mayfield's most uncomfortable data point: only 16.7% of organizations have complete visibility into employee AI usage. Five out of six CISOs are governing an estate they can't fully enumerate.

Shadow agents are worse than shadow SaaS: a rogue subscription leaks data, but a rogue agent holds credentials and takes actions on your behalf. Assessment starts with an inventory. Vijil Discover scans cloud VPCs, on-prem Kubernetes and VMware, endpoints, browser model use, and source repositories to build a registry of every agent — sanctioned and shadow — with fingerprinting and identity attribution. Vijil Diamond then tests each one against hundreds of scenarios built for that agent's context and persona, and returns a composite Trust Score across reliability, security, and safety. That score is the artifact a governance board can sign against.
Enforce: the same policy, running in production
A pre-deployment score decays the moment the agent meets real traffic. Vijil Dome takes the policies the agent was evaluated against and enforces them at runtime- filtering harmful inputs and outputs, detecting anomalies, and blocking policy violations in milliseconds, through layered pattern matching, classifiers, embeddings, and LLM-based checks. Critically, it monitors and logs. Every decision, every enforcement action and policy violation becomes an audit record.
That matters because Mayfield's respondents were explicit about what wins a deal: security efficacy, governance, and auditability lead vendor evaluation criteria.

Maintain: trust degrades
New attacks emerge. Models get updated. Workflows expand. A Trust Score from March is a historical document by September. Vijil Darwin learns from production telemetry — real attacks, edge cases, blocked violations — and proposes targeted improvements to agent instructions, configuration, and code. Every blocked attack becomes a training signal to improve resilience. The loop is evaluate, protect, improve, re-evaluate.
The mandate
Mayfield's survey found CISOs strongly prefer measurable pilots over vendor pitches, with success criteria, data boundaries, and human controls defined before evaluation begins.

A pilot without a defined pass mark is a demo with better lighting. Set objectives and define risk thresholds, measure agent resilience and trustworthiness before and after hardening, enforce trustworthiness in production, and re-establish trust through targeted improvement as conditions change and threats evolve. Trust stops being the thing that blocks the agent and becomes the thing that ships it.
Survey data: Mayfield, "Trust Is the Moat: The CISO's AI Mandate in the Agentic Era",


.png)
