Drata co-founder and CEO Adam Markowitz sees Artificial Intelligence’s rapid adoption creating an unprecedented trust gap that his company is perfectly positioned to solve. Drata empowers security teams to automate compliance, manage risk, and win with trust.
Markowitz said trust is a scarce resource that must be proven continuously. That’s an outstanding issue for most companies, based on an analysis of 2.1 million security questions asked on the Drata platform that found 89% of companies cannot properly answer stakeholder questions about their AI use.
“It’s creating a trust gap bigger than we’ve ever seen,” Markowitz said. “We’re kind of born for this moment, and the past five and one-half years have put us in the position to solve it.”
Comparing AI to past waves
Drata was founded before the AI surge. The company initially addressed issues related to SaaS and cloud proliferation. Markowitz said the patterns are similar in that companies flock to the technology before the full technological cost is realized. Wave-specific companies are formed
The AI agent costs are beginning to roll in, and they’re significant. Markowitz said the need to prove continuous compliance is growing, as seen in patterns gleaned from the millions of questions Drata’s platform handles. One year ago, few questions related to agentic AI. Now, 30% do.
Only 9% can provide proper answers to even surface-level questions, even as regulations are being updated or created to address AI-specific issues.
AI development is happening faster than previous waves, and touches more business areas. And that’s only the beginning. If AI agents are to become more embedded in revenue-generating and customer-facing workflows (Markowitz said a trust bottleneck prevents many companies from moving forward), businesses must sufficiently answer many questions:
- How many agents are you running?
- What processes are they running?
- Who’s building them?
- Which identities are they linked to?
- What are your rules and policies for governing them?
Perhaps a company monitors how close its AI systems get to the theoretical safety perimeter. They feel safe. Have they considered drift that occurs as access or responsibilities change? As the agent forges links, can it cross any lines? Does your system stop or time out? Can you prove any of this?
“A frighteningly small percentage of enterprises we speak to can even answer the question of how many agents they’re running,” Markowitz said. “You can’t govern what you cant see. Right away, those other questions cant be answered.
“You unlock that bottleneck, and you can deliver meaningful outcomes and deliver the promise of AI to the enterprise.”
Investors, boards and, now, regulators are asking what happens if an AI agent makes a mistake. Who’s responsible? How do you know when a mistake happens? Will you know?
There’s plenty at stake.
“Companies that are proactive in putting that electric fence in place and moving faster are going to gain a huge competitive edge,” Markowitz said.
You can only learn so much from the past
Markowitz said past security frameworks can contribute to an AI security foundation, but their scope is limited. Those rules are easier to apply to humans than AI agents, whose speed and scale he said are unprecedented. That pace dictates that AI must be governed by AI; that’s Drata’s approach.
He used the example of a CEO and subordinate having different access levels to the same system. Monitoring that is straightforward.
Add agents into the mix, and they might inherit access levels, but over time create new agents to do new things. They get new access. Maybe it’s a simple agent tracking employee scanners. What if it inherits access to key HR systems to file reports, then creates a new agent?
Stakeholders are asking those questions. They not only expect answers, but they want proof.
“I don’t think there’s anything wrong with the wave,” Markowitz said. “But seeing the pattern and not doing anything about it…”
Select findings from Drata’s The State of GRC in the Age of AI
Drata identifies three compounding failures behind the AI expectation/reality gap:
- Vendors oversold tool capability
- Buyers bought breadth when they needed precision
- Governance never updated to match the speed of adoption
Interesting stats
● 43% of professionals report their current AI tools have actively made their jobs harder. This jumps to 55% for sub-$250 million revenue companies and falls to 36% for larger revenue firms)
● 71% of organizations report that an AI tool used for GRC functions has directly caused a failed audit or lapsed regulatory standard at least once.
● 90% admit some of their AI investments have fallen short of expectations.
● 86% of leaders say current AI tools are not enterprise-ready.
● 87% of professionals lack full visibility into the AI tools employees are using.
● 83% report being at least partially unprepared to handle the coming wave of AI integration.
● 64% prefer targeted agentic AI systems over broad, all-in-one platforms— rising to 70% among risk-focused buyers.
● 63% of GRC teams have absorbed workload increases of at least 20% without a single new hire.
Companies that are most successfully adapting to AI tend to act in four areas:
- They audit what they already have, which means they must have full knowledge of what’s in use across the organization.
- They buy agents, not platforms. They see through vendor overselling, security issues and scalability gaps to ask what specific outcomes an agent owns and who is responsible for them.
- They build trust infrastructure before they need it.
- They reset accountability at the executive level.
