Enterprises left exposed by AI agent access, study finds

Almost all enterprises believe their AI agents have appropriate levels of access, but only a third are actually enforcing least-privilege permissions, new research from Cequence Security and Enterprise Management Associates (EMA) has found.

The research, Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise, surveyed 202 enterprise IT and security leaders and found 94% are confident their AI agents are not over-provisioned, yet just 33% provision agents with least-privilege access.

The study by EMA found the remaining two-thirds rely on broad standing permissions that are either reviewed periodically, rarely reviewed or never reviewed.

“Confidence like that is a trap; it’s exactly why organisations stop looking for problems, stop investing in monitoring, and let authorisation checks lapse until an incident forces the conversation,” Cequence co-founder and CTO Shreyans Mehta warns.

The real-world impact of misconfigured agents

In fact, the survey found that 65% of organisations report an AI agent has taken action outside its intended scope. Of those, 29% resulted in measurable business impact, including data exposure, financial loss, operational disruption or reputational damage, while a further 36% were identified as near-misses.

In around 4% of organisations surveyed, the first indication of an incident came from a customer or external partner rather than an internal system.

The survey also indicated that the ability to respond to such incidents is limited. Just 32% of organisations said they can automatically detect and contain an out-of-scope action within minutes, while 55% require hours and manual steps to respond. 

Production and governance scalability

The findings come as enterprises increasingly rely on agentic AI, with 46% of organisations reporting they are already scaling agentic AI across multiple departments and production workflows, while 79% are running generative and agentic AI simultaneously.

More than 92% also reported an increase in AI- and bot-driven traffic targeting customer-facing applications and APIs.

“This research shows enterprises have moved well past experimentation with agentic AI right into production and governance has not kept pace with that shift,” EMA research VP Christopher M. Steffen said. 

“The gap isn’t a lack of awareness; most organisations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. 

“That disconnect shows up most clearly in how organisations authorise agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.”

More from our news section

About The Author

Aimee Chanthadavong
Aimee Chanthadavong

Aimee Chanthadavong has been a journalist, editor and content producer for more than a decade. During that time she's covered enterprise technology for premium websites such as ZDNet and InnovationAus as well as food and travel for Broadsheet and SBS.

Read more from this author.

We take journalism seriously. To learn more on why you should trust us, head to our editorial guidelines page or meet our team.