Summary is AI-generated, newsdesk-reviewed
  • 94% of firms confident in AI agent scope, yet only 33% ensure least-privilege access.
  • 65% experienced AI agents acting beyond scope, with 29% causing significant business issues.
  • 46% of organisations scaling AI across departments, 92% notice increased AI traffic.

New findings from Cequence Security and Enterprise Management Associates (EMA) reveal significant challenges in AI governance among enterprises.

Despite 94% of IT and security leaders expressing confidence in the appropriate scope of their AI agents, only 33% have implemented least-privilege access. The majority operate with broad standing permissions that are occasionally reviewed, indicating a governance gap as AI agents increasingly influence business operations.

Broad standing permissions

The disconnect between perceived and actual governance is manifesting in operational incidents. Of those surveyed, 65% have experienced AI agents acting beyond their intended scope, with 29% reporting significant impacts such as data breaches or financial losses. Furthermore, only 32% of organizations can swiftly detect and contain unauthorized agent actions, while 55% require several hours and manual resources to respond.

Additionally, in about 4% of cases, external entities identified the issue before internal systems did. This highlights a critical oversight in AI governance capabilities.

Customer-facing applications

The report underscores that current governance measures are lagging behind the rapid deployment of agentic AI across various sectors. A notable 46% of enterprises are expanding AI use across multiple departments, and 79% run generative and agentic AI concurrently. Moreover, 92% of organizations have seen an uptick in AI-generated traffic targeting their customer-facing applications and APIs.

A further analysis reveals that only 34% assess AI agent authorization precisely when the agent attempts an action. Most rely on outdated permissions set at the initial provisioning stage, risking prolonged access that exceeds the agent’s original task.

Challenges in AI pilot management

Mismanagement of AI agents not reaching production further complicates the issue

Mismanagement of AI agents not reaching production further complicates the issue. About 31% of AI pilots have been paused, discontinued, or abandoned, yet many retain live system access, posing ongoing risks. Alarmingly, 14% of organizations allow unrestricted connection of AI agents to external tools and data sources through the Model Context Protocol (MCP). Of those imposing restrictions, less than half actively maintain and audit their approved connections list.

Christopher M. Steffen, VP of Research at EMA, remarked: “This research shows enterprises have moved well past experimentation with agentic AI right into production and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organizations have policies in place and express real confidence in them.”

Shreyans Mehta, Co-founder and CTO at Cequence, pinpointed confidence as a major issue, noting that it leads to a lack of vigilance in monitoring and authorisation enforcement. This oversight is precisely the vulnerability Cequence aims to address by offering security teams real-time insights and immediate enforcement capabilities.

For further insights, join Christopher M. Steffen and Randolph Barr, Chief Information Security Officer at Cequence, in their upcoming webinar titled “Agents Without Guardrails.”

In case you missed it

How are new technologies reshaping casino surveillance and security?
How are new technologies reshaping casino surveillance and security?

Casinos are tasked with monitoring vast gaming floors, cashier cages, and access points. The market for casino security and surveillance demands software and hardware that provide...

HID boosts mobile access adoption for digital security
HID boosts mobile access adoption for digital security

HID, a pioneer in trusted identity solutions, announces new enhancements that help organisations fast-track their mobile access adoption as part of their broader digital transforma...

March Networks powers Fifth Third bank's security
March Networks powers Fifth Third bank's security

The challenge: Fifth Third Bank is one of America’s largest and fastest-growing financial institutions, with more than 1,500 financial centres and approximately 80 high-rise,...