39 views
58 minutes ago

94% of enterprises say their AI agents aren’t over-privileged. Only 33% have checked

Shreyans Mehta, Co-founder and CTO at Cequence.
Shreyans Mehta, Co-founder and CTO at Cequence.

A survey of 202 IT and security leaders by Cequence Security and Enterprise Management Associates found two thirds of organisations running agentic AI on standing permissions, with 65% reporting an agent that acted outside its intended scope.

Research published on 8 September by Cequence Security and the analyst firm Enterprise Management Associates found that 94% of enterprise IT and security leaders are confident their AI agents hold no more access than they need, while only 33% actually provision those agents with least-privilege access. The remaining two-thirds run on broad standing permissions that are reviewed periodically, rarely reviewed, or never reviewed at all.

The consequences are already showing up in production environments. Among the organisations surveyed, 65% have had an AI agent take an action outside its intended scope, and 29% recorded measurable business impact from those actions, including data exposure, financial loss, operational disruption or reputational damage. A further 36% caught a near-miss before damage occurred. In roughly 4% of organisations, the first indication that something had gone wrong came from a customer or an outside partner rather than from an internal system.

Detection speed is a related weakness. Only 32% of respondents can identify and contain an out-of-scope agent action within minutes through automated means, while 55% require hours and manual intervention.

The research also examined when authorisation is actually evaluated. Only 34% of organisations assess an agent’s authorisation at the moment it attempts a specific action, with the majority relying on periodic policy reviews or permissions set once at provisioning and never revisited. Abandoned projects compound the exposure: 31% of agentic AI pilots have been paused indefinitely, discontinued or abandoned, many of them real deployments whose credentials were never withdrawn. On external connectivity, 14% of organisations allow agents to reach outside tools and data sources through the Model Context Protocol without restriction, and among those maintaining an approved list, just 49% have a dedicated team auditing it regularly.

Deployment is no longer experimental, which is what gives the governance shortfall its weight. Some 46% of organisations report scaling agentic AI across multiple departments and production workflows, 79% are running generative and agentic AI simultaneously, and more than 92% have seen an increase in AI and bot-driven traffic against customer-facing applications and APIs.

Christopher M. Steffen, CISSP, CISA, VP of Research at EMA, said: “This research shows enterprises have moved well past experimentation with agentic AI right into production, and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organisations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved.”

Shreyans Mehta, Co-founder and CTO at Cequence, pointed to the confidence figures as the finding that concerned him most. “Confidence like that is a trap; it’s exactly why organisations stop looking for problems, stop investing in monitoring, and let authorisation checks lapse until an incident forces the conversation,” he said.

EMA surveyed IT and security leaders at organisations with 1,000 or more employees that are deploying or evaluating agentic AI. The sample spans North America and Europe, the Middle East and Africa, across technology, financial services, healthcare and manufacturing.

Leave a Reply

Welcome to

By signing or creating an account you agree with our Code of conduct & Privacy policy