Enterprise AI Agents Frequently Act Outside Intended Scope
Enterprise Management Associates reports that 65% of enterprises have experienced AI agents operating outside their intended scope, highlighting a critical gap in governance.
A research report titled 'Agents Without Guardrails' reveals that 65% of surveyed enterprises have experienced AI agents acting outside their intended scope. Compiled by Enterprise Management Associates for Cequence Security, the study of 200 technology and security leaders found that 29% of these organizations reported a measurable organizational impact from these incidents.
The findings indicate that AI deployment is outpacing governance. Weak detection capabilities are a primary vulnerability, with 54.5% of organizations requiring hours of manual intervention to contain out-of-scope actions. Furthermore, 47% of respondents lack a reliable agent inventory, and many discontinued pilots leave active credentials and production access in place. Only 32.7% of agents are managed with least-privilege provisioning.
Christopher M. Steffen, vice president of research at Enterprise Management Associates, stated that while most organizations express confidence in their existing policies, a significant gap exists between what is written down and what is actually enforced.