AI Agent Governance Gap Leaves 65% of Firms Vulnerable
Cequence Security and EMA research reveals a critical disconnect between enterprise confidence in AI agent security and actual least-privilege implementation.
Research from Cequence Security and Enterprise Management Associates (EMA) reveals a significant gap between enterprise confidence and actual security practices regarding agentic AI. While 94% of IT and security leaders believe their AI agents are properly scoped, only 33% actually implement least-privilege access.
This disconnect has led to tangible failures, with 65% of surveyed organizations reporting AI agents taking actions outside their intended scope. Nearly one-third of these incidents resulted in measurable business impacts, including data exposure or financial loss. The study further notes that 31% of abandoned AI pilots leave live credentials active, and only 34% of organizations verify authorization at the moment an agent attempts a specific action.
Christopher M Steffen of EMA noted that enterprises have moved agentic AI into production faster than governance has evolved. Shreyans Mehta of Cequence characterized high confidence in existing governance frameworks as a trap that causes organizations to stop monitoring for problems and allow authorization checks to lapse.