New Cequence & EMA Research: 94% of Enterprises Trust Their AI Agents Aren’t Over-Provisioned Yet Only 33% Actually Enforce It

Editorial Brief
At a glance: AI-assisted overview, optimised for journalists, search & news aggregators

Research by Cequence Security and Enterprise Management Associates reveals that while 94% of enterprises believe their AI agents have appropriate access, only 33% enforce least-privilege access. This gap in governance has led to incidents where AI agents act outside their intended scope, causing business impacts such as data exposure and financial loss. The findings highlight the need for improved governance as enterprises rapidly deploy AI across departments, often without adequate oversight of agent actions and authorisations.

EDITORIAL INSIGHT: Context, industry insight and market perspectives of this news story

As enterprise adoption of agentic AI accelerates, the gap between policy and practice around access management is emerging as a critical operational risk. While most organisations express high confidence in their AI governance, the research highlights a disconnect between stated controls and actual enforcement, with many relying on periodic reviews rather than real-time oversight. This misalignment is not merely theoretical, as a significant proportion of enterprises are already experiencing incidents where AI agents act beyond their intended scope, sometimes with tangible business consequences.

For IT and security leaders, the findings serve as a timely reminder that governance frameworks must evolve alongside deployment scale and complexity. As more organisations move from pilot projects to production workflows, the risks associated with unmanaged credentials, insufficient authorisation checks, and external connectivity become harder to ignore. The report’s data points to the need for automated, continual monitoring and prompt response mechanisms to ensure that AI agents operate within approved boundaries, especially as regulatory scrutiny and stakeholder expectations around AI security continue to grow.

Story Ideas
Technology

Abandoned AI Projects: A Security Threat

The research reveals that a significant number of abandoned AI projects leave behind live credentials, posing a security risk. This story can delve into the implications for cybersecurity and what companies need to do to mitigate these risks.

Target audience
technology, trade-industry
Story potential
6/10
Consumer impact

The Reality of AI Overconfidence in the Workplace

The disconnect between perceived and actual AI governance in enterprises suggests a widespread overconfidence that can lead to significant business impacts. This angle can examine how this overconfidence affects consumer trust and what companies are doing to safeguard customer data.

Target audience
consumer-lifestyle, business-finance
Story potential
7/10
Press Release

LONDON, UK — 1 September, 2026

Nearly every enterprise believes its AI agents are properly scoped but only a third have actually made sure of it. New research from Cequence Security, the leader in application, API, and agentic AI protection, and Enterprise Management Associates (EMA) found that 94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need, yet only 33% actually provision agents with least-privilege access. The remaining two-thirds run on broad standing permissions that are reviewed periodically, rarely reviewed, or never reviewed at all. The full report, Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise, is available for download at 

https://bit.ly/4cKxvBz.

 

The gap between confidence and practice is already showing up in production, not as a theoretical risk, but as incidents enterprises are living with right now. Among the organisations surveyed:

  • 65% have experienced an AI agent take an action outside its intended scope, including 29% with measurable business impact such as data exposure, financial loss, operational disruption, or reputational damage. Another 36% caught a near-miss before it caused damage.
  • Only 32% can detect and contain an out-of-scope agent action within minutes through automated means; 55% need hours and manual steps to respond.
  • In approximately 4% of the organisations surveyed, the first sign of trouble came from a customer or outside partner, not an internal system.

 

The findings point to one clear story. Governance has not kept pace with the speed of agentic AI deployment, and that gap is showing up at every stage of the agent lifecycle, from how agents are provisioned, to how their actions are authorised, to how they are decommissioned once a pilot ends. Other key findings from the report include:

 

Enterprises Have Moved Past the Pilot Stage

The scale of deployment makes the gap more urgent. 46% of organisations report they are already scaling agentic AI across multiple departments and production workflows, and 79% are running generative and agentic AI simultaneously. Further, more than 92% report an increase in AI and bot-driven traffic targeting customer-facing applications and APIs. 

 

Authorisation is Checked at the Wrong Time, Or Not At All

That governance gap extends to how access is enforced the moment an agent acts. Only 34% of organisations evaluate an AI agent’s authorisation at the moment it attempts a specific action. The majority rely on periodic policy reviews or standing permissions set once at provisioning and never revisited, meaning an agent’s access can quietly outlive the task it was originally granted for, and keep working long after anyone signed off on it.

 

Abandoned Pilots Are Leaving Live Credentials Behind

Additionally, there’s an increasing risk in how enterprises manage agents that don’t make it to production. 31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned. Many were real deployments with real system access and credentials that were never cleaned up. Every abandoned pilot with live credentials is an exposure nobody is actively watching.

 

External Connectivity Carries the Same Risk 

14% of organisations allow AI agents to connect to outside tools and data sources via the Model Context Protocol (MCP) without restriction. Among the majority who do limit those connections to an approved list, fewer than half (49%) have a dedicated team actively maintaining and auditing that list on a regular basis.

 

Christopher M. Steffen, CISSP, CISA, VP of Research at EMA, said: “This research shows enterprises have moved well past experimentation with agentic AI right into production and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organisations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organisations authorise agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.”

 

Shreyans Mehta, Co-founder and CTO at Cequence, said: “The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; its exactly why organisations stop looking for problems, stop investing in monitoring, and let authorisation checks lapse until an incident forces the conversation. This is the exact blind spot Cequence is built to close, giving security teams real-time visibility into what AI agents are actually doing and enforcing authorisation at the moment an agent acts, not after the fact.”

Notes to editors

Join Christopher M. Steffen, Vice President of Research at EMA, and Randolph Barr, Chief Information Security Officer at Cequence, for the “Agents Without Guardrails” webinar.

Thursday, 17 Sep 2026

    • 10:00 am PT / 01:00 pm ET

About the Research

EMA surveyed 202 enterprise IT and security leaders, including CIOs, CTOs, CISOs, and IT directors, at organisations with 1,000 or more employees that are deploying or evaluating agentic AI. Respondents are responsible for security, governance, or IT decision-making within their organisations. The sample spans North America and Europe, Middle East, and Africa, across a range of industries including technology, financial services, healthcare, and manufacturing.

About Enterprise Management Associates (EMA)

Founded in 1996, Enterprise Management Associates (EMA) is a leading industry analyst firm that provides deep insight across the full spectrum of IT and data management technologies. EMA analysts leverage a unique combination of practical experience, insight into industry best practices, and in-depth knowledge of current and planned vendor solutions to help EMA’s clients achieve their goals. Learn more about EMA research and analysis at www.enterprisemanagement.com.

About Cequence Security

Cequence protects the applications and data that power the agentic enterprise. More than a decade of bot defence and API security experience has established Cequence as the leader of safe and secure agentic AI adoption. The Cequence platform delivers deep insight into user, entity, and agent behaviour, enabling organisations to secure, govern, and control agentic AI workflows while protecting against bad actors and rogue agents. Cequence delivers value in minutes rather than days or weeks with a highly scalable, no-code approach. Trusted by the largest and most demanding private and public sector organisations, Cequence protects more than 10 billion daily API interactions and 4 billion user accounts. To learn more, visit https://www.cequence.ai/.

Get more news like this

Get more news like this on Google. Set News By Wire as a ‘Preferred News Source’ to get quicker access to news that’s important.

All done!
Thank you for subscribing.

Email Subscription