Enterprise Management Associates (EMA) recently published a research report prepared for Cequence Security, “Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise.” The report reveals a number of alarming statistics, with an initial focus on the outsized level of confidence that enterprises have in their AI agents. According to the report, 94% of the over 200 IT and security leaders surveyed are either somewhat confident or very confident that their AI agents are not granted more access than necessary. Nearly as many (92%) are confident that governance in their organizations is keeping pace with agentic AI.
Agents Already Running Core Operations
The report details the extent to which enterprises are currently incorporating AI agents into their operations. Of those surveyed, 46% are already scaling AI agents across multiple departments, and 79% are running generative and agentic AI in tandem. The leading use cases for these tools and agents are help desk (56.4%) and security (29.2%) operations.
In spite of this widespread usage of both generative AI tools and agentic AI, many of these organizations lack the guardrails and governance in place to support it. Nearly half (47%) are unable to reliably inventory the AI agents they are using. At the same time, AI usage among cybercriminals is increasing, with 92% of survey respondents reporting rising AI and bot traffic against their APIs.
These numbers underscore the crucial need for alignment between perceived and actual security. “The gap isn’t a lack of awareness; most organizations have policies in place and express real confidence in them,” says Christopher M. Steffen, CISSP, CISA, Vice President of Research at Enterprise Management Associates (EMA). “The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.”
Provisioning Data Reveals the Danger
The level of access provisioned to AI agents is one of the most significant factors in the risk introduced to organizations that use them. Less than one third (32.7%) of the organizations surveyed for the report provision access based on the principle of least privilege, underlining the massive gaps in how AI agents are managed. A total of 46% of organizations grant their AI agents broad standing access with varying frequencies of access reviews, while 10.9% of agents inherit the permissions of the user who deploys them.
Only 54.5% of organizations require and consistently enforce AI agents having unique, individually identifiable identities that can be distinguished from human users and generic service accounts. An additional 32.2% say that they have this requirement but do not consistently enforce it, highlighting the rift between many organizations’ policies and the measures they put into practice.
Incidents in Practice
While the places where governance and guardrails fall short are evident in enterprises’ own reports of their agentic AI security measures in place, data concerning actual security incidents only serves to drive the point home. Almost two-thirds (64.8%) of those surveyed report having seen an AI agent act outside its intended scope within their organizations: 29.2% cite incidents with measurable impacts like data exposure or financial, operational, or reputational damage, while 35.6% state that the action was caught before any material impact could occur.
Only a little more than one third (34.2%) of organizations report no known out-of-scope action taken by agentic AI. The public record is far less forthcoming than the survey and incident data regarding the risks of AI agents without proper safeguards and governance.
Slow Detection and Thin Evidence
The numbers are also not promising with regard to the detection and remediation of any security incidents that may arise involving agentic AI. When asked how quickly their organizations could detect and contain an issue if an agent acted outside of its intended operations, less than one third (32.2%) stated that they could do so within minutes. More than half (54.5%) would require hours to manually contain the incident after monitoring detected it.
Logging and documentation present another challenge to securing agentic AI. Nearly half (46%) of those surveyed said that their organizations could not easily produce a 30-day audit trail of a particular agent’s activities. Furthermore, 3.5% (seven organizations) reported that they were first informed of rogue behavior by a customer or external partner.
Authorization Timing as the Root Cause
The underlying issue in many of these agentic AI incidents is when authorization actually takes place. Of those surveyed, only 34.2% stated that their organizations evaluate authorization for AI agents for each action at the time of execution. An additional 37.6% determine authorization at periodic policy reviews, and 21.3% assign authorization based on the agent’s standing permissions, which can turn into permanent entitlements.
Many of these organizations also implement the Model Context Protocol (MCP) in unsecured ways: 13.9% allow users to connect AI agents via protocols like MCP without restriction, and 56.4% limit these connections to an approved or vetted list. Of the second group, only 49.1% actively maintain these approved lists with regular reviews conducted by a dedicated security or governance team. When it comes to deploying agentic AI, 54.5% of organizations leave deployment approval up to CIOs or CTOs, and only 15.8% leave the approval to CSOs or CISOs.
Abandoned Pilots Left in Production
A significant amount of risk comes from agentic AI pilots within an organization that are deployed and not shut down when their time in operation is through. Around 30% of AI agent pilots are paused, discontinued, or abandoned, with most of those being left in production with system access and credentials left in place.
The stalling of these agentic AI pilots comes down to a number of factors. Nearly half (48.5%) of those surveyed cited security concerns as reasons for pausing pilots, 22% cited gaps in identity and access management (IAM), and 18.8% cited a lack of formal governance policy or approval process for these agents. The residual exposure of these agents only continues to grow as AI investment renewals arrive.
Governing What Agents Do
Addressing and remediating the excessive risks of deploying agentic AI in the way that many organizations currently do requires organizations to take steps to more effectively govern and manage the AI agents they have in operation. This includes implementing task-specific authorization that is evaluated at the time of the action, automating detection and containment prior to scaling across departments, and treating decommissioning dormant AI agents as a crucial security event. This report reveals a number of alarming trends in agentic AI security that organizations should thoughtfully consider and account for when deploying and managing their agents.