Organizations are rapidly expanding the use of AI agents even as their ability to monitor and govern the technology falls behind, according to AvePoint’s 2026 State of AI report. The study surveyed 750 enterprise leaders responsible for information management, data security, or AI programs.
Although 82.7% of respondents said they were very or extremely confident they could prevent unauthorized AI-related access to company data, 72% of the “very confident” group and 62% of the “extremely confident” group reported experiencing such an incident during the previous year. AvePoint said organizations may overestimate their AI preparedness when they have written policies but lack evidence that those controls work in practice.
AI use grows as visibility declines
The gap is becoming more consequential as AI agents move into daily business operations. Respondents estimated that 46.9% of employees in their organizations use agents daily or weekly. They said agents were involved in 26.6% of work processes 12 months earlier and 39.1% at the time of the survey, and they expect that share to reach 54.8% within another year.
As adoption grows, organizations are becoming less certain about where and how AI is being used. The share of respondents unable to determine whether employees were using unsanctioned generative AI tools rose from 6.3% in 2025 to 17.6% in 2026. For AI-agent tools, 21.1% said they could not determine whether employees were using unsanctioned tools to create agents.
“To manage this emerging threat landscape, security teams need a mature, continuous security approach, which includes blue team programs, starting with a full inventory of all AI systems, including agentic components as a baseline for governance and risk management,” said Diana Kelley, chief information security officer at Noma Security.
The stakes are particularly high in cybersecurity, which respondents ranked as the top use case for AI agents. Their leading concern was that agents could make incorrect judgments or take inappropriate actions that damage data, followed by employees making decisions based on inaccurate agent outputs. Among respondents who were “extremely concerned,” agents bypassing human-in-the-loop controls ranked first. AvePoint also described cybersecurity response as one of the highest-risk agent deployments when data protection and governance controls are not in place.
Reported AI-related security incidents
The survey found that 88.4% of respondents experienced at least one agent-related security incident during the previous 12 months. The incidents included exposure or improper retention of sensitive data, manipulation through malicious or untrusted inputs, unauthorized agent actions, the creation or misuse of unauthorized or “shadow” AI identities, and loss of control over autonomous agents or workflows.
“These agents often operate under machine accounts or service identities, acting on behalf of human users, which makes it difficult to track permissions, monitor usage, and enforce accountability,” said Elad Luz, head of research at Oasis Security.
The report also said 89.5% of respondents experienced at least one generative AI-related security incident, up from 75.1% a year earlier. The listed events included inaccurate, untrustworthy, or altered AI-generated content; potentially harmful advice; insecure generated code; the detection of non-corporate-approved AI assistants; prompt-injection attacks that bypassed guardrails; unauthorized access; and sensitive-data disclosure.
AI-generated data expands the governance challenge
The challenge is compounded by the volume and condition of enterprise data. Respondents estimated that generative AI assistants create 35.5% of organizational data and expect that share to reach 42.1% within a year. Meanwhile, 84.1% said their organizations manage at least one petabyte of data, and 78.1% reported that at least half of it is more than five years old.
When AI systems consume and act on outdated, redundant, or low-quality information, they can produce unreliable results or carry existing errors into other business processes. AvePoint warned that those problems may compound as AI-generated content is reused across systems.
Data security and management concerns slow deployments
The report found that 86.9% of organizations delayed generative AI projects by an average of nearly six months because of data security and management concerns. A nearly identical share, 86%, reported delays involving AI agents.
Organizations are responding with greater spending. Protecting data used for AI training was identified as a leading investment priority by 79.5% of respondents, while 62.4% said they plan to increase spending on technology that monitors agent actions for compliance with organizational policies. Among organizations addressing generative AI security concerns, the share reporting no mitigation action fell from 8.3% in 2025 to 2.5% in 2026.
Human oversight and employee training were among the most common measures organizations reported using to address agent-related risks. The report also pointed to third-party governance tools that monitor agent actions for policy alignment and to the emerging category of AI Agent Management Platforms, which AvePoint described as providing visibility, lifecycle control, policy enforcement and auditability across agents.
“Trust in AI cannot be measured by confidence alone,” AvePoint Chief Technology Officer John Peluso said. He said organizations need to know how their AI systems are being used, maintain control over the data those systems handle, and be able to investigate and correct failures.