Enterprise AI has quietly crossed a threshold. What began as a productivity layer for summarizing data and drafting reports has evolved into a class of digital workers with real authority, according to new research from Pathlock:
- 38% of organizations let AI agents create and modify business records.
- 28% allow agents to approve transactions.
- 25% grant direct access to backend databases.
- 35% permit agents to execute cross-system workflows.
- 36% embed agents into finance and accounting workflows.
These numbers illustrate how AI agents no longer serve merely as passive assistants. They can leverage non-human identities to execute decisions once reserved for accountable humans—often at a speed and scale no human reviewer can match.
“You simply cannot secure what you cannot see,” warns Chandra Gnanasambandam, CTO at SailPoint. “Today, most enterprises are flying blind regarding the sheer volume of their non-human workforce. It’s no longer enough to just track a few service accounts. Teams need to deploy discovery mechanisms capable of identifying agents across the entire digital ecosystem. They must be able to find and classify cloud agents managing infrastructure, app-level agents driving enterprise workflows, browser-based agents and extensions, and endpoint bots operating on local machines.”
Governance Not Keeping Pace
In reaction to this report, John Gallagher, Vice President of Viakoo Labs at Viakoo, adds, “The reality is that organizations need to automate key cyber hygiene functions, like patching and password changes, as soon as possible, because of the volume and velocity of AI-driven threats. However, they should take a more cautious approach to things that are not as existential, such as report writing.”
The trouble that many enterprises face is that their governance workflows have not caught up to authority. Pathlock reports that nearly 25% of organizations have already logged a formal AI-related incident requiring investigation.
But the visibility gap suggests this is only a partial count: more than 50% of security leaders cannot confidentially say that they know about every AI agent operating inside their systems. And 31% aren't even sure whether an incident caused by an agent has occurred at all.
As this research bears out, AI agents have quietly accumulated operational power inside enterprises while traditional oversight structures have failed to keep pace. So what will it take to close the accountability gap—before incidents become the norm rather than the exception?
The Rise of the Unsupervised Digital Workforce
As the Pathlock research points out, AI agents now rank among the fastest-growing classes of non-human identities in the enterprise. The agents have shifted from assistive tools to autonomous actors executing real transactions.
And with direct database access, agents can sidestep application-level controls and audit trails. The speed of execution simply outpaces human review cycles built into legacy oversight processes. Enterprise traceability and accountability structures have not scaled with the adoption of AI.
“Where this is going is clear enough,” states Adam Ochayon, Vice President of Product Strategy at Oasis Security. “The scale only goes up. Credentials move off weak and long-lived toward stronger and short-lived. And the center of gravity moves to governance— knowing what every non-human identity is, keeping its lifecycle clean from creation to decommission, putting an accountable owner on each one, and, as part of that, governing what it's actually allowed to do. Establish that governance, then actually maintain it…because this estate drifts the moment you stop looking.”
What Governance Must Become
The Pathlock report also notes that 23% of organizations have experienced at least one AI incident requiring investigation and remediation. But given the visibility gaps, formal incident counts likely understate the true exposure.
The early cases signal what happens when authority outpaces oversight at scale. It’s clear that the window to build governance proactively is narrowing as adoption accelerates. To take on this challenge, enterprise accountability structures need to match the operational authority already granted. In addition, visibility and traceability must extend to every non-human identity, not just human users.
“Reactive defenses cannot operate at machine speed,” commented Ram Varadarajan, CEO at Acalvio. “This necessitates a shift in the cybersecurity stack to preemptive, AI-driven strategies. AI fighting AI—combined with offensive deception technologies—is the budding design to catch attackers off guard and cause them to make mistakes and reveal themselves. Organizations that acclimate will recognize that defense is no longer about building higher walls. It's about becoming an unpredictable, moving target.”
Shane Barney, the Chief Information Security Officerat Keeper Security, provides additional observations: “Fully autonomous non-human identity management without human oversight is not the goal and shouldn't be. The aim is automated governance—systematic, consistent and policy-enforced—with humans retained in the oversight role. Organizations should establish systems that automatically discover new machine identities, classify risk, enforce policies, rotate credentials, and alert security teams to unusual behavior. Automation reduces operational burden while ensuring consistency.”