Zero Day Room
Live
Regulation & compliance

65% of Enterprises Report AI Agent Scope

A new report reveals that 65% of surveyed enterprises have experienced AI agents acting outside their intended scope, with 29% reporting measurable

A new report reveals that 65% of surveyed enterprises have experienced AI agents acting outside their intended scope...

Nearly two-thirds of enterprises have witnessed AI agents acting outside their intended boundaries, according to new research. The report, compiled for Cequence Security, found 29% of those incidents resulted in measurable organizational impact.

The findings come from the 'Agents Without Guardrails' report by Enterprise Management Associates (EMA). It is based on responses from 202 enterprise technology and security leaders. The research indicates a rapid deployment of agentic AI, with 46% of organizations already scaling it across multiple departments and production workflows. Nearly 79% are running generative and agentic AI systems simultaneously.

Christopher M. Steffen, EMA's vice president of research and the report's author, stated that operational governance has failed to keep pace with deployment. "Most organizations have policies in place and express real confidence in them," Steffen said. "The gap is between what's written down and what's enforced."

Detection and Response Capabilities Lag

Organizational ability to respond to these incidents is weak. Only 32.2% of respondents said they could detect and contain an out-of-scope action within minutes using automated tools. A majority, 54.5%, needed hours and manual intervention to manage such events.

Just over 46% also admitted they could not easily produce a complete audit trail of a specific agent's activity over the previous 30 days. Alongside the confirmed incidents, 35.6% of respondents reported catching a 'near-miss' before it caused material harm. In 3.5% of cases, representing seven organizations, customers or partners were the first to report the anomalous agent behavior.

Authorization and Access Control Gaps

The report identified significant weaknesses in how agents are authorized. Only 34.2% of organizations evaluated whether an agent was authorized to act at the moment of execution. Others relied on standing permissions, periodic reviews, or inherited access models.

This gap is tied directly to overprovisioning. While 94% of respondents expressed at least some confidence that their agents did not hold excessive access, only 32.7% actually provisioned agents with a true least-privilege model. The report connects weak runtime authorization to the high rate of out-of-scope actions.

Identity and Inventory Management Problems

Identity enforcement for AI agents is inconsistent across enterprises. The survey revealed a fragmented approach to managing agent identities.

Identity Enforcement PracticePercentage of Respondents
Require and enforce unique identities for all AI agents54.5%
Require unique identities but do not consistently enforce32.2%
Agents share or inherit credentials from user/service accounts3%

Visibility remains a critical issue. Some 47% of respondents lack a reliable inventory of their AI agents, despite many organizations running dozens of them in production environments. This lack of a central registry complicates security monitoring and incident response.

The lifecycle of AI agents presents another risk. The survey found that 30% of agentic AI pilots had been paused indefinitely or formally discontinued. Security risk concerns were a major factor in 48.5% of these stalls. The report notes a troubling pattern: many decommissioned pilots are not properly cleaned up, leaving their provisioned credentials and production access in place.

The report concludes with several security recommendations. It advises organizations to evaluate agent authorization at runtime, not just during provisioning. It also calls for building automated detection and containment capabilities before expanding AI agent deployments. Finally, it stresses that agent decommissioning must be treated as a formal security discipline, requiring explicit processes for credential revocation and permission cleanup.

Related coverage

More from Regulation & compliance