Recent research from Cequence Security and Enterprise Management Associates (EMA) reveals a significant governance gap in the deployment of AI agents within enterprises.
Although 94% of IT and security leaders are confident that their AI agents operate within necessary access limits, only 33% have ensured such limits are implemented effectively. The remaining enterprises operate with broad standing permissions that often go unreviewed, leaving them vulnerable to risks. The comprehensive report, titled "Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise," is now available for download.
Broad Standing Permissions in Practice
The study highlights that the discrepancy between confidence and actual governance is impacting enterprises significantly. Of those surveyed, 65% reported AI agents acting beyond their intended scope, with 29% encountering severe repercussions such as data breaches, financial losses, operational interruptions, or damage to reputation.
Additionally, 36% managed to intercept potential threats before they could cause harm. Alarmingly, only 32% of organizations can swiftly manage deviations using automated processes, while 55% require hours to address issues manually. In a small number of cases, external entities identified problems before the internal systems did.
Challenges in Customer-Facing Applications
Furthermore, only 34% review AI agents' access at the time of a specific action
The investigation underscores that governance mechanisms have not kept up with the fast-paced deployment of agentic AI, revealing flaws at every stage from provisioning to decommissioning.
Nearly half of the organizations surveyed are already scaling AI across multiple sectors, with 79% running both generative and agentic AI simultaneously. An overwhelming 92% report a surge in AI and bot traffic targeting customer-facing applications and APIs. Furthermore, only 34% review AI agents' access at the time of a specific action, with most relying on outdated policies that allow AI agents to maintain access long after their original tasks conclude.
The Risk of Abandoned AI Initiatives
The research indicates a growing concern around pilot AI agents that never progress to production. Approximately 31% of AI agent projects are halted indefinitely, canceled, or abandoned, often leaving sensitive system credentials exposed without oversight.
Meanwhile, 14% of organizations allow AI agents unrestricted access to external tools and data sources through the Model Context Protocol (MCP), posing additional security risks. Even among those who restrict such access, less than half have dedicated teams to continuously update and review these limitations effectively.
Insights from Industry Experts
Christopher M. Steffen, CISSP, CISA, VP of Research at EMA, commented, “This research shows enterprises have moved well past experimentation with agentic AI right into production, and governance has not kept pace with that shift. The gap isn't a lack of awareness; most organizations have policies in place and express real confidence in them. The gap is between what's written down and what's enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they're live, and it's the reason incidents are happening at a rate the industry hasn't fully reckoned with.”
Shreyans Mehta, Co-founder and CTO at Cequence, noted, “The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; it's exactly why organizations stop looking for problems, stop investing in monitoring, and let authorization checks lapse until an incident forces the conversation. This is the exact blind spot Cequence is built to close, giving security teams real-time visibility into what AI agents are actually doing and enforcing authorization at the moment an agent acts, not after the fact.”
Attendees interested in gaining deeper insights can participate in the "Agents Without Guardrails" webinar, featuring Christopher M. Steffen from EMA and Randolph Barr, Chief Information Security Officer at Cequence.
Nearly every enterprise believes its AI agents are properly scoped but only a third have actually made sure of it. New research from Cequence Security, the pioneer in application, API, and agentic AI protection, and Enterprise Management Associates (EMA) found that 94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need, yet only 33% actually provision agents with least-privilege access.
The remaining two-thirds run on broad standing permissions that are reviewed periodically, rarely reviewed, or never reviewed at all. The full report, Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise, is available for download now.
Broad standing permissions
The gap between confidence and practice is already showing up in production, not as a theoretical risk, but as incidents enterprises are living with right now. Among the organizations surveyed:
- 65% have experienced an AI agent take an action outside its intended scope, including 29% with measurable business impact such as data exposure, financial loss, operational disruption, or reputational damage. Another 36% caught a near-miss before it caused damage.
- Only 32% can detect and contain an out-of-scope agent action within minutes through automated means; 55% need hours and manual steps to respond.
- In approximately 4% of the organizations surveyed, the first sign of trouble came from a customer or outside partner, not an internal system.
Customer-facing applications
The findings point to one clear story. Governance has not kept pace with the speed of agentic AI deployment, and that gap is showing up at every stage of the agent lifecycle, from how agents are provisioned, to how their actions are authorized, to how they are decommissioned once a pilot ends. Other key findings from the report include:
- The scale of deployment makes the gap more urgent. 46% of organizations report they are already scaling agentic AI across multiple departments and production workflows, and 79% are running generative and agentic AI simultaneously. Further, more than 92% report an increase in AI and bot-driven traffic targeting customer-facing applications and APIs.
- That governance gap extends to how access is enforced the moment an agent acts. Only 34% of organizations evaluate an AI agent's authorization at the moment it attempts a specific action. The majority rely on periodic policy reviews or standing permissions set once at provisioning and never revisited, meaning an agent's access can quietly outlive the task it was originally granted for, and keep working long after anyone signed off on it.
- Additionally, there’s an increasing risk in how enterprises manage agents that don't make it to production. 31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned. Many were real deployments with real system access and credentials that were never cleaned up. Every abandoned pilot with live credentials is an exposure nobody is actively watching.
- 14% of organizations allow AI agents to connect to outside tools and data sources via the Model Context Protocol (MCP) without restriction. Among the majority who do limit those connections to an approved list, fewer than half (49%) have a dedicated team actively maintaining and auditing that list on a regular basis.
Well past experimentation
Christopher M. Steffen, CISSP, CISA, VP of Research at EMA, said: “This research shows enterprises have moved well past experimentation with agentic AI right into production and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organizations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.”
Shreyans Mehta, Co-founder and CTO at Cequence, said: “The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; its exactly why organizations stop looking for problems, stop investing in monitoring, and let authorization checks lapse until an incident forces the conversation. This is the exact blind spot Cequence is built to close, giving security teams real-time visibility into what AI agents are actually doing and enforcing authorization at the moment an agent acts, not after the fact.”
Join Christopher M. Steffen, Vice President of Research at EMA, and Randolph Barr, Chief Information Security Officer at Cequence, for the “Agents Without Guardrails” webinar.