94 Percent of Security Leaders Trust Their AI Agents, Only 33 Percent Actually Locked Them Down
Data Engineering

94 Percent of Security Leaders Trust Their AI Agents, Only 33 Percent Actually Locked Them Down

A new survey finds enterprises running dozens of AI agents cannot produce a complete 30-day activity log for nearly half of them, and confidence is not the same thing as control.

PublishedSeptember 25, 2026
Read time5 min read
Share

A confidence gap with a name

The report, titled 'Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise,' documents a specific and measurable disconnect between what security leaders believe about their AI agent deployments and what their own access control data actually shows. Ninety-four percent of IT and security leaders surveyed expressed confidence that their AI agents do not have excessive access to systems and data. Only 33 percent had actually implemented least-privilege provisioning, the access control practice that would make that confidence justified.

Cequence CISO Randolph Barr offered a sharp diagnosis of the gap's source: 'Confidence is usually measuring compliance, not cyber, that only holds if the person creating the agent gets it right.' His point is that survey confidence often reflects a belief that policy exists and was followed, not verification that the actual technical configuration matches that policy, a distinction that matters enormously once an agent is live and making autonomous decisions against production systems.

The scale at which this gap now operates

This is not a marginal or emerging concern confined to early pilots. Forty-six percent of organizations are already scaling agentic AI across multiple departments, and 31 percent are actively moving prototypes into production. Forty-three percent run between 6 and 20 active agents, and nearly 40 percent operate more than 20, meaning a meaningful share of enterprises are managing agent fleets large enough that manual, ad hoc oversight of each individual agent's permissions is no longer realistic.

Seventy-nine percent of organizations are running generative and agentic AI simultaneously, compounding the governance challenge: teams are managing two distinct AI risk profiles, one centered on output quality and hallucination risk, the other on autonomous action and system access, often with the same limited governance tooling and staff trying to cover both at once.

Broad access is still the default, not the exception

67.3 percent of organizations provision agents with broad, less-controlled access rather than task-specific, least-privilege permissions, essentially the inverse of standard security practice for any other class of automated system with production access. That gap between stated security posture and actual configuration is precisely what the survey's headline confidence numbers were measuring incorrectly: leaders reported confidence in policies that, in the majority of organizations, were not actually implemented at the technical level.

Cequence co-founder and CTO Shreyans Mehta put the risk of that misplaced confidence directly: 'Confidence like that is a trap, it's exactly why organizations stop looking for problems.' An organization that believes its agent access is already well controlled has little internal pressure to audit that belief against reality, which is exactly the condition under which a genuine security gap persists undetected until an incident forces the issue.

When agents misbehave, most organizations find out slowly

Sixty-five percent of organizations reported agents taking unintended actions, and 29 percent experienced measurable organizational impact as a result, figures that move this from a theoretical governance concern to a documented, widespread operational reality. The detection and response numbers are the more concerning half of the picture: only 32 percent of organizations can identify and contain an out-of-scope agent action within minutes, while 55 percent require hours to detect and respond.

That detection lag matters disproportionately for agentic systems compared to traditional software failures, because an agent taking unintended action can continue executing further actions, each potentially compounding the impact of the first, for the entire duration between the initial deviation and eventual detection. A traditional application bug typically fails in a bounded, repeatable way; an agent acting outside its intended scope can take a cascading sequence of increasingly consequential actions before anyone notices.

The audit trail gap regulators will care about

Forty-six percent of organizations cannot produce a complete 30-day agent activity log, a specific and consequential gap for any organization in a regulated industry where audit trail completeness is a compliance requirement rather than a best practice. For financial services, healthcare and other regulated sectors, an inability to answer 'what did this agent do over the past month' is a finding a regulator or auditor would flag directly during any review touching AI system usage, well beyond a mere operational inconvenience.

This audit gap compounds the detection lag problem described above: even after an organization eventually identifies that an agent took an unintended action, incomplete logging may prevent them from fully reconstructing what happened, when, and what downstream systems or data the action touched, undermining both the incident response process and any subsequent compliance reporting obligation.

What closing the gap actually requires

The practical implication for CISOs and data leaders is that closing this gap requires treating agent access governance as its own discipline, distinct from both traditional identity and access management and from generative AI content governance, with its own tooling, its own audit requirements and its own incident response runbooks built specifically around autonomous action rather than human-initiated requests.

Organizations scaling agent deployments faster than they are building this governance discipline are accumulating a specific, quantifiable form of technical debt: the gap between agents deployed and agents properly governed only grows harder to close as the number of active agents increases, and retrofitting least-privilege access and complete audit logging onto dozens of already-deployed agents is a substantially harder project than building those controls in from the start of any new agent rollout.

Tagged#news#data#data-engineering#databases#analytics#lakehouse#streaming#ai-agent-governance#cequence-security#enterprise-management-associates#least-privilege-access#ai-security-survey#audit-logging#agentic-ai-risk#access-control#compliance#incident-response