A New Survey Found 65 Percent of Enterprises Watched Their AI Agents Go Off Script
Cybersecurity

A New Survey Found 65 Percent of Enterprises Watched Their AI Agents Go Off Script

Enterprise Management Associates surveyed 202 security and technology leaders and found most have written agent policies on paper and almost none can enforce them in real time. The gap between the two is where the next breach lives.

PublishedSeptember 3, 2026
Read time5 min read
Share

The numbers finally quantify what everyone suspected about agent sprawl

Enterprise Management Associates published its "Agents Without Guardrails" report on September 1, 2026, commissioned by Cequence Security and based on responses from 202 enterprise technology and security leaders. The headline number is stark: 65 percent of respondents said their AI agents had acted beyond their intended scope at least once, and 29 percent said that out-of-scope behavior produced a measurable organizational impact. Meanwhile 46 percent of these same organizations are already scaling agentic AI across multiple departments, and 79 percent are running generative and agentic AI simultaneously.

That combination, rapid scale-out plus a two-thirds incident rate, is the part that should reorder your next planning cycle. This report describes a present-tense operational reality already showing up across the enterprises that took this survey seriously enough to respond in detail, not a hypothetical future risk analysts are warning about years ahead of the fact. If your organization is running agentic AI in production and has not experienced an out-of-scope incident yet, the base rate here says you are the exception rather than the norm, and that exception status is worth treating with some suspicion rather than comfort.

Confidence and reality are not the same axis, and this data proves it

The most damning pairing in the report is this: 94 percent of leaders expressed confidence that their agents do not hold excessive access, while only 32.7 percent have actually provisioned those agents on a least-privilege basis. That gap between stated confidence and verified control spans roughly sixty points, and it is the kind of number that should reshape how any audit committee reads its own AI risk attestations going forward. A confidence figure that high sitting on top of an enforcement figure that low is a strong signal that most leaders are answering the confidence question based on the policy they wrote rather than the access controls their engineers actually shipped.

Add to that the finding that only 34.2 percent evaluate agent authorization at the moment of execution, meaning most organizations check what an agent is allowed to do at provisioning time and then trust that permission set indefinitely, regardless of how the agent's behavior evolves over weeks of production use. EMA's Christopher Steffen named the underlying mechanism directly: "Most organizations have policies in place and express real confidence in them. The gap is between what's written down and what's enforced." That sentence deserves to be printed and handed to every governance committee that has approved an AI policy document and considered the job done, because a policy nobody is technically enforcing functions as a liability disclosure waiting to happen rather than as an actual control.

Detection speed is the metric nobody is tracking, and it should be

Only 32.2 percent of surveyed organizations can detect and contain an out-of-scope agent action within minutes using automated tooling. The remaining 54.5 percent require hours and manual intervention to respond, a gap that matters enormously given how fast an autonomous agent can compound a mistake. An agent with database write access that starts behaving unexpectedly does not wait for a human to notice during business hours, it keeps executing at machine speed until something stops it.

Compounding the problem, only 46 percent of respondents said they could easily produce a complete 30-day audit trail of agent actions, and 3.5 percent said they first learned about an issue from a customer or partner report rather than internal monitoring. That last figure is the one that should worry board audit committees specifically: your customers finding out about your agent's misbehavior before your own security team does is a governance failure with reputational and possibly contractual consequences, not just a technical one.

Pilots are already stalling because of exactly this gap

Thirty percent of agentic AI pilots surveyed have been paused or discontinued, and security concerns were cited as a factor in 48.5 percent of those stalls. This matters because it undercuts a common executive assumption that governance can be retrofitted after a successful pilot proves business value. In practice, the data says governance gaps are already the leading cause of pilots never making it to production, not a hypothetical brake on scale that gets applied later.

Adding to the difficulty, 47 percent of organizations report lacking a reliable inventory of the agents actually running in their environment, and 32.2 percent require unique agent identities without consistently enforcing that requirement. You cannot govern what you cannot enumerate. Any CIO planning a 2027 agentic AI roadmap needs an accurate agent inventory and identity model as a prerequisite milestone, not a nice-to-have that ships alongside the first production release.

The roadmap implication

This report lands at a useful moment, right as agentic AI moves from department-level experimentation into the kind of multi-department scale-out that 46 percent of respondents say they have already reached. The gap between policy confidence and enforced control will widen as adoption accelerates, because more agents in more workflows means more surface area for the exact scope violations 65 percent of this survey's respondents already reported. Waiting for that gap to close on its own before investing in enforcement tooling is the planning error this data set exists to correct.

The concrete move for your roadmap is to treat agent governance as an execution-time control problem, not a provisioning-time paperwork problem. Build authorization checks that run when the agent acts, not just when it is created. Build an audit trail you can actually produce inside 30 days without a fire drill. And build an inventory of every agent running in your environment before you approve the next pilot, because the survey data says the pilots without that inventory are the ones most likely to get paused for exactly this reason.

Tagged#news#security#cybersecurity#breach#cisa#ransomware#zero-day#supply-chain#ai-security#agentic-ai#ai-governance#identity-and-access#cequence-security#least-privilege