New research from Cequence Security and Enterprise Management Associates suggests that many enterprises are deploying AI agents with more confidence in their access controls than evidence that those controls are being enforced in practice.
The survey of 202 IT and security leaders at organizations with 1,000 or more employees found that 94% were confident their AI agents did not have excessive access. Only 33%, however, said they provision agents with least-privilege access, according to the research.
The gap is important because agentic AI systems can do more than generate responses. They may call tools, query data sources and take actions in connected systems. When those permissions are broad, persistent or poorly reviewed, an error or misuse can reach beyond the scope initially intended for an agent.
Cequence and EMA said 65% of surveyed organizations had experienced an AI agent taking an action outside its intended scope. The release says 29% of respondents reported measurable business impact, including data exposure, financial loss, operational disruption or reputational damage, while another 36% said they caught a near-miss before it caused damage.
The research is survey-based and was released by a security vendor that sells technology in this area, so its results should not be treated as an independent measurement of the entire market. Still, the methodology identifies a relevant population: IT and security decision-makers at large organizations that are deploying or evaluating agentic AI across North America, Europe, the Middle East and Africa.
The survey also highlights a response problem. Only 32% of organizations said they could detect and contain an out-of-scope agent action within minutes through automated means. Fifty-five percent said response took hours and manual steps. In about 4% of cases, the first indication of a problem came from a customer or external partner rather than an internal system.
Authorization timing was another focal point. Only 34% of respondents said they evaluate an agent’s authorization when it attempts a specific action. The rest rely more heavily on periodic reviews or permissions set at the time of provisioning, the release said. That means an agent may retain access after the specific task that justified it has changed or ended.
The report also points to cleanup risk. Thirty-one percent of agentic AI pilots had been paused indefinitely, discontinued or abandoned. The authors warn that pilots may leave behind active credentials and connections even when their business project no longer has an owner. Separately, 14% of respondents allow agents to connect to external tools and data through the Model Context Protocol without restriction.
For enterprise security teams, the practical takeaway is not that every agent requires a new security stack. It is that established identity and access practices need to be applied to agents throughout their lifecycle: initial provisioning, action-level authorization, monitoring, incident response and decommissioning.
Cequence’s product position is built around real-time visibility and authorization enforcement, but the broader operational issue is vendor-neutral. Teams adopting agents will need a clear inventory of what each agent can reach, who owns its permissions, how actions are logged and how access is removed when a pilot stops. Those controls can help reduce manual investigations and make policy enforcement more responsive when agents begin acting in production environments.

