New research from Cequence Security and Enterprise Management Associates (EMA) has surfaced one of the more uncomfortable numbers in enterprise AI right now: 94% of IT and security leaders are confident their AI agents don't have more access than they need. Only 33% have actually done the work to make that true.
That gap—between what organizations believe and what they've verified—is the subject of a new report, Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise, based on a survey of 202 enterprise IT and security leaders conducted by EMA on behalf of Cequence. The findings suggest that agentic AI governance hasn't just fallen behind deployment; in many organizations, it never caught up to begin with.
The report's first finding is that agentic AI is no longer an experiment. Nearly half of organizations surveyed (46%) say they're already scaling agentic AI across multiple departments and production workflows. Another 31% are actively moving prototypes into production. Just 2.5% have paused deployment over risk or governance concerns.
Most of these organizations aren't running a handful of pilot agents, either. More than 43% report running between six and 20 distinct active agents, and nearly 40% are running more than 20—multi-agent portfolios embedded in core operational functions like IT help desk automation, software development, security operations, and customer support, not isolated proofs of concept.
Compounding the challenge, 79% of organizations are running generative and agentic AI simultaneously, meaning the same security and IT teams are managing two very different categories of risk in parallel—content-generation risk and autonomous-action risk—often without distinct governance models for each.
The headline finding is a striking mismatch between belief and practice. When asked how confident they were that their AI agents don't have more access than they need, 94% of respondents expressed at least moderate confidence: 48.5% "very confident," 45.5% "somewhat confident."
But when asked how agents are actually provisioned, only 32.7% said their agents receive least-privilege access scoped specifically to their task. The remaining 67.3% are running on some form of broader, less-controlled access: 38.1% use broad standing access that's only reviewed periodically, 7.9% use broad access that's rarely or never reviewed, nearly 11% provision agents with the full permissions of whoever deployed them, and almost 9% have no consistent process at all.
Randolph Barr, CISO at Cequence Security, a San Francisco-based API security and bot management provider, said the confidence number is the part of the data that stands out most to him.
"What jumps out most is that 94% confidence sitting right next to only 33% of agents provisioned with least privilege," Barr said. "In my experience, that confidence is usually measuring compliance, not cyber; there's a policy, people go through a workflow and agree to a set of 'thou shalt nots,' and the assumption is that following the process means you're secure. But that only holds if the person creating the agent gets it right, and most orgs don't have the technical controls in place to actually manage, monitor, and enforce what that agent does once it's live."
That same pattern shows up again at the governance-framework level: 92% of respondents said they're confident their governance and compliance frameworks can keep pace with the rate of change in agentic AI—inside the same population where 67.8% have had a security or governance review directly delay or stop a deployment. The report frames that as evidence of governance arriving late as a friction point rather than functioning as a proactive control.
The consequences of that gap aren't theoretical. According to the survey:
65% of enterprises have experienced an AI agent take an action outside its intended scope. Of those, 29% saw measurable organizational impact—data exposure, financial loss, operational disruption, or reputational damage—and 36% caught a near-miss before it caused damage.
Only 32% can detect and contain an out-of-scope agent action within minutes through automated means. 55% need hours and manual steps to respond, 8% would only catch it during a scheduled review, and 4% would only find out after measurable impact had already occurred.
In roughly 4% of organizations, the first sign of trouble came from a customer or outside partner, meaning the incident had already reached external visibility before anyone inside the company knew.
46% of organizations cannot easily produce a complete audit trail of a specific agent's activity over the past 30 days, making post-incident reconstruction—what was accessed, what data were touched, what needs to be reversed—a matter of significant manual investigation, if it's possible at all.
Shreyans Mehta, Co-Founder and CTO at Cequence, pointed to the confidence figure as the crux of the problem: "The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; it's exactly why organizations stop looking for problems, stop investing in monitoring, and let authorization checks lapse until an incident forces the conversation."
The report points to a specific mechanism behind the incident rate: agent authorization is largely evaluated at provisioning time and never revisited. Only 34.2% of organizations evaluate an agent's authorization at the moment it actually attempts an action. The rest rely on periodic policy reviews or standing permissions set once and left in place—meaning an agent's access can quietly outlive the task it was granted for.
Identity enforcement shows a similar policy-practice gap. While 54.5% of organizations require and enforce unique, individually identifiable identities for AI agents, another 32.2% say the requirement exists on paper but isn't consistently enforced; and 3% acknowledge agents still share or inherit credentials from human or service accounts.
Visibility is another weak point: 47% of organizations cannot reliably inventory all the agents deployed across their environment, even as they run dozens of agents in core production workflows. And when it comes to who actually signs off on production deployments, security leadership is largely absent from the room. CIOs and CTOs approve 54.5% of agentic AI deployments, while CISOs or CSOs hold that authority in just 15.8% of organizations.
External connectivity carries a version of the same risk. Roughly 14% of organizations let agents connect to outside tools and data via the Model Context Protocol (MCP) without any restriction, and among the majority who do limit connections to an approved list, fewer than half (49%) have a dedicated team actively maintaining and auditing that list on a regular basis.
One of the report's more overlooked findings concerns agents that never made it to production, or that were shut down after launch. Thirty percent of agentic AI pilots have been paused indefinitely, formally discontinued, or abandoned, and most of these were real deployments with real system access and real credentials that were never cleaned up.
The leading factors behind stalled or abandoned pilots were security risk concerns (48.5%) and identity and access management gaps (22.3%)—meaning the agents most likely to have been shut down for governance reasons are also the ones most likely to have been decommissioned without proper credential revocation and permission cleanup.
Barr's advice for security leaders trying to close the gap starts with visibility, not policy.
"As a CISO, not knowing what you don't know is what keeps me up at night, so if I were telling someone where to start, it's to get a real inventory of every agent you actually have running, then go agent by agent and ask two questions: what is it actually doing versus what it was scoped to do, and is it operating on its own defined access or did it just inherit the permissions of whoever created it," Barr said. "That last one gets missed constantly, and it's exactly how an agent ends up with far more reach than anyone intended."
That guidance lines up with the three recommendations EMA draws directly from the data:
Govern what agents do, not just what they are. Authorization needs to be evaluated task by task, at the moment of action, not scoped once at provisioning and left to accumulate.
Build detection and containment capabilities before scaling further. Manual, hours-long response processes can't keep pace with multi-agent production portfolios operating at machine speed.
Treat decommissioning as a security event, not a project-closure checkbox. Every discontinued pilot that retains live credentials is unmonitored exposure sitting in production.
The report's authors describe the incident and near-miss rate—nearly two-thirds of organizations—as a number that should "reframe how the industry talks about AI risk," particularly given that most of these organizations have been running agentic AI in production for less than two years.
As Christopher M. Steffen, VP of Research at EMA, put it: "The gap isn't a lack of awareness; most organizations have policies in place and express real confidence in them. The gap is between what's written down and what's enforced when an agent takes an action nobody approved."