Cequence Security

16 stats1 reports

All Statistics

46% of organizations are already scaling agentic AI across multiple departments and production workflows.

Agentic AIEnterprise

79% of organizations are running generative and agentic AI simultaneously.

Generative AIAgentic AIEnterprise

More than 92% of organizations report an increase in AI- and bot-driven traffic targeting customer-facing applications and APIs.

Bot TrafficCustomer ApplicationsAgentic AIEnterprise

Only 34% of organizations evaluate an AI agent’s authorization at the moment it attempts a specific action.

AuthorizationAccess ControlAgentic AIEnterprise

31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned.

Agentic AIEnterprise

36% of organizations catch a near-miss from an AI agent before it causes damage.

Agentic AIIncident DetectionEnterprise

32% of organizations can detect and contain an out-of-scope agent action within minutes through automated means.

Incident ResponseAutomationAgentic AIEnterprise

Approximately 4% of organizations first learn about an AI agent problem from a customer or outside partner rather than an internal system.

Incident DetectionAgentic AIEnterprise

94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need.

AI GovernanceAccess ControlAgentic AIEnterprise

Only 33% of enterprise IT and security leaders provision AI agents with least-privilege access.

AI GovernanceLeast PrivilegeAgentic AIEnterprise

Two-thirds of enterprises run AI agents on broad standing permissions that are reviewed periodically, rarely, or never reviewed at all.

Access ControlAI GovernanceAgentic AIEnterprise

55% of organizations need hours and manual steps to respond to an out-of-scope agent action.

Incident ResponseOperational RiskAgentic AIEnterprise

65% of organizations have experienced an AI agent take an action outside its intended scope.

Agentic AIOperational RiskEnterprise

29% of organizations experience measurable business impact from an AI agent acting outside its intended scope, including data exposure, financial loss, operational disruption, or reputational damage.

Data ExposureFinancial LossAgentic AIEnterprise

14% of organizations allow AI agents to connect to outside tools and data sources via the Model Context Protocol (MCP) without restriction.

Model Context ProtocolAgentic AIAccess ControlEnterprise

49% of organizations that limit agent external connections to an approved list have a dedicated team actively maintaining and auditing that list on a regular basis.

Access ManagementAuditAgentic AIEnterprise