Cloud Security Alliance (CSA)

22 stats2 reports

All Statistics

57% of organizations report moderate or high confidence in identity scoping for AI agents.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
Identity ManagementRisk AssessmentAI AgentsIdentity Scoping

74% of organizations say AI agents often receive more access than necessary.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
Access ControlPrivilege ManagementAI Agents

Responsibility for AI agent identity and access is fragmented: 28% of organizations assign primary ownership to security leads, 21% to development/engineering, 19% to IT, and 9% to IAM teams.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
AI Agent GovernanceIdentity and Access ManagementOrganizational RolesAI Agents

28% of organizations can reliably trace agent actions to a human or system across all environments.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
TraceabilityAuditabilityAutonomous AI Agents

18% of IT and security professionals are highly confident their current IAM systems can manage agent identities effectively, while 35% report moderate confidence, 29% report slight confidence, and 18% report no or uncertain confidence.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
Identity and Access ManagementSecurity ConfidenceAutonomous AI Agents

58% of organizations estimate they currently have between 1 and 100 agents deployed.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
AI AdoptionAutonomous AI Agents

22% of organizations report that access frameworks are applied very consistently to AI agents.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
Access ControlAI AgentsIdentity Management

68% of organizations cannot clearly distinguish between human and AI agent activity.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
AI AgentsHuman vs AI Agent Activity

52% of organizations use workload identities for AI agents, 43% rely on shared service accounts, and 31% allow agents to operate under human user identities.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
Identity ManagementAccess ControlAI AgentsHuman User Identities

49% of organizations disable identities or revoke tokens as containment actions, 42% terminate the compute environment where an agent runs, and 33% remove or modify access policies in real time.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
Identity ManagementAccess Control

73% of organizations expect AI agents to become vital within the next year.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
AI Agents

AI agents operate across enterprise workflows: 67% are task automation agents, 52% are research agents, 50% are developer-assist agents, and 50% are security or monitoring agents.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
AI AgentsEnterprise

85% of organizations use AI agents in production environments.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
AI AgentsProduction Environments

79% of organizations believe AI agents create new access pathways that are difficult to monitor.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
Access ControlAccess MonitoringAI AgentsAccess Pathways

32% of organizations are uncertain how much time is required to implement and maintain authentication or credential handling for a typical AI agent.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
AuthenticationAI AgentsIdentity Management

52% of organizations say AI agents inherit access originally intended for humans or other systems at least sometimes.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
Identity ManagementPrivilege ManagementAccess ControlAI AgentsHuman User Identities

33% of organizations do not know how often AI agent credentials are rotated.

Cloud Security Alliance (CSA)Identity and Access Gaps in the Age of Autonomous AI·5mo ago
AI AgentsAI Agent CredentialsIdentity ManagementCredential Rotation

40% of organizations are increasing their overall identity and security budgets to accommodate AI agents, with 34% adding a dedicated budget line and 22% reallocating funds from other security areas.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
Security BudgetInvestmentAI Governance

44% of organizations use or plan to use static API keys and 43% use or plan to use username/password combinations for agents.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
AuthenticationAPI SecurityCredentials

21% of organizations maintain a real-time registry or inventory of their agents.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
Agent VisibilityAsset InventoryAutonomous AI Agents

Over 70% of organizations expect to manage dozens to hundreds of agents within the next 12 months, with 39% expecting 1–100 agents and 31% expecting 101–500 agents.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
AI AdoptionAutonomous AI Agents

84% of organizations doubt they can pass a compliance audit focused on agent behavior or access controls.

Cloud Security Alliance (CSA)Securing Autonomous AI Agents·6mo ago
ComplianceIdentity and Access ManagementAutonomous AI Agents