Cloud Security Alliance (CSA) & Token Security
All Statistics
38% of enterprises require human approval when AI agents exceed their scope.
24% of enterprises require actions that exceed an agent's scope to be logged.
53% of enterprises operate AI agents autonomously for low-risk tasks while applying human review for higher-risk actions.
43% of enterprises report operational disruption from AI agent-related incidents.
41% of enterprises say discovery of unknown AI agents happened multiple times in the past year.
29% of enterprises prioritize risk management, 28% prioritize monitoring, and 19% prioritize permission control for AI agents.
47% of unknown AI agents emerge in LLM platforms, including custom tools, assistants, and plugins.
13% of enterprises report fully autonomous AI agent models.
82% of enterprises have unknown AI agents running in their IT infrastructure.
53% of enterprises use human authorization as a primary signal for governing AI agent behavior.
79% of enterprises say context-aware controls will be important or very important in the next two years.
61% of enterprises report data exposure from AI agent-related incidents.
No organizations reported experiencing zero material business impact from AI agent-related incidents.
Only 21% of enterprises have formal decommissioning processes for AI agents.
65% of enterprises have experienced at least one AI agent-related incident in the past 12 months.
51% of unknown AI agents emerge in internal automation or scripting environments.
35% of enterprises report financial losses from AI agent-related incidents.
68% of enterprises report high confidence in their visibility into AI agents.
40% of unknown AI agents emerge in developer-created workflows.
24% of enterprises rely on human-in-the-loop models for most AI agent tasks.
11% of enterprises automatically block actions when AI agents exceed their scope.
63% of enterprises use action risk as a primary signal for governing AI agent behavior.
66% of enterprises have clear guardrails for defining AI agent boundaries.
40% of unknown AI agents emerge in SaaS tools with built-in automation.
82% of enterprises have discovered previously unknown AI agents in the past year.