Cloud Security Alliance (CSA) & Zenity
All Statistics
49% of enterprises feel slightly or not at all prepared for upcoming AI-related regulations.
50% of enterprises have at least partially documented governance policies for AI agent usage.
31% of enterprises have formally adopted a governance policy for AI agent usage.
15% of enterprises report that 76–100% of AI agents have defined ownership.
54% of enterprises report having between 1 and 100 unsanctioned AI agents.
16% of enterprises report high confidence in their ability to detect AI agent-specific threats.
53% of enterprises have had AI agents exceed their intended permissions, leaving them vulnerable to increased risk.
47% of enterprises experienced a security incident involving an AI agent in the past year.
43% of enterprises report that more than half of employees use AI agents regularly.
13% of enterprises feel highly prepared for upcoming AI-related regulations.
AI agent usage occurs in IT (53%), Security (37%), Customer Service (34%), and Engineering (34%).
34% of enterprises report ownership visibility for just 26–50% of their AI agents.
44% of enterprises report low or no confidence in their ability to detect AI agent-specific threats.
8% of enterprises say AI agents never exceed their intended permissions.
HIPAA (43%), the NIST AI Risk Management Framework (37%), and SOC 2 or ISO 27001 (34%) are the frameworks that most influence enterprises' AI agent governance.