Report by Cequence Security
Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise
Key Findings
46% of organizations are already scaling agentic AI across multiple departments and production workflows.
79% of organizations are running generative and agentic AI simultaneously.
More than 92% of organizations report an increase in AI- and bot-driven traffic targeting customer-facing applications and APIs.
Only 34% of organizations evaluate an AI agent’s authorization at the moment it attempts a specific action.
31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned.
36% of organizations catch a near-miss from an AI agent before it causes damage.
32% of organizations can detect and contain an out-of-scope agent action within minutes through automated means.
Approximately 4% of organizations first learn about an AI agent problem from a customer or outside partner rather than an internal system.
94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need.
Only 33% of enterprise IT and security leaders provision AI agents with least-privilege access.
Two-thirds of enterprises run AI agents on broad standing permissions that are reviewed periodically, rarely, or never reviewed at all.
55% of organizations need hours and manual steps to respond to an out-of-scope agent action.
65% of organizations have experienced an AI agent take an action outside its intended scope.
29% of organizations experience measurable business impact from an AI agent acting outside its intended scope, including data exposure, financial loss, operational disruption, or reputational damage.
14% of organizations allow AI agents to connect to outside tools and data sources via the Model Context Protocol (MCP) without restriction.
49% of organizations that limit agent external connections to an approved list have a dedicated team actively maintaining and auditing that list on a regular basis.