Enterprise Management Associates (EMA), an IT research and consulting firm, found 65% of respondents reported an AI agent had acted outside its intended scope or authorized access, according to its Agents Without Guardrails report.

According to the report, 29% reported measurable organizational impact and 36% reported a near miss caught before material impact. Still, just over a third reported no known out-of-scope action, while 1% were unsure whether one had occurred.

The research was prepared for Cequence Security, an application, API and agentic AI security vendor. EMA surveyed 202 IT and security decision-makers at organizations with at least 1,000 employees that were deploying or evaluating agentic AI, according to Cequence’s announcement.

High confidence masks broad access

In the same sample, 94% said they were very or somewhat confident their agents did not have more access than needed. Yet only 33% said new agents received only the access required for their task. Conversely, 38% used broad standing access reviewed periodically.

Authorization practices showed a similar gap. Only 34% said authorization was evaluated when an agent attempted a specific action. Another 38% relied on periodic policy reviews and 21% on standing permissions assigned to the agent.

Automated detection remains limited

The survey found 47% lacked an automated, centralized inventory of all agents operating across their organization. Just 32% said they could detect and contain an out-of-scope action within minutes using automated mechanisms, while 55% said detection could happen within hours but containment required manual steps.

For 4% of respondents, an external party, such as a customer or partner, was the primary way the organization first learned of out-of-scope agent behavior. The report also found 46% could not easily and completely produce a record of a specific agent’s actions over the previous 30 days.

Deployments push forward despite control gaps

Despite the reported control gaps, 46% said their organizations were scaling agentic AI across multiple departments and production workflows and an additional 31% were transitioning successful prototypes into production.

Asked what happened to most agentic AI pilots that did not reach production, 19% said they had been paused indefinitely, 12% said they had been formally discontinued or abandoned and 12% said they had been restarted from scratch.

Survey scope and EMA recommendations

In the report, 91% of respondents worked in technology functions, 71% were at organizations headquartered in North America and 49% worked at organizations with 1,000 to 2,499 employees.

The report does not break down reported impacts by type or severity; examples within the measurable-impact response option included data exposure and financial, operational or reputational consequences.

EMA recommends governing agent actions in real time and building detection and containment capabilities before organizations scale deployments. It also recommends treating decommissioning as a security process.

Personalized Feed
Personalized Feed