Enterprises Say Their AI Agents Are Secure; The Data Say Otherwise
SecureWorld, Monday, August 31st, 2026
94% of leaders are confident their agents lack excess access; only 33% have actually scoped least privilege.
A survey of 202 enterprise IT and security leaders by EMA finds agentic AI already operational rather than experimental: 46% are scaling agents across multiple departments and production workflows, 31% are moving prototypes into production, and only 2.5% have paused over risk.
More than 43% run six to 20 active agents and nearly 40% run over 20, embedded in help desk automation, software development, security operations and support.
The headline gap is between belief and practice - 94% expressed at least moderate confidence agents do not have more access than needed, but only 32.7% provision least-privilege access scoped to the task, with 38.1% relying on broad standing access reviewed only periodically.