AI Agents Outpace Enterprise Guardrails
65% of enterprises have seen AI agents act out of scope, with weak detection and authorization gaps.
Most enterprises are discovering that their AI agents sometimes do things they weren't supposed to. A new report from Enterprise Management Associates (EMA), compiled for Cequence Security, found that 65% of surveyed organizations have seen AI agents act outside their intended scope, and 29% reported measurable organizational impact from those actions.
The report, titled Agents Without Guardrails, is based on responses from 202 enterprise technology and security leaders. It paints a picture of rapid deployment outpacing the controls meant to keep agents in check.
Scaling Up, But Not Securing
Adoption is clearly moving beyond pilots. Some 46% of respondents said their organizations were already scaling agentic AI across multiple departments and production workflows, while nearly 79% were running generative and agentic AI simultaneously.
Yet that scale hasn't come with proportionate oversight. The report suggests that many companies are pushing agents into production faster than they can secure them.
Detection and Response Lag
The ability to respond to out-of-scope actions was found to be weak. Only 32.2% of respondents said they could detect and contain an out-of-scope action within minutes using automated mechanisms, while 54.5% needed hours and manual intervention.
Just over 46% also said they could not easily produce a complete audit trail of a specific agent's activity over the previous 30 days.
Authorization Gaps
Authorization was another gap in many organizations' current approaches. Only 34.2% evaluated whether an agent was authorized to act at execution time, with others relying on standing permissions, periodic reviews, or inherited access.
The report tied that gap to overprovisioning. While 94% were at least somewhat confident their agents did not hold more access than they needed, only 32.7% provisioned agents with least privilege.
"Most organizations have policies in place and express real confidence in them," Steffen said. "The gap is between what's written down and what's enforced."
— Christopher M. Steffen, Vice President of Research at EMA and the report's author
Identity and Inventory Issues
The survey also identified risk after pilots ended. Some 30% of agentic AI pilots had been paused indefinitely or formally discontinued, with security risk concerns a major factor in 48.5% of stalls.
The report said many were not cleaned up, despite having been provisioned with credentials and production access.
Identity enforcement was uneven. While 54.5% required and enforced unique identities for all AI agents, 32.2% required them without consistently enforcing the mandate, and 3% said agents shared or inherited credentials from user or service accounts.
Visibility was a related problem. Some 47% of respondents lacked a reliable agent inventory, despite many organizations running dozens of agents in production.
Near Misses and External Discovery
Alongside those incidents, 35.6% of respondents had caught a near-miss before experiencing material harm. Some 3.5%, seven organizations, said they most often first learned of out-of-scope behavior when a customer or partner reported it.
Key Data Points
- 65% of enterprises have seen AI agents act out of scope
- 29% reported measurable organizational impact
- Only 32.2% can detect and contain out-of-scope actions within minutes automatically
- 54.5% need hours and manual intervention
- Only 34.2% evaluate agent authorization at execution time
Why It Matters
The report's recommendations—evaluating agent authorization at runtime, building automated detection and containment before expanding deployments, and treating agent decommissioning as a security discipline—offer a path forward. But the current gaps suggest that many organizations are running ahead of their ability to govern these systems.
This could mean that as agentic AI continues to scale, the risk of out-of-scope actions grows not just in likelihood but in potential impact. The fact that most incidents are caught only after manual review, and that many organizations lack a full audit trail, suggests that the true scope of the problem may be underestimated. For enterprises, the message is clear: the time to tighten guardrails is now, before the next incident involves more than a near-miss.
Sources
- Infosecurity Magazine Original source
Continue Reading
AI Exploit Porting: Fast, Costly, Still Needs Humans
Forescout researchers used Claude to port a PLC exploit, revealing AI's potential and limits in attack development.
OpenClaw 2.0: New shine, same security risks
OpenClaw's big update simplifies setup and revamps the UI, but security gaps remain, and critics say the fixes are insufficient.
Claude Code Hijack via Website Summary
Researchers show Anthropic's Claude Code can be tricked into running malicious code by summarizing a website.