Security Magazine logo
search
cart
facebook twitter linkedin youtube
  • Sign In
  • Create Account
  • Sign Out
  • My Account
Security Magazine logo
  • NEWS
    • Security Newswire
    • Technologies & Solutions
  • MANAGEMENT
    • Leadership Management
    • Enterprise Services
    • Security Education & Training
    • Logical Security
    • Security & Business Resilience
    • Profiles in Excellence
  • PHYSICAL
    • Access Management
    • Fire & Life Safety
    • Identity Management
    • Physical Security
    • Video Surveillance
    • Case Studies (Physical)
  • CYBER
    • Cybersecurity News
    • More
  • BLOG
  • COLUMNS
    • Career Intelligence
    • Cyber Tactics
    • Cybersecurity Education & Training
    • Leadership & Management
    • Security Talk
  • EXCLUSIVES
    • Annual Guarding Report
    • Most Influential People in Security
    • The Security Benchmark Report
    • Top Guard and Security Officer Companies
    • Top Cybersecurity Leaders
    • Women in Security
  • SECTORS
    • Arenas / Stadiums / Leagues / Entertainment
    • Banking/Finance/Insurance
    • Construction, Real Estate, Property Management
    • Education: K-12
    • Education: University
    • Government: Federal, State and Local
    • Hospitality & Casinos
    • Hospitals & Medical Centers
    • Infrastructure:Electric,Gas & Water
    • Ports: Sea, Land, & Air
    • Retail/Restaurants/Convenience
    • Transportation/Logistics/Supply Chain/Distribution/ Warehousing
  • EVENTS
    • Industry Events
    • Webinars
    • Solutions by Sector
    • Security 500 Conference
  • MEDIA
    • Interactive Spotlight
    • Photo Galleries
    • Podcasts
    • Polls
    • Videos
      • Cybersecurity & Geopolitical Discussion
      • Ask Me Anything (AMA) Series
  • MORE
    • Call for Entries
    • Classifieds & Job Listings
    • Newsletter
    • Sponsor Insights
    • Store
    • White Papers
  • EMAG
    • eMagazine
    • This Month's Content
    • Advertise
  • SIGN UP!
CybersecuritySecurity NewswireCybersecurity News

Only 33% of AI Agents Provisioned With Least-Privilege Access

By Jordyn Alger, Managing Editor
Fingerprint on laptop
Immo Wegmann via Unsplash
August 31, 2026

Research from Cequence Security and Enterprise Management Associates (EMA) reveals a mere 33% of AI agents are provisioned with least-privileged access, yet 94% are confident their agents don’t have more access than necessary. The remaining two-thirds are dependent on broader standing permissions reviewed periodically, rarely, or not at all. 

Key findings from the report include: 

  • 65% have had AI agents take action outside of their intended roles, with 29% having a measurable business impact. 36% were caught moments before causing measurable business impact. 
  • 32% can detect and quarantine out-of-scope agent action within minutes via automated means; 55% require hours and manual steps. 
  • 34% evaluate an agent’s authorization the moment it attempts a certain action. 
  • 14% allow agents to connect to outside tools and data sources without restriction. 
  • 4% discovered out-of-scope concerns from outside partners or customers rather than internal systems. 

Security Leaders Weigh In

Christopher M. Steffen, CISSP, CISA, Vice President of Research at Enterprise Management Associates (EMA):

This research demonstrates that enterprises have moved well past experimentation with agentic AI right into production, and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organizations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.

Randolph Barr, Chief Information Security Officer at Cequence Security:

What jumps out most is that 94% confidence sitting right next to only 33% of agents provisioned with least privilege. In my experience that confidence is usually measuring compliance, not cyber; there’s a policy, people go through a workflow and agree to a set of "thou shalt nots," and the assumption is that following the process means you’re secure. But that only holds if the person creating the agent gets it right, and most orgs don’t have the technical controls in place to actually manage, monitor, and enforce what that agent does once it’s live. 

As a CISO, not knowing what you don’t know is what keeps me up at night, so if I were telling someone where to start, it’s get a real inventory of every agent you actually have running, then go agent by agent and ask two questions: what is it actually doing versus what it was scoped to do, and is it operating on its own defined access or did it just inherit the permissions of whoever created it. That last one gets missed constantly, and it’s exactly how an agent ends up with far more reach than anyone intended.

Aviv Nahum, Co-founder and CEO at Above Security:

AI permissions and configuration are more consequential now than ever. Knowing this, organizations must treat AI agents as first-class identities and a new class of insiders. Understanding which agents are deployed and what they’re doing, who manages those tools, and what systems or credentials they have access to, is essential to identifying risks associated with synthetic insiders. This enables teams to assess agentic activity and determine whether behavior makes sense or is a red flag. But achieving this level of intelligence requires a new approach that closes the gaps left open by traditional bot management approaches. To combat the speed of AI agents, the defensive model must continuously investigate the behaviors of both humans and synthetic agents with built-in triggers that automate intervention when suspicious behaviors are detected.

Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint:

AI has made it easier for bad actors to generate bots and automated threats, and it’s also expanded the threat surface that organizations must cover. This has contributed to an increase in malicious and non-malicious breaches. AvePoint’s research found, for example, that 88% of organizations experienced an AI-related breach in the last year, as AI became increasingly capable and widely used — by both good actors and bad. 

The most effective defenses combine least-privilege access, strong identity controls, continuous monitoring, audit trails, and human approval for high-risk actions. Organizations are increasingly treating AI agents like non-human employees that require governance and oversight. The biggest gaps are visibility, control, and trust: many organizations still don’t know which agents are operating, what permissions they have, or how they’re making decisions. As agents become more autonomous, governance and observability are struggling to keep pace with adoption. This has led to a trust gap in AI systems that organizations must work to repair.

Chris Radkowski, Security and Risk Expert at Pathlock:

The rise of AI agents and machine identities has fundamentally outpaced traditional identity security. As agentic AI takes on real business actions with real permissions, the attack surface expands in ways most organizations aren’t prepared to see, let alone secure. Credential abuse, account takeover, and sophisticated social engineering are increasingly targeting the non-human identities (NHIs) that operate quietly in the background with little oversight. That is why we believe that securing the modern enterprise means treating identity holistically by extending governance, least-privilege, and adaptive controls across every identity, human, or machine. In the AI era, identity isn’t just an IT problem. It’s the foundation of trust itself.

KEYWORDS: artificial intelligence (AI) Artificial Intelligence (AI) Security identity (ID) management least privileged access

Share This Story

Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!

Jordynalger

Jordyn Alger is the managing editor for Security magazine. Alger writes for topics such as physical security and cyber security and publishes online news stories about leaders in the security industry. She is also responsible for multimedia content and social media posts. Alger graduated in 2021 with a BA in English – Specialization in Writing from the University of Michigan. Image courtesy of Alger

Recommended Content

JOIN TODAY
To unlock your recommendations.

Already have an account? Sign In

  • Cyber tech background

    Security’s Top Cybersecurity Leaders 2026

    Security magazine’s Top Cybersecurity Leaders 2026 award...
    Cybersecurity
  • Iintegration and use of emerging tools

    Future Proof Your Security Career with AI Skills

    AI’s evolution demands security leaders master...
    Security Education & Training
    By: Jerry J. Brennan and Joanne R. Pollock
  • The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report

    The 2025 Security Benchmark Report surveys enterprise...
    The Security Benchmark Report
    By: Rachelle Blair-Frasier
Manage My Account
  • Security Newsletter
  • eMagazine Subscriptions
  • Manage My Preferences
  • Online Registration
  • Mobile App
  • Subscription Customer Service

More Videos

Sponsored Content

Sponsored Content is a special paid section where industry companies provide high quality, objective, non-commercial content around topics of interest to the Security audience. All Sponsored Content is supplied by the advertising company and any opinions expressed in this article are those of the author and not necessarily reflect the views of Security or its parent company, BNP Media. Interested in participating in our Sponsored Content section? Contact your local rep!

close
  • Northland Controls sponsored content
    Sponsored byNorthland Controls

    The Execution Gap: Why Great Security Design Doesn't Always Deliver Great Security

Popular Stories

security

6 Crisis Response Best Practices (That Actually Hold Up When Things go Sideways)

Photograph of apartment complex patios

Enhancing Residential Building Security

Man in suit looking out window at city

Why GSOCs and Protective Intelligence Are the Cornerstone of Executive Protection

5 Minutes with Johnson

Can Organizations Trust Their Own AI?

Patient in bed

When Cyberattacks Hit Medical Devices, Patients Pay the Price

Events

August 27, 2026

Leveraging AI & Mobility to Advance Your Security Domain

LIVE: August 27, 2026 at 2 PM EDT Explore how AI-driven cloud security solutions can elevate your security domain enhancing threat detection, streamlining operations, and delivering the resilience modern organizations demand.

September 10, 2026

So, You Have an Emergency Management Plan… Now What?

LIVE: September 10, 2026 at 2 PM EDT Turning an emergency management plan into an actionable program that prepares staff, students, and partners to respond effectively is a challenge. Learn to move beyond compliance and build a resilient school safety program.
View All Submit An Event

Products

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products


Alertmedia sponsored webinar

Related Articles

  • Robinhood on laptop

    Risks of Robinhood Using AI Agents to Trade, Make Purchases

    See More
  • AI

    93% of Organizations Use or Plan to Use AI Agents for Sensitive Security Tasks

    See More
  • Name tags

    Estonia to Grant Digital IDs to AI Agents

    See More

Related Products

See More Products
  • security culture.webp

    Security Culture: A How-to Guide for Improving Security Culture and Dealing with People Risk in Your Organisation

See More Products

Events

View AllSubmit An Event
  • June 3, 2026

    The Role of AI and Video in Measuring Health, Safety, and Security Standards

    ON DEMAND: OSHA fines grab headlines, but most compliance issues start with everyday operational gaps: missed protocols, unsecured areas, or slow response. Learn how emerging technologies & AI can be leveraged towards more proactive compliance.
  • May 7, 2026

    Beyond Cameras: Revolutionizing Perimeter Security with LiDAR, AI and Digital Twins

    ON DEMAND: In this webinar, we will explore how LiDAR‑based detection, AI‑powered analytics and digital twins are transforming the future of perimeter protection with 3D detection, real-time situational awareness and unified operational views.
View AllSubmit An Event
×

Sign-up to receive top management & result-driven techniques in the industry.

Join over 20,000+ industry leaders who receive our premium content.

SIGN UP TODAY!
  • RESOURCES
    • Advertise
    • Contact Us
    • Store
    • Want More
  • SIGN UP TODAY
    • Create Account
    • eMagazine
    • Newsletter
    • Customer Service
    • Manage Preferences
  • SERVICES
    • Marketing Services
    • Reprints
    • Market Research
    • List Rental
    • Survey/Respondent Access
  • STAY CONNECTED
    • LinkedIn
    • Facebook
    • YouTube
    • X (Twitter)
  • PRIVACY
    • PRIVACY POLICY
    • TERMS & CONDITIONS
    • DO NOT SELL MY PERSONAL INFORMATION
    • PRIVACY REQUEST
    • ACCESSIBILITY

Copyright ©2026. All Rights Reserved BNP Media, Inc. and BNP Media II, LLC.

Design, CMS, Hosting & Web Development :: ePublishing