Only 33% of AI Agents Provisioned With Least-Privilege Access

Research from Cequence Security and Enterprise Management Associates (EMA) reveals a mere 33% of AI agents are provisioned with least-privileged access, yet 94% are confident their agents don’t have more access than necessary. The remaining two-thirds are dependent on broader standing permissions reviewed periodically, rarely, or not at all.
Key findings from the report include:
- 65% have had AI agents take action outside of their intended roles, with 29% having a measurable business impact. 36% were caught moments before causing measurable business impact.
- 32% can detect and quarantine out-of-scope agent action within minutes via automated means; 55% require hours and manual steps.
- 34% evaluate an agent’s authorization the moment it attempts a certain action.
- 14% allow agents to connect to outside tools and data sources without restriction.
- 4% discovered out-of-scope concerns from outside partners or customers rather than internal systems.
Security Leaders Weigh In
Christopher M. Steffen, CISSP, CISA, Vice President of Research at Enterprise Management Associates (EMA):
This research demonstrates that enterprises have moved well past experimentation with agentic AI right into production, and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organizations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.
Randolph Barr, Chief Information Security Officer at Cequence Security:
What jumps out most is that 94% confidence sitting right next to only 33% of agents provisioned with least privilege. In my experience that confidence is usually measuring compliance, not cyber; there’s a policy, people go through a workflow and agree to a set of "thou shalt nots," and the assumption is that following the process means you’re secure. But that only holds if the person creating the agent gets it right, and most orgs don’t have the technical controls in place to actually manage, monitor, and enforce what that agent does once it’s live.
As a CISO, not knowing what you don’t know is what keeps me up at night, so if I were telling someone where to start, it’s get a real inventory of every agent you actually have running, then go agent by agent and ask two questions: what is it actually doing versus what it was scoped to do, and is it operating on its own defined access or did it just inherit the permissions of whoever created it. That last one gets missed constantly, and it’s exactly how an agent ends up with far more reach than anyone intended.
Aviv Nahum, Co-founder and CEO at Above Security:
AI permissions and configuration are more consequential now than ever. Knowing this, organizations must treat AI agents as first-class identities and a new class of insiders. Understanding which agents are deployed and what they’re doing, who manages those tools, and what systems or credentials they have access to, is essential to identifying risks associated with synthetic insiders. This enables teams to assess agentic activity and determine whether behavior makes sense or is a red flag. But achieving this level of intelligence requires a new approach that closes the gaps left open by traditional bot management approaches. To combat the speed of AI agents, the defensive model must continuously investigate the behaviors of both humans and synthetic agents with built-in triggers that automate intervention when suspicious behaviors are detected.
Dana Simberkoff, Chief Risk, Privacy, and Information Security Officer at AvePoint:
AI has made it easier for bad actors to generate bots and automated threats, and it’s also expanded the threat surface that organizations must cover. This has contributed to an increase in malicious and non-malicious breaches. AvePoint’s research found, for example, that 88% of organizations experienced an AI-related breach in the last year, as AI became increasingly capable and widely used — by both good actors and bad.
The most effective defenses combine least-privilege access, strong identity controls, continuous monitoring, audit trails, and human approval for high-risk actions. Organizations are increasingly treating AI agents like non-human employees that require governance and oversight. The biggest gaps are visibility, control, and trust: many organizations still don’t know which agents are operating, what permissions they have, or how they’re making decisions. As agents become more autonomous, governance and observability are struggling to keep pace with adoption. This has led to a trust gap in AI systems that organizations must work to repair.
Chris Radkowski, Security and Risk Expert at Pathlock:
The rise of AI agents and machine identities has fundamentally outpaced traditional identity security. As agentic AI takes on real business actions with real permissions, the attack surface expands in ways most organizations aren’t prepared to see, let alone secure. Credential abuse, account takeover, and sophisticated social engineering are increasingly targeting the non-human identities (NHIs) that operate quietly in the background with little oversight. That is why we believe that securing the modern enterprise means treating identity holistically by extending governance, least-privilege, and adaptive controls across every identity, human, or machine. In the AI era, identity isn’t just an IT problem. It’s the foundation of trust itself.
Looking for a reprint of this article?
From high-res PDFs to custom plaques, order your copy today!







