At many organizations, AI agents are no longer experimental. Eighty-one percent of technical teams are actively using or producing agents capable of autonomous actions on behalf of employees, according to a February 2026 report on AI agent security released by vendor Gravitee.
This growing set of autonomous AI tools is insufficiently governed at many organizations, according to Gravitee and two other 2025 and 2026 security vendor surveys. The three reports agree that unintended incidents and breaches are already occurring. They found similar shortcomings among surveyed companies, including partial policies, limited monitoring and inadequate treatment of agents as risky identities circulating in their systems.
NIST has advanced AI agent governance efforts by officially requesting information about methodologies for improving the secure use of AI agent systems, with responses that were due March 9, 2026. Additionally, comments on a proposed NIST paper about managing agents’ privileges in computer systems are due April 2, 2026.
This article, the first in a two-part series on AI agent security, examines early AI agent governance benchmarks, incident types and origins, maturity of tailored controls and data access concerns. Part two will provide a playbook for CISOs and their colleagues to strengthen security and reduce risks around AI agents.
See “From CEO Deepfakes to AI Slop, AI Incident Tracking Ramps Up” (Jul. 30, 2025).
The Three Studies
Each of the three studies on AI agents is based on surveys conducted during 2025. NeuralTrust based its “The State of AI Agent Security 2026” (NeuralTrust Report) on surveys that were conducted in August and September 2025. Gravitee rooted its “State of AI Agent Security 2026” (Gravitee Report) in surveys conducted in December 2025 and January 2026. SailPoint issued its “AI agents: The new attack surface” (SailPoint Report) in May 2025.
SailPoint procured responses from 353 IT/security practitioners or leaders, while Gravitee surveyed 919 technology executives and technical practitioners, and NeuralTrust gathered information from more than 160 CISOs and security leaders.
The findings in the three reports broadly align on companies’ level of usage, oversight gaps and incident prevalence. The reports also revealed that while many companies have already witnessed rogue behavior from their AI agents, their leaders are not deterred from advancing agent development.
See “Risk and Compliance Survey Highlights the Role of Compliance in AI Governance” (Oct. 29, 2025).
Adoption Outpacing Security Measures
The three surveys each illuminate a structural gap between use and controls, describing a shared pattern: roughly four out of five companies now use AI agents to a significant degree, but only half implemented some initial governance for agents.
The reports’ usage statistics line up. SailPoint found “82% of companies are already using AI agents,” while Gravitee said that “81% of teams are past the planning phase.” NeuralTrust concluded that “enterprises are deploying AI agents faster than they can secure them. 72% have implemented or are scaling AI agents.”
NeuralTrust conveyed the nuance that many organizations are moving cautiously with agent implementation rather than letting a herd of AI agents run amok on the job. Only 10% of companies stated they had fully deployed agents, and only 4% reported scaling agents across multiple departments.
The reports had parallel findings on companies’ central governance levels for AI agents as well, although the authors gathered slightly different data.
- Sailpoint reported on policies. “Only 44% currently have any governance policies in place for AI agents,” it found.
- Gravitee assessed monitoring and security approval. “On average, only 47.1% of an organization’s AI agents are actively monitored or secured,” Gravitee reported. “Only 14.4% have achieved ‘full’ IT and security approval for their entire agent fleet,” and 45% obtained a “good” level of approval, it noted. The rest had approval for some agents or “hardly any.”
- NeuralTrust looked at security controls. “Only 29% report comprehensive AI-specific security controls,” it found. “A quarter (25%) have no AI-specific controls at all.”
See “How Under Armour and People Inc. Took AI Governance From Crawl to Walk to Run” (Sep. 24, 2025).
Internal and External Incidents Reported
The reports reveal some troubling agent interactions with external players, but also treat many episodes that occurred inside organizations, where deployed agents took unintended or unauthorized actions, as “incidents.”
Prevalence of Incidents
“An overwhelming 88% of organizations report either confirmed or suspected AI agent security or privacy incidents within the last year,” the Gravitee Report states. Likewise, 80% of those surveyed by SailPoint revealed that “AI agents have performed unintended actions of accessing and sharing inappropriate data.”
NeuralTrust gathered fewer tales of incidents, sharing that “1 in 5 organizations report at least one AI agent–related breach, mostly from prompt injection or data exposure.”
Types of Incidents
The agent-fueled incidents reported by those surveyed by NeuralTrust include:
- “prompt injection/adversarial manipulation” (68%);
- “data leakage of sensitive or regulated data” (61%);
- “harmful or false customer interactions” (46%);
- “misuse or abuse by users or end customers” (41%); and
- “compromise of third-party plugin/model/API (application programming interface)” (28%).
Of those incidents, respondents characterized 36% as “a compliance or regulatory breach.” The NeuralTrust Report notes that only 3% of the incidents involved “unauthorized actions/privilege escalation.”
Many episodes that NeuralTrust sees in its work involve agents unexpectedly pulling data from internal sources or misusing data internally, company researcher Alessandro Pignati told the Cybersecurity Law Report.
Gravitee shared with the Cybersecurity Law Report a further breakdown of the incidents set forth in its report. A company representative cautioned that AI produced the following analysis of the 919 responses. In order of seriousness, the incidents include:
- adversarial attacks and malicious exploitation, labeled highly serious (5%);
- data retention and privacy violations (15%), some highly serious because they involved data regulated under HIPAA or the GDPR;
- data leakage and unauthorized exposures (25%), some labeled highly serious;
- excessive privileges or access control misfires, generally allowing the agent unauthorized access to systems (15%), which carried medium to high seriousness;
- “third-party and vendor risks,” averaging a medium level of seriousness (10%); and
- systemic risks in “governance, oversight and shadow AI” (30%), generally of low or medium seriousness and typically considered “near-misses” or policy violations.
Both the NeuralTrust and Gravitee Reports highlight broadly similar categories of agent‑driven risk – adversarial manipulation, privacy and data‑handling failures, unauthorized access and third‑party exposure – though they use different labels and severity scales. Each report also underscores that many incidents involve data leakage or inappropriate internal data use rather than dramatic, autonomous, high-level takeovers of systems.
See “Recent Developments and Upcoming Obligations Under the E.U. AI Act” (Feb. 4, 2026).
Sample Incidents
The Gravitee Report elaborates on the list of incident types by providing examples. In one example, a financial services practitioner reported that an agent programmed with read-only privileges used elevated permissions to adjust workflows and pursue administrative functions outside its original scope.
In another example, a life sciences startup used an agent that gained “write” privileges in user databases because the human’s instructions “bypassed our input sanitization layer,” an executive told Gravitee, adding that a circuit-breaker control halted the breach in two seconds.
Additionally, a telecom company reported than an internal agent used for task automation “attached some sensitive information and was trying to send outside the organization,” the Gravitee Report recounts.
Cyber vendor Lakera, in a December 2025 report, noted that key attack patterns included prompts designed to convince agents to access confidential internal data, asking an agent to process webpages or files embedded with malicious instructions, and burying executable code into text to travel “through an agent pipeline.” Other incident examples can be found in non-profit OWASP Foundation’s database for agentic AI incidents and vulnerabilities.
Companies discovered agents’ misbehavior by logging account access and monitoring for unexpected calls to APIs, the Gravitee Report states.
See “Defending Against Faster, Stealthier and More Sophisticated Cyber Adversaries” (Sep. 10, 2025).
Partial Progress on Safeguards for Agents
NeuralTrust concluded that 29% of organizations had achieved mature safeguards for agents. Components of maturity, the report enumerates, included dedicated oversight frameworks for agents, some continuous monitoring of agent activity, regular testing of agents and integration of AI oversight into enterprise risk management.
Companies’ Initial Moves to Secure Agent Activity
Many companies (46%) have adapted their legacy security frameworks to address AI agent risks, rather than building an agent-first security approach, NeuralTrust discovered. Because existing security tools were not designed for autonomous systems, they may leave important gaps in monitoring agents' behavior and decisions, Pignati observed.
Companies often begin their agent security efforts with the prompts, which flows from their 2024 and 2025 efforts to control large language models (LLMs), Pignati reported. “They work on the system prompts because they don’t have specific security solutions implemented for agents,” he said. Setting tasks that the agents cannot perform is often the first move, he elaborated. The LLM "legacy" security leads organizations to concentrate on stopping prompts that leak data, hallucinated model outputs and attacks deploying prompts.
Other common initial steps include restricting agents from accepting requests for sensitive information or forcing them to process information only from designated knowledge bases, Pignati observed.
See “How Do You Put a System of Controls in Place When Your Target Keeps Moving?” (Mar. 31, 2021).
Security Focus Shifts to Misuse and Excessive Agency
AI security teams are broadly shifting focus from hallucinations to misuse, a turn back to traditional cybersecurity concerns, Gravitee observed. “Notably, nearly half of respondents now consider ‘misuse or unauthorized access of LLMs’ as a top-tier concern” for AI security efforts, it found.
Security teams also focus on evaluating whether an agent “is too efficient at performing actions it was never intended to do,” Gravitee said. OWASP’s “Top 10 For Agentic Applications 2026” similarly lists “excessive agency” as a top risk, along with prompt injection attacks.
When organizations create safeguards for AI agents, “the focus shifts overwhelmingly toward observability" and controlling their access, Gravitee noted. NeuralTrust agreed, saying that “visibility is the new perimeter” for AI defense.
See “Steps to Address the New California Audit Rule That Seeks to Reset Reasonable Security” (Nov. 5, 2025).
Fragmented Monitoring
The most common safeguard that companies use is monitoring agent activity (42% are doing some agent monitoring), reflecting the prioritization of observability, NeuralTrust found. However, respondents reported their companies' monitoring includes little analysis of agents' behavior.
Although monitoring generally is common, many companies only track a portion of the agents they use, according to the Gravitee Report. Only 3.9% of organizations report that they monitor more than 80% of their AI agents and one-third of organizations (30.9%) actively monitor 40% of their deployed agent fleet, Gravitee reported.
Further, although the ability to monitor AI agents in action is crucial to establishing a user’s trust in the tool, only 7.7% of the Gravitee Report’s respondents audit daily. Many companies (37%) audit monthly and 22% audit weekly, “leaving a significant window for undetected misuse or errors,” Gravitee found.
Monitoring agent-to-agent (A2A) communication, an area of high peril, should be a top concern for companies, but there is limited scrutiny of this by companies as well. “Only 24.4% of organizations report having full visibility into which AI agents are interacting with others,” while 46% claim to have “good” visibility. Thus, many organizations remain “blind to how authority is being delegated internally,” Gravitee noted.
See “Checklist for Selecting Privacy Tech Solutions” (Nov. 1, 2023).
Identity Management Prevalent but Weak
Due to the considerable risk of AI agents taking unintended actions, structural controls are very important. Identity management and credential control is the foremost structural option. SailPoint found that 62% of organizations use their systems to “provision and govern” AI agents. NeuralTrust found that 38% of companies applied their role-based access control software (RBAC) to the new "AI employees."
Yet the reports all concluded that identity management is a major weakness for agent security. Most organizations still treat agents as extensions of human users or generic service accounts, Gravitee reported. Only 21.9% of respondents currently treat AI agents as independent, identity-bearing entities within their security model, which is “the foundational security principle of unique identity,” it cautioned. The rest treated agents as extensions of their users, which leaves significant gaps in auditability and granular access control, it added.
One Gravitee respondent described a situation that many companies may be experiencing. “Honestly, general LLM security is still a concern on an enterprise level, so we have all been using our own personal accounts with the agents,” and will not focus on agent security until the automated workflows are more finalized, the practitioner said.
Some of the companies attempting to follow security principles by giving agents their own identity are creating fresh trouble. Troublingly, in 64% of organizations, "AI agents often rely on several access identities, complicating efforts to track and correlate data usage and sharing,” the SailPoint Report states.
See “Staying Ahead of Rising Identity-Based and Cloud Intrusions” (Mar. 19, 2025).
Controls for Agent-to-Agent Credential Sharing
Whether existing identity solutions can operate as effective structural safeguards for AI agents remains a key issue. Model Context Protocol (MCP) servers became the standard gateway for agent tool access in 2025, yet only 23.7% of organizations had adapted their authentication systems to control access to MCP and other agentic infrastructure, Gravitee noted.
Agents often share an original employee’s passwords with several other agents they invoke while completing tasks, Gravitee chief product officer Linus Håkansson told the Cybersecurity Law Report. “For agent-to-agent interactions, teams rely heavily on insecure or shared methods for authentication,” like API keys (45.6%) and “generic tokens” (44.4%), Gravitee warned in its report. Only 17.8% use “secure standards like mTLS,” a protocol using digital certificates, it added.
Agents’ password handoffs are becoming too complex for some authentication methods. “The secondary agents might invoke multiple different MCP tools, which themselves might invoke APIs, databases, etc. This delegating of permissions makes generic tokens and API keys obsolete and a security risk,” Håkansson said.
While approvals of human employees' credentials typically require multiple managers or executives, SailPoint learned that companies’ IT departments often are the only decision-maker for AI agent access (as reported by 35% of respondents), and companies commonly approve agents’ access in fewer steps than they approve access for humans (as reported by 34% of respondents). “IT may lack full awareness of the specific types of data being accessed – such as customer information, intellectual property, or employee records – by the agent, making it difficult to apply appropriate compliance or sensitivity controls,” its report states.
See “Gauging Uptake of AI in Cybersecurity” (Nov. 12, 2025).
Data Loss Prevention Software
Another key structural safeguard is data protection software. A majority of SailPoint respondents expressed concern about agents sharing privileged or inappropriate data, with 52% claiming that their company can track and audit all data that AI agents use and share.
NeuralTrust found that 31% of companies use data loss protection software to try to thwart any sensitive data leaking, but cautioned that such software often lacks automated enforcement mechanisms to keep up with agents’ quick movement.
Effective governance of AI agents begins with understanding the data that they may access, SailPoint observed, warning its survey revealed that compliance (47%) and legal (39%) often are uninformed about agent data access.
Other Safeguards
Prompt injection filtering (27%) and red teaming (19%) “remain niche,” NeuralTrust found. “Few organizations simulate or anticipate adversarial behavior.” AI supply chain protection (16%) is emerging, “but verifying third-party models, tools, and APIs is still largely manual,” the NeuralTrust Report states.
None of the three reports revealed companies’ practices around implementing human oversight, like the use of stop points to wait for human approval of agent decisions.
Best Practices for Agent Safeguards
NeuralTrust estimated only 10% of its respondents had implemented comprehensive, predictive and autonomous governance for agent security. Businesses in the financial industry led healthcare and telecom companies in establishing structured oversight of agents because of “heavy compliance mandates (Basel III, DORA, NIS2)” in Europe, it noted.
To achieve comprehensive, predictive and autonomous agent security governance, a company should:
- automate monitoring of agent behavior and data interactions;
- conduct adversarial simulation and automatic containment;
- align proactively with emerging AI regulations; and
- aim to create automated “self-learning governance” that constantly refines security controls.
Companies also should prioritize an inventory of all AI agents, given the dispersed rollout of agents across departments without central oversight, Pignati advised.
AI agents are largely invisible to traditional asset management, Gravitee reported. One-quarter of companies rely on manual spreadsheets, and 22.5% have no formal catalog of their agents, it found.
Longstanding security controls built to stop human intruders or malicious software frequently allow AI agents to slip through, according to the NeuralTrust Report. “As AI autonomy expands, traditional defenses, built for human-triggered systems, fail to catch unintended actions, data leaks and adversarial manipulations,” NeuralTrust warned. “AI agents don’t just malfunction, they act. The incidents are less about hacking and more about oversight and control gaps,” it concluded.