Quick Facts

  • 88% of organizations reported AI agent security incidents last year, with the average cost of an AI-powered breach reaching $5.72 million
  • Only 17% of enterprises have deployed AI agents, despite 42% planning deployment within 12 months due to permissions management challenges
  • The average organization experiences 223 AI-related data policy violations per month, with incidents increasing 56.4% year-over-year

Enterprise AI agents are hitting a wall — and it’s not model performance. The real bottleneck is permissions.

Organizations struggle to define what AI agents can access, on whose behalf, and how systems verify those permissions. This governance challenge has become the primary barrier preventing widespread AI agent adoption in enterprises.

“Frankly, that’s where we see customers struggling when they try to build do-it-yourself AI by just accessing raw data, so the richness of the security model gets lost, and the results become overly broad,” said Gerrit Kazmaier, president for product and technology at Workday.

The numbers tell a stark story. While 88% of organizations reported AI agent security incidents last year, only 24.4% have full visibility into which AI agents communicate with each other. The average organization now manages 37 deployed agents.

Traditional identity and access management systems were built for human users who log in and out. AI agents operate continuously, span multiple applications, and generate activity at machine speed. They inherit user privileges but lack human judgment about when not to use available access.

“Identity is security,” said Todd McKinnon, CEO of Okta. “When you move AI into production, you give agents access to real systems, real data and your customer data. One compromised agent identity cascades across millions of automated actions.”

The financial stakes are rising. AI-powered breaches cost an average of $5.72 million, while shadow AI breaches cost $670,000 more than traditional incidents. EU AI Act fines reach up to €35 million or 7% of global annual revenue.

Companies are responding with governance-first approaches. Workday completed its $1.1 billion acquisition of Sana in November 2025, building AI agents directly on existing security and governance models. Over 400 Workday customers now use self-service agents for HR and finance tasks.

“It has to live in the system of record, that’s not a preference, that’s the only way it works,” said Dan Obendorfer, director of product at Würk. “If your permissions are defined somewhere outside of where the data actually lives, you’ve already lost.”

Gartner projects 33% of enterprise software applications will include agentic capabilities by 2028, up from under 1% in 2024. But a Kiteworks survey found that while 100% of security leaders have agentic AI on their roadmap, most cannot stop agents when something goes wrong.

Microsoft requires a single identity for every agent, making actions attributable and enforceable. ServiceNow launched Autonomous Security & Risk to govern AI agent identities and permissions across enterprises.

The governance-containment gap represents the defining security challenge of 2026, with organizations deploying AI agents faster than they can govern them.

Read more: The AI agent bottleneck isn’t model performance

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.