AI Governance Library

Enterprise AI Security Starts With AI Agents

The risk associated with AI agents is no longer theoretical. Survey findings indicate that autonomous systems are already exceeding intended permissions and operating outside intended scope in day-to-day efforts. In many environments, these behaviors occur at least occasionally.
Enterprise AI Security Starts With AI Agents

⚡ Quick Summary

Co-authored by the Cloud Security Alliance (CSA) and Zenity, Enterprise AI Security Starts With AI Agents presents findings from a survey of 445 IT and security professionals conducted in late 2025. The report establishes that agentic AI has moved into widespread production, with 43% of organizations reporting that over half their workforce uses AI agents regularly. However, governance and defensive controls lag significantly behind adoption: 47% of organizations experienced a security incident involving an AI agent in the past 12 months, and 53% report that agents occasionally or frequently exceed their intended permissions. Because organizations average multi-platform deployments with unclear ownership and limited runtime guardrails, compliance frameworks often serve as an imperfect stand-in for cohesive security strategies.

🧩 What's Covered

This empirical survey report explores the deployment, operational challenges, security posture, and governance mechanisms surrounding autonomous enterprise AI agents. Key findings and data points covered across the document include:

  • Adoption Scale and Platform Proliferation: Beyond high workforce penetration (43% with >50% usage), 43% of enterprises deploy across four or more agentic platforms (such as OpenAI Agents/Operator, Microsoft Copilot/Azure OpenAI, and Google Vertex AI), with only 5% operating on a single centralized platform. Primary functional use centers on IT (53%), security (37%), customer service (34%), and engineering (34%).
  • The Rise of Shadow AI Agents and Ownership Deficits: 47% of organizations report operating 101 or more unsanctioned AI agents. Furthermore, accountability remains fractured: only 15% state that 76–100% of their agents have clearly defined owners, while the plurality (34%) report ownership definitions covering only 26–50% of agents.
  • Scope Violations and Incident Detection Gaps: Only 8% of organizations state that agents never exceed intended permissions. Incidents are frequent (47% in the past year), with detection and response taking 5 to 24 hours for 38% of respondents and over a day for 20%. Only 16% express high confidence in their tools to detect agent-specific threats like prompt injection, cost abuse, secrets exposure, and over-privileged actions.
  • Governance Defaulting to Compliance: Only 31% have formally adopted AI agent governance policies. In lieu of internal strategies, organizations rely on HIPAA (43%), NIST AI RMF (37%), and SOC 2 / ISO 27001 (34%). Yet, only 13% feel highly prepared for upcoming AI-specific regulations.

💡 Why it matters?

The report demonstrates a structural shift in enterprise cybersecurity: the primary attack and failure surface is transitioning from static infrastructure and static access rights to autonomous execution and real-time behavior. When autonomous systems interact with sensitive enterprise data—such as financial records (39%), customer data (37%), and credentials (22%)—scope creep and prompt injection transform minor software anomalies into major enterprise exposures. Relying on legacy perimeter defenses and standard compliance checklists fails to contain non-deterministic, agentic tool invocation.

❓ What's Missing

As an empirical survey report, the publication focuses on quantitative benchmarks rather than technical control specifications. It does not provide detailed technical implementation playbooks, model context protocol (MCP) server security architecture diagrams, or step-by-step remediation workflows for compromised agents. Readers looking for concrete policy templates or code-level runtime guardrails will need to consult supplementary technical guidance.

👥 Best For

Chief Information Security Officers (CISOs), AI security architects, IT governance leaders, compliance officers, and risk managers overseeing enterprise agentic workflows and multi-agent systems.

📄 Source Details

Published by: Cloud Security Alliance (CSA) & Zenity
Publication Date: 2026
Methodology: Online survey of 445 IT and security professionals conducted in September and November 2025 across Americas (57%), EMEA (27%), and APAC (15%).

📝 Thanks to

Lead author Hillary Baron, alongside contributors Marina Bregkou, Josh Buker, and Ryan Gifford, and the Cloud Security Alliance research team in collaboration with Zenity.

About the author
Jakub Szarmach

AI Governance Library

Curated Library of AI Governance Resources

AI Governance Library

Great! You’ve successfully signed up.

Welcome back! You've successfully signed in.

You've successfully subscribed to AI Governance Library.

Success! Check your email for magic link to sign-in.

Success! Your billing info has been updated.

Your billing was not updated.