2 Sep 2026

Nearly every enterprise believes its AI agents are properly scoped but only a third have actually made sure of it. New research from Cequence Security, the pioneer in application, API, and agentic AI protection, and Enterprise Management Associates (EMA) found that 94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need, yet only 33% actually provision agents with least-privilege access.

The remaining two-thirds run on broad standing permissions that are reviewed periodically, rarely reviewed, or never reviewed at all. The full report, Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise, is available for download now.