94% Confident, 33% Enforced: The AI Agent Governance Gap Is the Real Enterprise Risk

New Cequence Security & EMA research finds nearly every enterprise believes its AI agents are properly scoped — yet only a third enforce least-privilege access. The gap between confidence and enforcement is exactly where agentic AI programs break.
On August 31, 2026, Cequence Security and Enterprise Management Associates (EMA) published research that should be required reading for anyone deploying AI agents in production. EMA surveyed 202 enterprise IT and security leaders — CIOs, CTOs, CISOs, and IT directors at organizations with 1,000 or more employees — and found that 94% are confident their AI agents don't have more access than they need. Only 33% actually provision agents with least-privilege access.
Read that again. Nearly every enterprise believes its agents are properly scoped. Only a third has made sure of it. The other two-thirds run on broad standing permissions that are reviewed periodically, rarely, or never.
The Gap Is Already Producing Incidents
This isn't a theoretical risk. Among the organizations surveyed:
- 65% have experienced an AI agent take an action outside its intended scope — including 29% with measurable business impact: data exposure, financial loss, operational disruption, or reputational damage.
- Only 32% can detect and contain an out-of-scope agent action within minutes through automated means. 55% need hours and manual steps.
- Only 34% evaluate an agent's authorization at the moment it attempts a specific action. The rest rely on standing permissions set once at provisioning.
- 31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned — many with live credentials that were never cleaned up.
That last number deserves more attention than it gets. An abandoned pilot with live system access is exposure nobody is actively watching. The survey found that in roughly 4% of organizations, the first sign of an agent problem came from a customer or outside partner — not an internal system.
This Is Not a Capability Problem
The industry narrative treats agent failures as a model-quality problem: the AI wasn't smart enough, hallucinated, misunderstood. The Cequence/EMA data tells a different story. The same survey found 46% of organizations are already scaling agentic AI across multiple departments and production workflows. The agents work. What's missing is the enforcement layer around them.
Governance has not kept pace with deployment speed — at provisioning, at the moment of action, and at decommissioning. Trust without enforcement is exactly why pilots stall, get paused, or quietly leave credentials behind.

"The industry doesn't have an agent-capability problem — it has an agent-governance problem. If your agent's permissions were set once at provisioning and nobody has looked at them since, you don't have a governed agent. You have a standing credential with a language model attached."
What Governed by Design Actually Means
At Pyra, we build agents around the enforcement layer, not the other way around. In practice, closing the confidence-enforcement gap requires four things:
- Approval gates. High-consequence actions pause for a human decision. Not a notification after the fact — a gate before the action.
- Role-based access control. Agents get the minimum access the workflow requires, evaluated when the agent acts, not just when it's provisioned.
- Full audit trails. Every action, every input, every decision — logged and reviewable. When something goes out of scope, you find out in minutes, not from a customer.
- Client-instanced isolation. Each deployment runs in its own environment. A scope problem in one instance can't become everyone's problem.
This is the architecture behind our platform and every agent we deploy. It's also why we're skeptical of general-purpose agents bolted onto existing systems with broad standing permissions — the survey data shows exactly where that road leads.
Three Questions to Ask This Week
- Can you list every AI agent in your environment with live credentials — including paused pilots?
- Is authorization evaluated when your agents act, or only when they were provisioned?
- If an agent took an out-of-scope action right now, would you learn about it in minutes — or from a customer?
If any answer is uncomfortable, the gap in the Cequence/EMA data is your gap too. The good news: it's closeable, and closing it is what turns a stalled pilot into a production system. See how we approach it on our security page, or talk to us about a governance review of your current agent footprint.
Source: Cequence Security & EMA, "Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise," announced August 31, 2026. Survey of 202 enterprise IT and security leaders at organizations with 1,000+ employees, North America and EMEA. Statistics cited as reported by the study's authors; verified September 2, 2026.

