IT Brief Australia - Technology news for CIOs & IT decision-makers
Australia
Survey finds AI access controls lag behind confidence

Survey finds AI access controls lag behind confidence

Wed, 2nd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Cequence Security and Enterprise Management Associates have published research showing a gap between enterprise confidence in AI agent access controls and the controls they actually enforce. The survey found that only 33% of organisations provision AI agents with least-privilege access.

The findings are based on a survey of 202 enterprise IT and security leaders at organisations with 1,000 or more employees that are deploying or evaluating agentic AI across North America, Europe, and the Middle East and Africa.

Almost all respondents said they were confident their AI agents did not have more access than needed. Yet while 94% expressed that confidence, only a third said they enforce least-privilege provisioning. The rest rely on broad standing permissions that are reviewed periodically, rarely reviewed, or not reviewed at all.

That mismatch is already showing up in incidents. The research found that 65% of organisations had seen an AI agent take an action outside its intended scope, and 29% said the incident caused measurable business impact, including data exposure, financial loss, operational disruption, or reputational damage.

Another 36% said they stopped a near-miss before damage was caused. In about 4% of cases, the first sign of trouble came from a customer or outside partner rather than internal monitoring systems.

Production use

The survey suggests many companies have moved beyond small-scale trials. Some 46% said they were scaling agentic AI across multiple departments and production workflows, while 79% reported running generative and agentic AI at the same time.

At the same time, more than 92% reported an increase in AI-driven and bot-driven traffic targeting customer-facing applications and APIs. This points to a broader security issue as companies expand the use of autonomous and semi-autonomous software tools in business processes.

Speed of response also emerged as a weakness. Only 32% of organisations said they could detect and contain an out-of-scope agent action within minutes through automated means, while 55% said they needed hours and manual steps to respond.

Access checks

The report also found that many organisations check authorisation too early in the process, if they check it at all. Only 34% said they evaluate an AI agent's authorisation at the moment it attempts a specific action.

Most respondents said they rely on periodic policy reviews or on permissions granted at provisioning and then left in place. That means an agent can retain access beyond the task for which approval was originally given.

The research highlighted another risk in abandoned pilots. It found that 31% of agentic AI pilots had been paused indefinitely, discontinued, or abandoned, raising the prospect that credentials and system access granted during testing may remain active without ongoing oversight.

External connections present a similar issue. Some 14% of organisations said they allow AI agents to connect to outside tools and data sources through the Model Context Protocol without restriction.

Among those that limit such connections to an approved list, fewer than half said a dedicated team actively maintains and audits that list regularly. This suggests control frameworks for third-party connectivity may also be lagging behind deployment.

Christopher M. Steffen, Vice President of Research at Enterprise Management Associates, said: "This research shows enterprises have moved well past experimentation with agentic AI into production, and governance has not kept pace with that shift. The gap isn't a lack of awareness; most organisations have policies in place and express real confidence in them. The gap is between what's written down and what's enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organisations authorise agent actions and monitor them once they're live, and it's the reason incidents are happening at a rate the industry hasn't fully reckoned with."

The study covered respondents including Chief Information Officers, Chief Technology Officers, Chief Information Security Officers, and IT directors. It focused on decision-makers responsible for security, governance, or IT policy in sectors including technology, financial services, healthcare, and manufacturing.

For Cequence, the results underline a broader market concern over how companies govern AI systems once they move from pilot projects into operational use. The survey suggests the issue is no longer confined to identity management, but extends to standing permissions, delayed authorisation checks, and weak monitoring once agents are live.

Shreyans Mehta, Co-Founder and Chief Technology Officer at Cequence, said: "The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; it's exactly why organisations stop looking for problems, stop investing in monitoring, and let authorisation checks lapse until an incident forces the conversation. This is the exact blind spot Cequence is built to close, giving security teams real-time visibility into what AI agents are actually doing and enforcing authorisation at the moment an agent acts, not after the fact."