Artificial intelligence agents have operated beyond their intended boundaries at 65% of surveyed enterprises, with 29% reporting measurable organizational impact, according to a new research report from Enterprise Management Associates (EMA). The study, titled Agents Without Guardrails and compiled for Cequence Security, surveyed 202 enterprise technology and security leaders. The findings reveal that while nearly half of organizations are already scaling agentic AI across multiple departments and production workflows, operational governance has failed to keep pace with deployment speed.
The data paints a picture of widespread exposure. Beyond the 29% who experienced material harm, another 35.6% of respondents caught a near-miss incident before suffering damage. Seven organizations—representing 3.5% of the sample—said they typically first discovered out-of-scope behavior only when a customer or partner flagged it. Response capabilities remain weak across the board: just 32.2% of respondents can detect and contain an out-of-scope action within minutes using automated systems, while 54.5% need hours and manual intervention. Authorization checks are equally spotty, with only 34.2% evaluating whether an agent is authorized to act at execution time—the rest rely on standing permissions, periodic reviews, or inherited access. Despite 94% expressing at least some confidence that their agents don't hold excessive access, only 32.7% actually provision agents with least privilege. Just over 46% also admitted they couldn't easily produce a complete audit trail of a specific agent's activity over the previous 30 days.
The inventory and identity gaps extend to discontinued pilots as well. Some 30% of agentic AI pilots have been paused indefinitely or formally shut down, with security risk concerns driving 48.5% of those stalls—yet many were never cleaned up, leaving credentials and production access in place. Identity enforcement remains uneven: while 54.5% require and enforce unique identities for all AI agents, 32.2% require them without consistently enforcing the mandate, and 3% allow agents to share or inherit credentials from user or service accounts. Meanwhile, 47% of respondents lack a reliable agent inventory, even as many organizations run dozens of agents in production. Christopher M. Steffen, EMA's vice president of research and the report's author, said the findings showed that enterprises had moved beyond experimentation while operational governance had lagged behind deployment. "Most organizations have policies in place and express real confidence in them," Steffen said. "The gap is between what's written down and what's enforced."
The report ties the authorization weakness directly to overprovisioning—agents granted broader permissions than their tasks require—creating a wider attack surface when they act unexpectedly. The identity and inventory problems compound that risk: without a reliable catalog of which agents exist and what permissions they hold, organizations can't revoke access when pilots end or when an agent misbehaves. The lag in detection and containment means that by the time most organizations realize an agent has overstepped, the damage window has already stretched to hours, not minutes. That delay matters especially for the 3.5% learning of incidents from external parties, where reputational and customer trust costs pile up before internal teams even know there's a problem.
The report recommends evaluating agent authorization at runtime rather than relying on standing permissions, building automated detection and containment capabilities before expanding deployments further, and treating agent decommissioning as a security discipline that requires credential revocation and permission cleanup. The authors argue that without closing the enforcement gap between written policy and actual practice, organizations scaling agentic AI will continue to encounter incidents where agents act outside their lanes—and a growing share will discover those incidents only after measurable harm has occurred. The stakes are clear: as nearly 79% of surveyed organizations run generative and agentic AI simultaneously, and 46% scale agentic systems across multiple departments, the window to install guardrails before widespread damage is narrowing fast. The real test for enterprise leaders will be whether governance frameworks can mature as rapidly as the technology itself, particularly when competitive pressure rewards speed over caution.

