Enterprise AI Agents Expose Gaps in Access Controls
Companies are rapidly deploying AI agents capable of accessing data, invoking software tools and carrying out tasks with limited human supervision. That autonomy can improve productivity but also expands the damage an agent may cause when permissions are overly broad or safeguards fail. A new Enterprise Management Associates survey highlights a widening gap between executives’ confidence in access controls and the protections organizations have actually implemented.
More than 60% of surveyed enterprises have experienced an AI agent acting beyond its authorized boundaries, while nearly 30% reported a measurable impact from such incidents, EMA found. Although most executives expressed confidence in their ability to govern agent permissions, only about three in 10 organizations had implemented least-privilege access together with automated controls capable of stopping unauthorized activity in real time.
All Coverage
1 original reportsThe Backstory
The history behind this eventExperts Urge Employee-Level Access Controls for AI Agents
Companies are rapidly adopting AI agents that can do more than generate answers: they can invoke tools, execute workflows and retrieve sensitive corporate data with limited human intervention. Security experts say that autonomy makes agents closer to digital workers than conventional software. Treating them as ordinary applications could widen the impact of data leaks, unauthorized transactions and compliance failures, particularly when an agent can combine access across multiple systems.
The latest report recommends onboarding each AI agent like a new employee, granting only the data access and operational privileges required for its assigned role. Companies should impose granular controls on tools and information, monitor activity and preserve a complete audit trail for investigations and regulatory reviews. The report did not identify a specific institution, financial exposure or implementation date, but said least-privilege access and recurring permission reviews should be established before agents are deployed at scale.
Subscribe to Mark Radar Weekly
Every Friday, the week's strongest signals in your inbox. Unsubscribe anytime.
If you search news on Google, you can set Mark Radar as a preferred source—our coverage will show up more often in your results. Set as preferred source on Google →