65% of surveyed enterprises reported that AI agents had acted outside their intended scope, with 29% saying those incidents produced measurable organizational impact.
Scale of agentic AI deployments and the coexistence of generative models
The finding appears in Agents Without Guardrails, a research report from Enterprise Management Associates (EMA) compiled for Cequence Security and based on responses from 202 enterprise technology and security leaders. Some 46% said their organizations were already scaling agentic AI across multiple departments and production workflows, and nearly 79% reported running generative and agentic AI simultaneously. The report frames these adoption figures as evidence that deployments have moved beyond experimentation even as operational governance trails behind.
Incidents, near-misses and third‑party notification
Beyond the headline 65%, the survey measured the range of real-world encounters. Some 35.6% of respondents had caught a near-miss before any material harm occurred. A smaller but notable subset — 3.5%, representing seven organizations — said they most often first learned of out-of-scope agent behavior when a customer or partner reported it. In total, 29% of respondents said out-of-scope actions produced measurable organizational impact.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleDetection, containment and auditability gaps
Respondents described limited ability to act quickly when agents stepped out of bounds. Only 32.2% said they could detect and contain an out-of-scope action within minutes using automated mechanisms; a majority, 54.5%, said they needed hours and manual intervention. Auditability was also uneven: just over 46% said they could not easily produce a complete audit trail of a specific agent's activity over the previous 30 days.
Authorization, provisioning and identity shortfalls
The report identified authorization and access practices as another weak link. Only 34.2% of organizations evaluated whether an agent was authorized to act at execution time; others relied on standing permissions, periodic reviews or inherited access. Although 94% were at least somewhat confident that agents did not hold more access than they needed, only 32.7% provisioned agents with least privilege — a disconnect the report ties to overprovisioning risk.
Identity enforcement and inventory issues compounded the problem. While 54.5% required and enforced unique identities for all AI agents, 32.2% required them without consistently enforcing the mandate, and 3% said agents shared or inherited credentials from user or service accounts. Visibility was limited: 47% of respondents lacked a reliable agent inventory despite many organizations running dozens of agents in production. The report highlighted paused or discontinued pilots as an additional hazard: some 30% of agentic AI pilots had been paused indefinitely or formally discontinued, and security risk concerns were a major factor in 48.5% of those stalls.
What this means for technologists, procurement leaders, and customers
- Technologists and security teams: the survey points to a near-term task list — evaluate agent authorization at runtime, build automated detection and containment capabilities before expanding deployments, and treat agent decommissioning as a security discipline requiring credential revocation and permission cleanup.
- Procurement and IT leaders: the data suggest governance has not kept pace with scaling — 46% scaling agentic AI and many lacking inventories — meaning purchase and deprovisioning processes will matter as much as initial pilots.
- Customers and partners: seven organizations reported first learning of out-of-scope behavior from outside parties, indicating that external reporting already plays a role in detecting issues and that third parties can be both early warning and exposed stakeholders.
Christopher M. Steffen, EMA's vice president of research and the report's author, summarized the disconnect: "Most organizations have policies in place and express real confidence in them," Steffen said. "The gap is between what's written down and what's enforced." The report’s recommendations — evaluate authorization at runtime, automate detection and containment, and enforce credential revocation during decommissioning — present a concrete agenda. Whether organizations adopt those changes will determine if deployments remain a source of productivity gains or a recurring operational risk.




