Enterprise environments now average one AI agent, live or in draft mode, for every employee.
Ospin’s headline: scale and speed — 1:1 agent-to-employee and 14x interaction growth
A recent report by Ospin analyzed enterprise production environments in 2026 and reported two striking measures of scale: an average of one AI agent, live or in draft, per employee, and a 14x increase in workforce interactions with AI agents between January 2026 and June 2026. Those two figures anchor the report’s central finding: AI agents are not a niche experiment inside organizations but have become a pervasive element of daily work.
Ospin’s timing — measuring the first half of 2026 — frames the growth as both rapid and recent. The combination of pervasive agents and sharply rising interactions creates a simple arithmetic risk: more agents multiplied by more human contact produces many more opportunities for misconfiguration, misuse, or unintended behavior.
Who’s building them: 67% by non-engineering teams (GTM, Customer Success, Operations)
Ospin reports that 67% of agents are being built by employees without engineering backgrounds, specifically naming go-to-market (GTM), Customer Success, and Operations teams. That shift in builders signals a decentralization of agency creation: the people closest to customers or processes are creating agents, often outside traditional provisioning and access-control workflows.
Because those creators frequently sit outside engineering, the report implies that provisioning discipline — the security and access scoping teams rely on — can be outrun by business teams moving faster than controls are applied.

Audit-ready is a season. It shouldn't be.
Evidence in spreadsheets, controls drifting between audits, frameworks multiplying on flat headcount. Nubivance runs continuous compliance on Rapid7 Cyber GRC - SOC 2, HIPAA, ISO 27001, PCI, CMMC.
End the scrambleAccess and scoping: 60% granted allow-all beyond defaults
When agents were provisioned beyond default settings, researchers found that 60% of those agents were granted "allow-all" access rather than being scoped to the permissions their tasks required. The phrase "allow-all" is used in the report to describe access granted beyond intended defaults, a provisioning pattern that concentrates broad privileges on agents whose functions were often narrowly described.
This finding ties the scale of agents to concrete access decisions: widespread creation by non-engineers, combined with permissive provisioning, means a majority of expanded-deployment agents carry blanket access rather than tightly constrained, task-specific permissions.
Capability creep: 60% exceed their original stated intent
Ospin further found that 60% of agents were judged to have configured capabilities that exceeded their original stated intent. That percentage mirrors the access finding and adds a second axis of divergence: capability creep as distinct from permission scope.
Two 60% figures in the report — one for allow-all access and one for capabilities exceeding intent — present a consistent portrait: a majority of agents, once extended beyond defaults, both receive broad access and are configured to do more than they were initially designed to do.
What this means for technologists, procurement leaders, and end users
- Technologists and security teams: The report highlights rapid internal growth in agent count and interaction volume and documents that many agents are built by non-engineers; those teams will be watching for unscoped "allow-all" provisioning and capability creep because Ospin quantifies both phenomena at 60%.
- Procurement and operations leaders: With 67% of agents being created by GTM, Customer Success, and Operations, procurement will need to reconcile decentralized creation with centralized provisioning policies and consider whether current default settings and approval gates match the new deployment velocity.
- End users and business teams: The data show business teams are both creators and primary users of agents; the report’s numbers suggest these teams are frequently operating beyond default constraints, which means they will need clearer guardrails tied to the permissions and capabilities Ospin documented as commonly over-extended.
Ospin’s dataset delivers a compact but pointed message: AI agents in enterprise production are numerous, growing rapidly in usage, and often provisioned or configured in ways that outstrip originally stated intent. The paired statistics — 67% of agents built by non-engineers and two 60% measures for permissive access and capability creep — suggest the locus of risk is as much organizational and procedural as it is technical.
For readers who want to review the original report and reporting, the source story is available at https://www.securitymagazine.com/articles/102493-ai-tools-are-provided-full-enterprise-access.




