Half of Production AI Agents Run Unsecured: A 2026 Reality Check

Enterprise AI agents crossed a line this year. They are no longer experiments someone runs in a sandbox — they are processes with credentials, running against production systems. The security posture has not kept up. In Gravitee's State of AI Agent Security Report 2026, a survey of 750 senior technology leaders, roughly 48% of production AI agents were running unsecured. Here is what the data says, and what to do before you deploy your next one.

The three gaps in the data

The report's numbers line up into a single story: deployment is outrunning governance.

  • Volume — enterprise agent fleets roughly doubled between December 2025 and April 2026, and 38% of organizations now run more than 100 agents
  • Coverage — about 48% of production agents run unsecured, and only 19.7% of organizations fully secure every agent before it reaches production
  • Ownership — just 7.2% have a named individual with formal accountability for agent behavior, while 32.4% describe accountability as unclear or situation-dependent

This is not theoretical. In the same survey, 54% of organizations had experienced or suspected a security incident involving agents, and 34.9% confirmed one occurred.

The confidence gap is the real finding

One pair of numbers deserves more attention than the rest. 91.8% of respondents expressed confidence in their visibility into agent activity — while mean monitoring coverage sat at roughly 52%. Nearly half of agent activity is unobserved, and almost everyone believes otherwise.

That gap matters more than any single control, because it changes what questions get asked. A team that believes it has visibility does not go looking. If you take one action from this article, make it the boring one: open the logs and count how many of your agents actually appear there.

Where unmanaged agents come from

Most ungoverned agents are not built by a rogue engineer. They accumulate through ordinary, well-meant decisions:

  • A productivity tool granted read access to mail or calendar during a free trial
  • An integration connected to shared drives or chat so it can "have context"
  • A browser-based agent that reads page content and acts on it — which is also how prompt injection reaches your systems
  • A pilot that quietly became load-bearing because it worked

Five controls to set before deployment

None of these require new tooling. They require a decision made before the agent runs, not after.

  • Name an owner. One person accountable for what the agent does. Only 7.2% of organizations have this, so it is unusually cheap differentiation.
  • Start read-only. Grant write, send, and delete permissions individually, each with a stated reason.
  • Define the kill switch first. Who stops it, how, and how fast — written down before launch.
  • Require an audit trail. An agent whose actions leave no log cannot be investigated after an incident.
  • Schedule the inventory. A recurring quarterly review that revokes unused integrations. Agents accumulate; nothing removes them by default.

Deploy narrow, then widen

The pattern that keeps teams out of trouble is unglamorous: run one agent against one low-blast-radius workflow, watch the logs for a few weeks, then expand. It feels slow compared with rolling out a fleet, but it front-loads the discovery of failure modes at a point where reversing costs almost nothing.

A useful rule of thumb: your agent count should never exceed the number of agents you could describe from memory. When you cannot list them, you have stopped managing them.

Frequently asked questions

Does this apply to a small team with two or three agents?

The controls scale down cleanly. With three agents, naming an owner and writing the kill switch takes an afternoon. The organizations in trouble are the ones that skipped this step when they had three and now have a hundred.

What is the fastest way to find agents nobody is tracking?

Review the OAuth and connected-app lists on your main platforms — mail, calendar, storage, chat. Third-party access grants are usually where unmanaged automation shows up first, and revoking one takes seconds.

How much should I trust these survey figures?

They come from 750 senior technology leaders, so the sample skews toward organizations already invested in agents, and the direction is more reliable than any single percentage. Treat the trend — adoption outpacing governance — as the finding, not the decimal places.

Related on AI Learning Lab: AI Browsers and the Prompt Injection Problem · How to Compare AI Agent Tools · How to Fact-Check AI Answers

Comments

Popular posts from this blog

Free vs Paid AI Tools: When Is Upgrading Actually Worth It?

AI Search vs Traditional Search: How to Use Each in 2026

Are AI Certifications Worth It in 2026? A Practical ROI Test