Artificial intelligence is entering a new phase. Organizations are no longer simply experimenting with generative AI chatbots. Increasingly, they are deploying AI agents capable of making decisions, accessing enterprise systems, interacting with applications, and executing tasks with limited human intervention.

While these capabilities promise significant productivity gains, they also introduce an entirely new category of security, governance, and operational risk.

Token Security commissioned the Cloud Security Alliance (CSA) to develop a survey and report to better understand the industry’s knowledge, attitudes, and opinions regarding autonomous AI agents. The study examined how organizations are governing AI agents as they become embedded in enterprise systems and operational workflows. 

The survey report titled “Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises” reveals a growing reality: AI agents are becoming embedded in day-to-day business operations faster than organizations can establish the governance needed to manage them effectively. The survey found that 65% of organizations experienced at least one AI agent-related security incident during the previous year, while 82% discovered previously unknown or “shadow” AI agents operating without the knowledge of security or governance teams.

The report examines how organizations are structuring AI agent governance in practice, and where gaps remain as agent adoption scales.

The report demonstrates that securing AI agents requires far more than traditional cybersecurity controls. Organizations need visibility into every AI agent, clear governance policies, lifecycle management, risk-based authorization, continuous monitoring, and well-defined guardrails throughout the agent lifecycle.

Key Findings

1. Exception Handling Is Emerging as the Primary Control Plane for AI Agents 

Exception handling has emerged as the dominant operational control model for AI agents. A majority of organizations report that their AI agents operate autonomously for low-risk tasks but require human review for high-risk actions (53%), while an additional 24% rely on human-in-the-loop models for most tasks. Only 13% indicate fully autonomous deployments with no human review. This distribution indicates that autonomy is typically bounded and tiered, not absolute. Human control has not disappeared: instead it is concentrated on areas where the stakes are highest. 

The predominance of periodic oversight indicates that runtime governance is structured around checkpoints and review cycles instead of real-time, always-on enforcement. Oversight is present, but it is not universally embedded at every execution layer. 

When an agent attempts something unexpected, organizations are more likely to require approval or document the action than to stop it outright. Automatic blocking exists, but it is not the dominant approach. 

The data shows that most organizations are not trying to prevent every unexpected action in advance. Instead, they allow AI agents to operate within defined boundaries and step in when risk increases. Higher-risk or out-of-scope actions are routed to approval workflows, logged for review, or handled differently depending on the system. Control is applied at key moments rather than enforced uniformly at all times. 

Key Finding 2:  Organizations Believe They See Their AI Agents Yet Shadow Deployment Continues 

Organizations express strong confidence in their visibility into AI agents, yet frequent surprise discovery reveals a persistent gap between operational awareness and assurance-grade oversight. When asked to rate their understanding of all AI agents and autonomous workflows running across teams and tools on a five-point scale—where 5 represents complete visibility and 1 represents limited visibility—22% select 5, and 46% select 4. In total, 68% rate their visibility as high (4–5), while 15% report limited visibility (1–2). On the surface, this suggests that AI agents are sufficiently visible to support day-to-day operations and management. Most organizations believe they know what is running and where. 

The data suggests many organizations have sufficient visibility to operate AI agents day to day, but not enough completeness to guarantee that exception-driven controls apply universally

However, that confidence coexists with widespread surprise discovery of AI agents.  In the past year, 82% report discovering at least one AI agent or autonomous workflow that was created without the knowledge of security, IT, or governance teams. Of those, 41% experienced this multiple times, while another 41% encountered it at least once.  Only 11% report no such discoveries.

The result is a gap between perceived oversight and actual governance coverage.

Key Finding 3:  AI Agent Lifecycle Controls Are Maturing But Decommissioning Lags 

Retirement Debt

Organizations are strengthening early-stage AI agent lifecycle controls, but weak decommissioning practices are creating a growing layer of “retirement debt.” A key part of this front-end discipline is clarity of intent at creation. 

Fifty-nine percent report that an agent’s intended purpose is clearly or very clearly documented, while only 12% indicate weak documentation. Defining what an agent is meant to do establishes the governance boundary within which it can safely operate. 

That clarity is reinforced by more formal lifecycle controls. A majority report conducting periodic permission reviews (68%), and over half have defined creation or onboarding processes (52%). Nearly half monitor agent behavior or performance (44%), and 35% document ownership. 

Key Finding 4:  Risk and Delegation Are Becoming the Cornerstones of AI Agent Governance 

Risk and delegation are emerging as the primary policy signals shaping how organizations govern AI agent behavior. Underlying this shift is a broader pattern: AI agent risk is driven by the combination of access and autonomy—what systems an agent can reach and how independently it can act. As both increase, so does potential impact, making risk a central input into governance decisions. 

Rather than fragmenting across many possible inputs, organizations appear to be standardizing on risk magnitude and human authorization as the most authoritative signals for policy evaluation. 

This emphasis reflects a shift away from static, role-based access models toward more adaptive decision frameworks. Risk level introduces dynamic evaluation—what is the potential impact of this action? Delegation introduces accountability—has a human explicitly authorized or scoped this action? Together, these signals create a policy language grounded in both consequence and intent.

Key Finding 5:  AI Agent Incidents Are Reshaping Operational Security Priorities 

Security incidents involving AI agents are widespread across organizations. Nearly two-thirds of organizations report experiencing a security incident involving an AI agent or autonomous workflow within the past 12 months (65%). Only 29% report no such incident, and the remainder were unsure or did not respond. 

This indicates that agent-related security events are now common operational realities rather than edge cases. AI agents have moved firmly into production environments, and with that shift comes measurable exposure. 

These incidents affect multiple areas of the business and carry meaningful consequences. Among organizations that experienced an incident, 61% report exposure or mishandling of sensitive data, 43% report disruption to business operations, and 41% cite incorrect or unintended actions within business processes. Financial cost is reported by 35%, and 31% experienced delays in customer-facing or internal services.


What This Means for Your Organization

AI agents should no longer be treated as isolated experiments. As they gain access to business applications, cloud environments, sensitive data, and automated workflows, they introduce new risks that traditional AI policies may not fully address.

Organizations should establish clear ownership for every AI agent, maintain visibility into where agents are deployed, limit their permissions, monitor their actions, and define how they are approved, updated, and retired. Governance must evolve alongside adoption, not after an incident occurs.

The priority is not to slow innovation, but to ensure AI agents can operate securely, responsibly, and within clearly defined boundaries.


AI Readiness Must Include AI Agent Governance

Many organizations are investing heavily in generative AI, but the next challenge will not be deploying AI agents- it will be governing them.

AI agents combine intelligence with action. Unlike traditional AI assistants that simply generate content, AI agents can access systems, invoke APIs, retrieve data, make decisions, and perform business processes autonomously. That dramatically expands both their value and their risk.

At Reputiva, we believe organizations should begin preparing now by focusing on five foundational capabilities:

  • Discover and inventory AI agents across the enterprise
  • Establish AI governance policies before large-scale deployment
  • Apply least-privilege identity and access controls to AI agents
  • Continuously monitor AI agent behaviour for anomalous activity
  • Integrate AI agent governance into existing cloud security, IAM, cybersecurity, and risk management programs

The organizations that succeed with AI won’t simply deploy more AI agents, they’ll build governance frameworks that scale securely alongside them.

Prepare Your Organization for Secure AI Agent Adoption

AI agents are rapidly becoming part of everyday business operations. Now is the time to ensure your organization has the governance, security, and operational controls needed to adopt them responsibly.

Book a consultation with Reputiva to learn how an AI Readiness Assessment can help your organization establish secure AI governance, strengthen identity and access controls, reduce AI-related risks, and prepare for scalable AI agent adoption.


Reputiva

Reputiva is a cloud, cybersecurity, and FinOps advisory firm helping SMEs reduce cyber risk, strengthen cloud environments, and manage technology costs with confidence. We publish practical insights on cloud security, identity, AI risk, compliance, and digital transformation.

Author posts

Navigate

Let's talk

Networks

Privacy Preference Center