The News
Cequence Security and Enterprise Management Associates (EMA) have released joint research titled “Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise,” based on a survey of 202 enterprise IT and security leaders at organizations with 1,000 or more employees. The central finding is a striking confidence-to-practice gap: 94% of respondents believe their AI agents are not over-provisioned, yet only 33% actually enforce least-privilege access. The research also found that 65% of surveyed organizations have already experienced an AI agent acting outside its intended scope, with 29% reporting measurable business impact including data exposure, financial loss, or operational disruption.
Analyst Take
The Confidence Trap Is the Real Vulnerability
The most consequential number in this report is the 94% confidence figure. When security leaders believe a problem is solved, they stop funding controls, stop monitoring closely, and stop asking hard questions in vendor reviews. Cequence’s CTO names this dynamic directly: confidence is “exactly why organizations stop looking for problems.” That’s not a rhetorical flourish. It describes a well-documented pattern in enterprise security where perceived control substitutes for actual control, and the substitution goes undetected until an incident forces a reckoning.
The mechanics here are worth spelling out for both security architects and ITDMs evaluating agentic AI investments. The authorization problem is not primarily an identity problem. Organizations largely know who (or what) their agents are. The failure is temporal: only 34% evaluate an AI agent’s authorization at the moment it attempts a specific action. The rest rely on standing permissions set at provisioning and reviewed periodically, rarely, or never. An agent’s effective access can silently outlast the task it was originally granted for. That’s not a gap in identity infrastructure. It’s a gap in runtime enforcement, and it requires a different class of tooling to close.
A Governance Debt That Scales With Deployment
The urgency of these findings is compounded by the speed of deployment. With 46% of surveyed organizations already scaling agentic AI across multiple departments and production workflows, the attack surface is expanding faster than governance frameworks can adapt. This mirrors a broader pattern ECI Research has observed in the public sector. According to ECI Research’s Google GovTech Survey Results, 31.8% of respondents estimated that AI will assist or generate between 1% and 25% of their organization’s code within the next 12 months, but a significant secondary cluster is moving faster: 49.6% of respondents selected “26% to 50%.” That’s not pilot-stage volume. That’s production-grade dependency on AI-generated or AI-assisted output, and it implies that the governance frameworks organizations are still building will need to cover a much larger footprint than currently budgeted.
The abandoned-pilot problem compounds this further. When 31% of agentic AI pilots are paused, discontinued, or abandoned without credential cleanup, those deployments become unmonitored access points. No one owns them. No one is watching them. And the credentials they carry don’t expire because nobody told the system the pilot was over. For ITDMs, this is a specific and addressable operational risk. It requires the same lifecycle discipline applied to human contractor offboarding, applied consistently to AI agents.
What the FedRAMP Parallel Teaches Us
There’s an instructive precedent in how the public sector has handled AI adoption friction more broadly. According to ECI Research’s Google GovTech Survey Results, 31.8% of respondents cited “FedRAMP/compliance approval friction for AI vendors” as the single largest blocker preventing widespread AI adoption in their developer workflows. The compliance machinery exists, but it hasn’t been built with agentic AI’s runtime authorization requirements in mind. Most FedRAMP authorization processes assess a system’s security posture at a point in time, not the real-time behavioral envelope of an autonomous agent making decisions across APIs, data sources, and external tools like MCP connections. That structural mismatch is not Cequence’s problem to solve alone, but it is the environment their platform has to operate within, and it shapes the competitive opportunity clearly.
For developers and security engineers building or integrating agentic systems, the takeaway is architectural: authorization logic cannot live only at the identity layer. It has to exist at the action layer, enforced at the moment an agent attempts something, not inherited from a policy document signed off weeks earlier. That design principle should be non-negotiable in any agentic AI architecture review, regardless of vendor.
Looking Ahead
The agentic AI governance market is about to get crowded. The Cequence and EMA research effectively defines the problem space with enough precision that it will accelerate competitive responses from API security vendors, identity platforms, and cloud-native security providers who will each claim a slice of runtime authorization. Cequence’s advantage is that it arrives with a decade of bot defense and API behavioral analysis already in production, which gives it a credible foundation for the “detect and contain within minutes” capability that only 32% of surveyed organizations currently have. That’s a reference point competitors will struggle to match quickly.
Over the next 12 to 24 months, the governance gap documented here will shift from a research finding to a compliance requirement. Regulatory bodies in financial services and healthcare are already developing guidance on AI agent accountability, and federal acquisition frameworks will eventually incorporate agentic AI oversight into ATO and FedRAMP processes. Organizations that treat this as a future compliance checkbox rather than an active security posture problem today will find themselves in catch-up mode when those requirements land. The incident data already collected in this report should be the forcing function. If 29% measurable business impact doesn’t move the conversation, a regulator mandate will.
Stay Ahead of Application Development Trends
Get weekly analyst insights, research notes, event coverage, and AppDevANGLE updates delivered directly to your inbox.
Subscribe for Weekly Insights
Join technology leaders, practitioners, and GTM teams following the trends shaping modern software delivery.
Looking for deeper research access?
Explore ECI Research reports, survey insights, and market analysis through the ECI Research Portal.
