Many organizations are struggling to manage the access privileges of AI agents, with a significant majority of IT and security leaders reporting that these agents retain access to company systems and data even after their assigned tasks are completed. This persistent access poses a substantial risk, as AI tools can continue to operate and access sensitive information long after their intended use, according to a recent industry report.
The report highlights that 99.7% of IT and security leaders confirm their organizations have formal policies governing AI tool data access. However, a significant enforcement gap exists, with many suspecting or confirming that an AI tool or agent has accessed sensitive data beyond its required scope within the past year. Only 57% of organizations feel their policies are sufficiently documented and enforced to clearly understand what data AI tools are permitted to access. Real-time policy checks for AI access are conducted by only about 51% of organizations, and fewer than one in five detected the most recent instance of out-of-scope access as it occurred.
A key concern is that AI agents often inherit the permissions of the user who launches them. This can grant the agent broad access, including privileges accumulated by the employee over years, which may be entirely unrelated to the agent's specific assignment. With such extensive permissions, an agent can autonomously select tools and execute a sequence of actions to achieve a goal, potentially taking steps not anticipated when the initial access was approved.
The issue is compounded by employees feeling pressured to use AI tools with sensitive or confidential information without clear guidance on permissible use. A substantial 76% of employees admitted to bypassing formal approval processes at some point to use AI tools on work systems. The data accessed by these tools can include customer records, employee information, financial data, security logs, and source code.
Organizations often lack automated mechanisms to revoke AI access once a session concludes. Forty-two percent of IT and security leaders reported no automatic way to remove AI access when a session ended, relying instead on scheduled revocations, audits, or employees to manually disconnect tools. This leaves credentials active and allows tools to continue reaching company systems and data until permissions expire or are manually revoked.
Visibility into AI agent actions is also limited for many security teams. Monitoring may not cover all tools, leaving individual actions unchecked. Software build and deployment pipelines and Kubernetes environments, where coding agents might operate and modify applications and infrastructure, showed the lowest levels of enforcement at the moment of action. Detection of out-of-scope data access by an AI tool or agent often takes a day or longer, during which time the agent can continue to operate without human intervention. Even when unauthorized access is detected, while credentials might be revoked immediately, additional time may be needed to terminate an active session, allowing the tool to continue operating.
Tracing AI access events involving sensitive data to the authorizing individual is a challenge, with only 36% of IT respondents consistently able to do so. This lack of traceability hinders investigations into incidents, making it difficult to ascertain why access was granted, what conditions applied, and who was responsible. Furthermore, employees often express uncertainty about what constitutes sensitive information, whether their AI tools can access it, and who would be accountable for improper use. Many are unaware if a tool can be stopped from accessing sensitive data, and some who observed an AI tool accessing more information than expected did not report it, leaving security teams uninformed about potential unauthorized activity.






