• About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Privacy Policy
  • Contact us
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit
      • 2026
      • 2025
    • Webinars
      • AI in Finance
      • The Resilient Enterprise
    • CXO50 KSA
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
  • News
  • Opinion
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
    • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit
      • 2026
      • 2025
    • Webinars
      • AI in Finance
      • The Resilient Enterprise
    • CXO50 KSA
    • CXO50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai 2025
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Digital Magazine
  • GITEX x AI EVERYTHING
No Result
View All Result
CXO Insight Middle East
No Result
View All Result

New Cequence & EMA research: 94% trust AI agents, only 33% enforce controls

by CXO Staff
September 9, 2026
in Business, Channel, Middle East, News, Region

New Cequence & EMA Research: 94% of enterprises trust their AI agents aren’t over-provisioned, only 33% actually enforce it

Anomali launches ThreatStream Next-Gen to turn intelligence into action

Nearly every enterprise believes its AI agents are properly scoped. Only a third have actually made sure of it.

Today, new research from Cequence Security found that 94% of enterprise IT and security leaders are confident their AI agents do not have more access than they need, yet only 33% actually provision agents with least-privilege access. The remaining two-thirds run on broad standing permissions that are reviewed periodically, rarely reviewed, or never reviewed at all. The full report, Agents Without Guardrails: The Agentic AI Governance Gap in the Enterprise, is available for download at https://www.cequence.ai/wp-content/uploads/2026/08/EMA-Research-Report-Agents-Without-Guardrails.pdf.

That gap between confidence and practice is already showing up in production, not a theoretical risk, but as incidents enterprises are living with right now. Among the organizations surveyed:

  • 65% have experienced an AI agent take an action outside its intended scope, including 29% with measurable business impact, including data exposure, financial loss, operational disruption, or reputational damage. Another 36% caught a near-miss before it caused damage.
  • Only 32% can detect and contain an out-of-scope agent action within minutes through automated means; 55% need hours and manual steps to respond.
  • In approximately 4% of organizations surveyed, the first sign of trouble came from a customer or outside partner, not an internal system.

The findings point to one clear story. Governance has not kept pace with the speed of agentic AI deployment, and that gap is showing up at every stage of the agent lifecycle, from how agents are provisioned, to how their actions are authorized, to how they are decommissioned once a pilot ends. Other key findings from the report include:

Enterprises have moved past the pilot stage

The scale of deployment makes the gap more urgent. 46% of organizations report they are already scaling agentic AI across multiple departments and production workflows, and 79% are running generative and agentic AI simultaneously. Further, more than 92% report an increase in AI and bot-driven traffic targeting customer-facing applications and APIs.

Authorization is checked at the wrong time, or not at all

That governance gap extends to how access is enforced in the moment an agent acts. Only 34% of organizations evaluate an AI agent’s authorization at the moment it attempts a specific action. The majority rely on periodic policy reviews or standing permissions set once at provisioning and never revisited, meaning an agent’s access can quietly outlive the task it was originally granted for, and keep working long after anyone signed off on it.

Abandoned pilots are leaving live credentials behind

Additionally, there’s an increasing risk in how enterprises manage agents that don’t make it to production. 31% of agentic AI pilots have been paused indefinitely, discontinued, or abandoned. Many were real deployments with real system access and credentials that were never cleaned up. Every abandoned pilot with live credentials is exposure nobody is actively watching.

External connectivity carries the same risk

14% of organizations allow AI agents to connect to outside tools and data sources via the Model Context Protocol (MCP) without restriction. Among the majority who do limit those connections to an approved list, fewer than half, just 49%, have a dedicated team actively maintaining and auditing that list on a regular basis.

Christopher M. Steffen, CISSP, CISA, VP of Research at EMA, said: “This research shows enterprises have moved well past experimentation with agentic AI right into production, and governance has not kept pace with that shift. The gap isn’t a lack of awareness; most organisations have policies in place and express real confidence in them. The gap is between what’s written down and what’s enforced when an agent takes an action nobody approved. That disconnect shows up most clearly in how organizations authorize agent actions and monitor them once they’re live, and it’s the reason incidents are happening at a rate the industry hasn’t fully reckoned with.”

Shreyans Mehta, Co-founder and CTO at Cequence, said: “The number that jumped out to me is the 92% being confident in their governance frameworks. Confidence like that is a trap; it’s exactly why organisations stop looking for problems, stop investing in monitoring, and let authorisation checks lapse until an incident forces the conversation. This is the exact blind spot Cequence is built to close, giving security teams real-time visibility into what AI agents are actually doing and enforcing authorisation at the moment an agent acts, not after the fact.”

Tags: CequenceCequence SecurityEMA Research
ShareTweet

Related Posts

Salam, SmartFactory partner to transform Saudi manufacturing
Business

Salam, SmartFactory partner to transform Saudi manufacturing

September 9, 2026

Etihad Salam Telecom Company (Salam) signed a Memorandum of Understanding (MoU) with Smartech Digital Solutions Co. (SmartFactory) at LEAP 2026,...

GISEC 2026: Group-IB calls for a shift from detection to prediction
Future

GISEC 2026: Group-IB calls for a shift from detection to prediction

September 9, 2026

Group-IB confirmed its participation in GISEC Global 2026, held from 16–18 September 2026 at the Dubai Exhibition Centre (DEC) in...

Discussion about this post

Latest Issue

Salam, SmartFactory partner to transform Saudi manufacturing

Salam, SmartFactory partner to transform Saudi manufacturing

September 9, 2026
Anomali launches ThreatStream Next-Gen to turn intelligence into action

New Cequence & EMA research: 94% trust AI agents, only 33% enforce controls

September 9, 2026
GISEC 2026: Group-IB calls for a shift from detection to prediction

GISEC 2026: Group-IB calls for a shift from detection to prediction

September 9, 2026

The most trusted source of strategic intelligence for IT decision makers in the Middle East.

About

  • About Us
  • Advertising
  • Digital Magazine
  • Supplements
  • Media Pack
  • Contact Us

Policies

  • Privacy Policy
© 2025 – CXO Insight Middle East. All Rights Reserved.
Facebook-f X-twitter Linkedin
Separated they live in Bookmarksgrove right at the coast of the Semantics, a large language ocean. A small river named Duden.

About

  • About Us
  • Site Map
  • Contact Us
  • Career

Policies

  • Help Center
  • Privacy Policy
  • Cookie Setting
  • Term Of Use

Join Our Newsletter

© 2024 – CXO Insight Middle East. All Rights Reserved.

Facebook-f Twitter Youtube Instagram

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
Join our mailing list
Sign up here to get the latest news, updates and special offers delivered directly to your inbox.
No Result
View All Result
  • News
  • Opinions
  • Business
    • Industries
      • Transport
      • Retail
      • Government
      • Real Estate
      • Education
      • Energy
      • Banking and Finance
  • Channel
  • Future
    • Tech
    • Gadgets
    • Science
    • Space
    • Sustainability
  • Events
    • Channel Awards
      • 2025
      • 2024
      • 2023
    • Channel Insights Summit
      • 2026
      • 2025
    • Webinars
      • AI in Finance
      • The Resilient Enterprise
    • CXO50 KSA
    • CX50 Oman
    • CXO50
      • 2026
      • 2025
    • ICT Awards
      • Dubai
      • Saudi Arabia
    • Cyber Strategists Summit
      • 2026
      • 2025
      • 2024
      • 2023
      • 2022
      • 2021
    • Cloud Connect 2025
    • All events
  • Videos
  • GITEX x AI Everything
  • Digital Magazine

© 2025 - CXO Insight Middle East. All Rights Reserved.