71% of surveyed organizations report their AI agents can access sensitive information, with 40% of agents reaching data outside explicit approval. 40% of developers grant agents persistent credentials that outlive task completion, creating audit gaps that delay incident detection and accountability.
AI agents access data no one approved, leaving accountability unclear
33% of surveyed companies experienced breaches or security incidents tied to overprivileged non-human identities; 71% reported unintended consequences from agent actions.