Can companies control what AI agents can access? Gartner finds a governance gap
In a survey of 297 cybersecurity leaders, 54% said their organisation had no defined approach to limiting AI-agent access or reused human permissions. The finding supports tighter privilege controls, but the public release omits geography, sampling and question wording.
Editorial responsibility: The Impact of AI Editorial Desk · Report a factual concern
Research topic
How organisations limit the permissions and operational impact of autonomous AI agents
At a glance
- 1Gartner says 54% of 297 cybersecurity leaders surveyed in Q2 2026 had no defined approach to limiting AI-agent access or relied on access designed for humans.
- 2In a separate Q2 survey of more than 300 enterprise-risk leaders, 76% ranked AI-driven vulnerability discovery among their ten leading emerging risks.
- 3The release supports governing agents by what they can do, but it does not publish geography, sampling, response rate, weighting or exact question wording.
Living evidence record
Impact record IAI-1MVZ4OL
Evidence stage
Observed
Confidence
Supported
Reporting basis
Source analysis
Independent support
Not yet
Record status
Monitoring
Last checked
30 September 2026
Source trail
2 direct sources across 1 source type.
People impact
Documented in this record.
Uncertainty
Limits and next checks are explicit.
Stages describe the evidence available—not whether a technology is good or bad. See the public method.
Related-source reporting disclosure
This record analyses 2 linked source records around the same underlying development. The extra records add method, date or context, but they do not by themselves constitute independent replication of every performance claim or predicted outcome.
The headline gap is about permissions, not machine intelligence
Gartner reported on 30 September that 54% of organisations represented in a survey of 297 cybersecurity leaders either had no defined approach to limiting AI-agent access or relied on permissions designed for human users. The survey was conducted in the second quarter of 2026. The combined category matters: the release does not separate organisations with no approach from those reusing human access, so it cannot tell readers how many have no control at all. It does show that a majority had not established a clearly agent-specific model by the definition used in the survey.
Gartner's central recommendation is to govern autonomous and multiagent systems by action privilege rather than a claim about how intelligent the model is. That is a practical security distinction. A modest model connected to email, code repositories, payment tools or industrial systems can cause serious harm if it can act broadly, preserve credentials or pass work to another agent. A more capable model operating in a sandbox with narrow, revocable permissions may present a smaller immediate operational risk.[1][2]
Human accounts are a poor template for persistent agents
Human identity systems often assume that one account belongs to one person who signs in, understands a task and can be disciplined for misuse. An AI agent can operate continuously, copy context between tasks, call tools at machine speed and trigger other agents. Giving it the same broad role as an employee can therefore multiply the effect of a mistaken instruction, malicious prompt, compromised integration or exposed credential. Conventional least-privilege principles still apply, but teams need to express them at the level of each tool, action, dataset and spending or change limit.
A safer design starts with a separate non-human identity for every production agent, short-lived credentials, allow-listed tools, explicit read and write scopes, transaction ceilings and high-consequence actions that require a person. Logs should record the model and version, prompt or task, retrieved data, tool calls, approvals and resulting changes. A kill switch is useful only if someone can detect a problem and invoke it in time; organisations also need rate limits, rollback paths and rehearsed incident response for actions an agent has already taken.[1][2]
A second survey describes risk perception, not attack incidence
Gartner also says 76% of more than 300 enterprise-risk leaders surveyed in the second quarter ranked AI-driven discovery of cyber vulnerabilities among their ten leading emerging risks. This is a measure of what leaders prioritised, not the number of attacks, vulnerabilities or losses. The denominator is described only as more than 300, and the public release does not say whether the respondents came from the same organisations as the 297 cybersecurity leaders.
The release connects that concern to pre-emptive defences, deepfake-resistant authorisation and preparation for post-quantum cryptography. Those topics have different evidence bases and timelines. An organisation should not buy a broad category of security product merely because leaders rank a risk highly. It should first map exposed assets and agent pathways, test concrete threat scenarios and decide whether a proposed control reduces likelihood or impact in a way that can be measured against cost and operational friction.[1]
What security teams can test now—and what would change our assessment
Teams can begin with an inventory of every deployed or piloted agent and the systems, secrets and data it can reach. For each one, ask whether the permissions are narrower than the task, whether retrieved content can issue instructions, whether another agent can inherit authority, whether consequential actions require a separate channel, and whether logs are sufficient to reconstruct an incident. Red-team exercises should include prompt injection, poisoned documents, tool substitution, repeated low-value transactions and attempts to escalate from read to write access.
Our confidence in the reported prevalence would increase if Gartner published the countries, industries, organisation sizes, sampling frame, response rate, weighting, exact questions and the split between 'no defined approach' and 'human access'. It would weaken if the sample were concentrated among Gartner clients already concerned about cyber risk or if respondents interpreted 'AI agent' inconsistently. For now, the study is a credible warning that agent permissions deserve their own control model, not a population estimate for every organisation worldwide and not evidence that 54% have already suffered an agent-related breach.[1][2]
What this means for people
- Security and IT teams may need to review agent permissions separately from employee access rather than inherit broad human roles by default.
- Customers and workers can be affected when an agent reads private data or takes an irreversible action, so narrow access and meaningful human review protect more than the organisation itself.
Global context
Gartner presents the findings as international, but the public release does not provide a geographic breakdown. Identity rules, incident reporting and sector regulation vary across jurisdictions, so organisations should combine the general control principle with local legal and operational requirements.
What the evidence does not yet show
- The release does not report geography, industry mix, organisation size, sampling frame, response rate, weighting or exact question wording.
- The 54% figure combines organisations with no defined approach and those reusing predefined human access, without publishing the split.
- The results measure reported governance and risk priorities, not verified control effectiveness, breach incidence or financial loss.
What to watch next
- Disclosure of the survey instrument and separate estimates for absent controls versus reused human permissions.
- Independent incident data linking particular agent permissions or tool chains to real security failures.
- Adoption of non-human identities, task-level privileges, approval boundaries and reconstructable agent audit logs.
Evidence trail
Sources used for this report
Links checked 30 September 2026
This report is labelled source analysis. We summarise and analyse source material in our own words; company statements remain attributed claims until independently supported. Translated summaries preserve the meaning of the original source and link back to it. Read our editorial standards.
Continue the story
Related reporting
Security & Defence
Palo Alto Networks launches continuous AI-led exposure testing
The company says Unit 42 will combine frontier models with security expertise to find and validate weaknesses. Independent evidence of coverage, false positives and remediation outcomes is still needed.
5 min · 2 sources
Security & Defence
Is AI changing cyberattacks—or speeding up familiar tactics?
Microsoft's 2026 Digital Defense Report says threat actors are using AI across parts of existing attack workflows while people, credentials and exposed systems remain central. Its vast telemetry offers useful scale, but the public summary does not disclose a common denominator for every headline percentage.
9 min · 2 sources
Security & Defence
Did AI agents hack government websites—or only attempt to?
California has served OpenAI with an investigative subpoena over agent-related cybersecurity incidents. The update separates a compulsory information request from any finding of liability, while preserving the evidence limits around the reported government-site activity.
8 min · 4 sources
Reader discussion
Add evidence, experience or a question
No account is required. Reader notes are published after a brief civility, relevance and safety check; disagreement is welcome.
Published reader notes
0No published reader notes yet. You can start the evidence-led discussion above.
Prefer a private correction or response? Contact the newsroom.