TL;DR: One in eight reported AI breaches is now linked to agentic systems, while 76% of organisations cite shadow AI as a definite or probable problem and 31% do not know whether they experienced an AI security breach in the past year, according to HiddenLayer’s 2026 AI Threat Landscape Report based on a survey of 250 IT and security leaders. The governance gap is no longer theoretical: controls built for static software cannot reliably contain systems that browse, execute, and act at runtime.
Editorial analysis by NHI Mgmt Group, based on content published by HiddenLayer: “HiddenLayer Releases the 2026 AI Threat Landscape Report, Spotlighting the Rise of Agentic AI and the Expanding Attack Surface of Autonomous Systems”.
By the numbers:
- 76% of organisations now cite shadow AI as a definite or probable problem.
- 31% of organisations do not know whether they experienced an AI security breach in the past 12 months.
Key questions
Q: What breaks when privileged AI agents can read untrusted input directly?
A: Prompt injection risk rises because the agent may treat user content as instruction instead of context.
Q: Why do agentic AI deployments increase breach risk even when the model is accurate?
A: Accuracy does not remove risk when the system can still take harmful actions.
Q: How should organisations govern shadow AI without blocking legitimate use?
A: Start with approved-use policy, tool inventory, and data classification.
Practitioner guidance
- Define agent runtime boundaries Limit which tools, files, and workflows each AI system can reach, and separate read, write, and execute permissions so a compromised agent cannot move freely.
- Inventory shadow AI and assign owners Create a live register of all AI systems, their credentials, approved use cases, and accountable business owners so offboarding and review are possible.
- Move controls to issuance time Require approval and policy checks before an agent receives access, rather than relying on later review cycles that may never see the risky action.
Bottom line: Agentic AI turns runtime tool use into the main security boundary, which means identity and authorisation controls matter more than prompt quality alone.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Agentic AI turns access governance into behaviour governance. Traditional IAM assumes the identity is relatively stable, and that the main question is whether the right access was assigned. That assumption breaks when the actor can choose tools, sequence actions, and continue operating after context changes. The field needs to stop treating agent governance as a wrapper around the model and start treating it as a runtime identity problem.
A few things that frame the scale:
- 92% agree governing AI agents is critical to enterprise security, yet only 44% have implemented any policies to do so, according to AI Agents: The New Attack Surface report.
- 33% of organisations report their AI agents have accessed inappropriate or sensitive data beyond their intended scope, which shows scope drift is already operational.
A question worth separating out:
Q: What should organisations do first after discovering unmanaged AI agents?
A: Organisations should first isolate the credentials, tool connections, and data paths attached to the unmanaged agent before expanding use further. Then they should decide whether the system is approved, remediated, or retired. That sequence limits hidden authority and reduces the chance of an unseen workflow becoming an attack path.
👉 Read our full editorial: AI threat landscape report shows agentic systems widening AI risk
Agentic AI creates an assumption collapse in identity governance: access review assumes privilege persists long enough to be observed, certified, and removed, but autonomous systems can acquire, use, and chain access within a single runtime session. That breaks the review model before it even starts. The implication is that governance has to move from post-hoc certification to issuance-time control and runtime containment.
A few things that frame the scale:
- A May 2025 Gartner poll of 147 CIOs and IT leaders found that 24% had already deployed AI agents, 50% were experimenting and 17% planned to deploy by the end of 2026.
A question worth separating out:
Q: What is the difference between agentic AI risk and ordinary software risk?
A: Agentic AI risk is defined by runtime decision-making and tool use, not by static code paths. Ordinary software executes prebuilt logic, while an agent can select actions, chain tools, and alter its next step based on context. That changes the control model from guarding inputs and outputs to governing authority, delegation, and execution scope.
👉 Read our full editorial: AI threat landscape report shows agentic systems widening AI risk