TL;DR: Agentic AI is already in production at 69% of enterprises, but only 21% maintain a fully up-to-date inventory of agents, tools, and connections, according to Akto's State of Agentic AI Security 2025 report. The control gap is no longer theoretical: governance, visibility, and runtime enforcement are lagging the pace of autonomous action.
NHIMG editorial — based on content published by Akto: The State of Agentic AI Security 2025
By the numbers:
- 69% of enterprises are already piloting or running early production agent deployments.
- Only 21% of organizations maintain a fully up-to-date inventory of agents, MCP servers, tools, and connections.
- 79% of organizations have no formal governance policy for AI agents or MCP connections.
Questions worth separating out
Q: How should security teams govern AI agents that can access enterprise systems?
A: Security teams should govern AI agents as non-human identities with explicit ownership, scoped privileges, and continuous monitoring.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.
Q: What breaks when organizations do not inventory AI agents and MCP connections?
A: Security teams lose the ability to answer what exists, what it can reach, and who owns it.
Practitioner guidance
- Build a live agent inventory Track every agent, MCP server, tool, and delegated connection in a continuously updated register so security teams can see what exists and who owns it.
- Define action boundaries for each agent Classify which tool calls are read-only, which can modify data, and which require approval before execution so permissions reflect actual runtime risk.
- Add runtime guardrails around tool execution Block unsafe calls, log every tool invocation, and enforce policy at the moment of action rather than relying on post-event review.
What's in the full report
Akto's full blog covers the operational detail this post intentionally leaves for the source:
- Breakdowns of agent inventory, monitoring, and governance maturity by survey segment.
- The reported threat categories practitioners ranked highest for 2026 planning.
- Examples of runtime guardrails and control patterns discussed for agentic deployments.
- The full benchmark findings from 100+ verified security and AI leaders.
👉 Read Akto's analysis of the state of agentic AI security in 2025 →
AI agents and governance blind spots: what IAM teams need now?
Explore further
Agent inventories are now an identity control, not a discovery exercise. When 79% of organizations lack a fully up-to-date inventory of agents, MCP servers, tools, and connections, the issue is not operational tidiness. It is that identity governance cannot begin without knowing what non-human actors exist and what they are allowed to do. In agentic environments, inventory is the first control plane, and without it every downstream policy is partial at best.
A few things that frame the scale:
- 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%), according to AI Agents: The New Attack Surface report.
- 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: Who is accountable when an AI agent takes an unsafe action?
A: Accountability should sit with the business owner of the agent, the team that provisioned the access, and the control owners responsible for monitoring and revocation. If no one can answer who approved the identity, the scope, and the oversight model, the governance framework is not complete enough for production.
👉 Read our full editorial: Agentic AI security readiness is lagging enterprise adoption