TL;DR: AI agents are in production at 72% of organisations, yet 92% say they cannot scale them safely and 66% grant them equal or greater access than human employees, according to JumpCloud’s Agentic IAM Pulse Report. The core problem is not adoption, but governance designed for static identities being applied to actors that can act without consistent human oversight.
Editorial analysis by NHI Mgmt Group, based on content published by JumpCloud: “JumpCloud Research Reveals AI Agents are Operating Without Governance in Critical Workflows”.
By the numbers:
- 72% of organizations have AI agents in use, but 92% report serious limits in safely scaling their deployments.
- 66% of organizations grant AI agents equal or greater system access than human employees.
- 55% of organizations lack a centralized kill switch to cut AI agent access across all systems.
Key questions
Q: What breaks when AI agents have broader access than their tasks require?
A: Over-privileged agents break segregation of duties, weaken auditability, and expand blast radius across transactions, data lookups, and workflow triggers.
Q: Why do human-in-the-loop approvals fail to scale for production AI agents?
A: Human-in-the-loop approval fails at scale because it depends on people seeing and judging actions fast enough to matter.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.
Practitioner guidance
- Define agents as governed identities Create an inventory that treats every AI agent as a first-class identity with owner, purpose, scope, and lifecycle status recorded from day one.
- Constrain agent access before production use Set pre-approved system boundaries, least-privilege scopes, and explicit escalation conditions before agents are allowed into financial, HR, or customer workflows.
- Replace ad hoc approval with policy guardrails Use policy-based controls for high-risk actions so the agent can only operate inside bounded authority rather than depending on a human to approve each step.
Bottom line: AI agents are already in production, but many organisations have not updated identity governance to match their operating speed or autonomy.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
AI agent governance is now an access paradox, not a tooling gap: the report shows organisations are granting agents equal or greater access than human employees while supervision declines in production. That combination means the control problem is no longer just provisioning. It is whether the enterprise can justify broad machine access without equivalent accountability. Practitioners should treat agent privilege as a blast-radius decision, not an automation convenience.
A few things that frame the scale:
- 92% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
- 23.7% of organisations share secrets through insecure methods such as email or messaging applications.
A question worth separating out:
Q: Who should be accountable when an AI agent causes a security or business incident?
A: Accountability should sit with a named owner outside the agent itself, usually a security or business leader with authority to approve scope and contain misuse. If the organisation defaults to IT alone, governance becomes operationally vague and incident response slows because no one owns the decision to restrict or stop the agent.
👉 Read our full editorial: AI agent governance gaps widen as production use expands
AI agent governance is now an access paradox, not a tooling gap: the report shows organisations are granting agents equal or greater access than human employees while supervision declines in production. That combination means the control problem is no longer just provisioning. It is whether the enterprise can justify broad machine access without equivalent accountability. Practitioners should treat agent privilege as a blast-radius decision, not an automation convenience.
A few things that frame the scale:
- 92% of organisations acknowledge that their non-human IAM practices lag behind or are merely on par with their human identity and access management efforts, according to The 2024 Non-Human Identity Security Report.
- 23.7% of organisations share secrets through insecure methods such as email or messaging applications.
A question worth separating out:
Q: Who should be accountable when an AI agent causes a security or business incident?
A: Accountability should sit with a named owner outside the agent itself, usually a security or business leader with authority to approve scope and contain misuse. If the organisation defaults to IT alone, governance becomes operationally vague and incident response slows because no one owns the decision to restrict or stop the agent.
👉 Read our full editorial: AI agent governance gaps widen as production use expands
AI agent governance is now an identity architecture problem, not an AI experimentation problem. When 72% of organisations already have agents in production and 92% cannot scale safely, the issue is no longer pilot readiness. The control plane has to govern non-human decision makers as first-class identities, because business use has already moved beyond the sandbox. Practitioners should treat this as a core IAM and NHI design issue, not a niche AI oversight topic.
A few things that frame the scale:
- 70% of organisations grant AI systems more access than they would give a human employee performing the exact same job, according to the 2026 Infrastructure Identity Survey.
- Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.
A question worth separating out:
Q: Who should be accountable for AI agent actions in enterprise systems?
A: Accountability should sit with the team that owns the agent, its policies, and the connected tools, not only with the person who typed the original prompt. When a software actor can send messages, update records, and move data across systems, responsibility must follow the governed identity and its enforcement layer.
👉 Read our full editorial: AI agent governance gaps widen as production use expands