Companies Are Racing to Deploy AI Agents — Governance Is Struggling to Keep Up
Enterprises are deploying artificial intelligence agents at a striking pace, and a recent vendor report suggests some organizations are approaching a ratio of roughly one AI agent per employee. That figure comes from a report published by Opsin, a company that sells AI governance software, distributed as a paid press release rather than independent research. It should be read as a marketing claim from a party with a direct commercial interest in this narrative, not as a verified industry statistic.
Opsin's report also claims that workforce interactions with AI agents grew 14 times over in a six-month period, that 67% of agents are built by employees without an engineering background, and that 60% of agents provisioned beyond default settings were granted broad, allow-all access. These numbers derive from Opsin's own proprietary, non-peer-reviewed methodology. Vendor-sponsored research in the security industry tends to highlight dramatic figures that justify the sponsor's own product category, and that pattern appears to be present here as well. Without independent verification or published methodology, these specific statistics are best treated as attention-getting claims rather than established fact.
What Independent Research Actually Confirms
Setting aside the vendor's specific numbers, a broader and better-supported trend does emerge from non-vendor-conflicted sources. The Cloud Security Alliance, a nonprofit research and standards body, has published research indicating that AI agent security incidents are now common inside enterprises, and that agentic AI introduces novel challenges around what the industry calls non-human identity, or NHI, governance. The CSA describes these challenges as materially different from traditional IT security problems, since autonomous agents can take actions and chain together permissions in ways human user accounts typically do not.
Gartner has separately issued formal guidance identifying what it calls "AI agent sprawl" as an emerging enterprise risk, outlining a six-step framework for managing it. Because this guidance comes from an independent analyst firm rather than a company selling a competing governance product, it carries more weight than a single vendor's self-published statistics. Together, the CSA and Gartner findings support a consistent picture: enterprises are adopting agentic AI faster than they are building the oversight structures to manage it.
The Over-Permissioning Problem, According to Industry Vendors
Several security vendors — including SailPoint, Akamai, and Kovrr — have published research and blog content arguing that AI agents are frequently granted more system access than their actual function requires. These findings point in a similar direction as Opsin's claims and are worth noting as directionally supportive. However, these companies also sell identity and access governance products, so their published data, like Opsin's, should be understood as coming from parties with a stake in the conclusion rather than as neutral third-party findings.
A recurring concern raised across this vendor research is that many AI agents are provisioned with "allow-all" style access rather than permissions scoped to their specific task. Opsin's report frames this as affecting roughly 60% of the agents it examined, describing several common attack paths that can result. Because this statistic and its underlying methodology have not been independently published or verified, it should be treated as a possibility raised by an interested party rather than a confirmed industry-wide rate. The broader concern it points to — that permission scope for AI agents often exceeds actual need — is nonetheless echoed across multiple sources with varying degrees of independence.
Why Non-Human Identity Governance Is Becoming Its Own Discipline
As organizations deploy growing numbers of AI agents, a new area of security practice has begun to take shape around what's called non-human identity governance. The Cloud Security Alliance has produced a dedicated whitepaper on agentic AI governance, treating this as a distinct and recognized security category rather than a subset of conventional identity and access management.
The practical issue is that identity frameworks built around human employees — with predictable login patterns, defined roles, and manual access requests — don't map cleanly onto autonomous software agents that can be created quickly, granted broad permissions by default, and left running with minimal oversight. This structural mismatch is what several researchers point to as the underlying reason over-permissioned agents can become attractive targets or unintentional attack vectors, independent of any single vendor's specific statistics.
The Governance Gap Is Real — Even If the Headline Statistic Isn't Verified
Reconciling these threads, an important distinction emerges: the specific numbers attached to this trend — one agent per employee, 14x growth, 60% over-permissioned — originate from a paid press release by a company selling the exact governance software those numbers argue for. That doesn't mean the underlying concern is unfounded. Independent bodies like the Cloud Security Alliance and Gartner, which have no product to sell into this specific narrative, corroborate the broader thesis that enterprises are deploying AI agents faster than they are building the governance structures to manage them.
Gartner's six-step framework for managing AI agent sprawl offers a practical starting point for organizations grappling with this gap, emphasizing structured discovery of existing agents, clear ownership and lifecycle management, and scoped rather than default-broad permissions. Many in the security research community view agent oversight as a maturing but urgent priority — one that enterprises will need to address on its own merits, separate from any individual vendor's promotional statistics.