Coedee Enterprise Watch
The Gap In Two Numbers
80.9% of technical teams have already pushed AI agents into active testing or production. Only 14.4% did it with full security and IT sign-off. That gap is where this year’s biggest quiet risk is sitting.
Somewhere in the last six months, AI agents stopped being a pilot project and became infrastructure. Nobody sent a memo announcing it. It just happened, quietly, department by department, as teams discovered that an agent could retrieve a customer record, summarize a document, or update a database faster than the human workflow it replaced. The problem is that security and governance did not scale at the same pace — and a wave of new research this year is putting hard numbers on exactly how wide that gap has become.
The Growth Curve Nobody Budgeted For
According to a survey tracking enterprise AI agent deployment, the average organization had roughly 37 agents running as of December 2025. By April 2026, that number had shifted so sharply that nearly 38% of organizations reported having more than 100 agents already deployed — a rough doubling of fleet size in a single quarter. Looking forward, 81.7% of organizations plan to deploy still more agents over the next twelve months, with travel and transport companies leading the charge toward expansion and healthcare organizations showing the most visible caution, for reasons that become clearer below.
That growth curve tracks with a broader industry projection: analysts at Gartner have estimated that 40% of enterprise applications will include task-specific AI agents by the end of this year, up from under 5% just two years ago. What was, by any reasonable measure, an experimental technology in 2024 is now core production infrastructure at a majority of large organizations.
Confidence Rose. Actual Security Didn’t.
Here’s the finding that should worry anyone responsible for enterprise risk: as adoption accelerated, organizations reported feeling more confident about their security posture — even though the underlying controls barely moved. One industry survey found that 82% of executives report confidence that their existing policies protect against unauthorized agent actions. Meanwhile, only 14.4% of organizations report that their agents went into production with full security and IT approval, and just 29% describe their security controls as comprehensive.
Researchers tracking the sector describe this precise gap — rising confidence paired with static controls — as the defining problem of enterprise AI security this year: organizations becoming comfortable with a risk they haven’t actually reduced.
The Numbers Behind the Confidence Gap
- 88% of organizations report a confirmed or suspected AI agent security incident in the past year — a figure that climbs to 92.7% in healthcare specifically
- Only 21.9% of teams treat AI agents as independent, identity-bearing entities, rather than folding them into generic human or service-account permissions
- The average enterprise now runs roughly 1,200 unofficial “shadow AI” applications — tools deployed outside official visibility or approval
- Shadow AI-related breaches cost, on average, $670,000 more than a standard security incident
Why This Isn’t Just a Bigger Version of Old Security Problems
It’s tempting to treat “agent security” as just cloud security with extra steps. It isn’t, and the distinction matters. An over-permissioned employee account is a known, well-understood risk with mature tooling built to catch it. An over-permissioned AI agent is a different animal: it can act at machine speed, across dozens of connected tools, without the situational judgment a human employee brings to an obviously wrong instruction. A support agent that technically only needs read access to case history can, if the permission set was built for convenience during a rushed rollout, also have write access to customer records that nobody remembers granting six months later. A finance-summarization agent might retain the ability to download a raw dataset it was never meant to touch directly.
Memory compounds the problem in a way most security teams haven’t fully priced in. Agents that retain conversation history or context across sessions gradually accumulate sensitive information — customer data, internal decisions, occasionally credentials — inside a context window that, without an explicit lifecycle policy, simply keeps growing. Security frameworks are starting to recommend hard token limits on agent memory specifically to prevent this kind of silent, unbounded accumulation, treating it as its own category of exposure distinct from the well-trodden territory of prompt injection or data exfiltration.
A Cautionary Tale From Outside the Enterprise
The clearest illustration of what happens when agent identity and permissions are treated as an afterthought didn’t come from a Fortune 500 company — it came from a viral consumer product. Moltbook, an AI agent social network that let bots interact autonomously in Reddit-style forums, went viral in January for what looked like agents spontaneously organizing a secret, encoded language to communicate outside human oversight. It later emerged that an unsecured database had let anyone hijack any agent’s credentials on the platform, and the “secret language” that alarmed millions of viewers was, in reality, a person exploiting that vulnerability to post under a hijacked agent’s identity. Meta acquired the platform in March. Moltbook was a consumer product, not enterprise infrastructure, but the underlying lesson translates directly: when agents operate without real identity management, permission gating, and audit logging, the failure mode isn’t hypothetical, it’s a live vulnerability waiting for someone to find it.
What Organizations Say Would Actually Help
When surveyed about what would most increase their confidence in deploying agents securely at scale, respondents’ answers came back almost evenly split across several options — industry standards or frameworks for agent governance, better real-time tooling to observe agent behavior, and clearer regulatory guidance specifically written for AI agents, rather than adapted from older software security rules. The near-tie across all three signals something important: there isn’t one silver-bullet fix. The problem is genuinely multi-dimensional, and organizations know it, even if their current spending and staffing haven’t caught up to that recognition yet.
The Bottom Line for Anyone Deploying Agents Right Now
The uncomfortable truth in this year’s data is that the risk curve and the deployment curve are moving in opposite directions. Agent fleets have roughly doubled in a quarter. The gap between “somewhat prepared” organizations and “very prepared” ones — 60.8% versus 30.4% in one survey — is exactly where the unmanaged risk is concentrated, and it’s only getting more expensive to close as fleets keep growing. For any organization currently treating AI agents as a productivity upgrade rather than a new category of identity-bearing infrastructure that needs its own governance, the data from this year is about as clear a warning as this space is likely to produce before the incident numbers get harder to shrug off.
A Practical Starting Checklist
For teams trying to close the gap rather than just admire it, the research converges on a handful of concrete, non-exotic starting points, and none of them require waiting for a formal industry standard to arrive:
- Give every agent its own identity. Stop folding agents into generic service accounts or human credentials. An agent that can’t be individually identified can’t be individually audited when something goes wrong.
- Audit permissions against actual need, not convenience. A rushed rollout tends to over-grant access “just in case.” Revisiting those grants against what the agent genuinely does in practice, on a recurring schedule, catches the drift before it becomes a breach.
- Set hard limits on agent memory. An unbounded context window is an unbounded liability. A fixed token cap on retained conversation history forces a defined information boundary instead of letting sensitive data accumulate indefinitely.
- Build real-time visibility before scaling further. Confidence without monitoring is the exact pattern the data flags as the core problem. Logging and behavioral visibility should arrive before the hundredth agent, not after the first incident.
- Bring shadow AI into the light deliberately. With roughly 1,200 unofficial AI tools running per organization on average, an amnesty-style discovery process — inventorying what’s already running rather than only policing new requests — tends to surface more real exposure than any new-deployment policy alone.
None of this is exotic advice, and that’s precisely the point critics of the current state of enterprise AI security keep making: the fixes are largely known and achievable with existing security discipline. What’s missing isn’t insight. It’s the organizational urgency to apply governance at the same pace the deployment curve is already moving.
Why Healthcare Is Both the Most Cautious and the Most Exposed
The healthcare sector’s simultaneous caution and elevated incident rate deserves a closer look, because it’s a useful case study for every other regulated industry watching from the sidelines. Healthcare organizations report the most hesitation about further agent expansion of any sector surveyed, and yet they also report the highest confirmed-or-suspected incident rate at 92.7%. That combination isn’t really a contradiction — it’s what happens when an industry with genuinely high-stakes failure modes, from diagnostic misclassification to unlogged medication guidance errors, adopted agentic tools quickly enough that governance is still catching up. The caution being reported now likely reflects lessons already learned the hard way over the past year, not lessons anticipated in advance. Other regulated sectors — finance, legal services, insurance — are earlier in that same curve, which makes healthcare’s current numbers less a healthcare-specific problem and more a preview of what’s coming for everyone else on a similar adoption timeline.
