AgentsRolesInsightsCases🌐 EspañolGet an agent📱 WhatsApp · Talk to Luz

88% of companies already had an incident with their AI agents — and 82% of their executives think they're protected

Two 2026 studies with more than 2,600 senior technical leaders surveyed reveal the same gap: 96% of companies already have agents deployed, but nearly half operate without real oversight. The risk doesn't come from the agent that fails — it comes from the one that works without anyone watching.

Two truths coexist inside the enterprise this August. The first: 96% already have at least one AI agent in production — not as a pilot, but as part of daily operations. The second: 88% experienced a security or privacy incident related to those agents in the last year. Two 2026 studies, with more than 2,600 senior technical leaders surveyed in total, document not just massive adoption, but the gap between what executives believe and what actually happens inside their agent stack.

96%of companies already use AI agents in some productive capacity — not in a pilot (OutSystems State of AI Development 2026, 1,900 global IT leaders)
88%experienced confirmed or suspected AI agent security or privacy incidents in the last year (Gravitee State of AI Agent Security 2026, 750+ senior tech leaders, UK+USA)
48%of all AI agents in production run with no monitoring — mean security coverage across the full deployed fleet: 52% (Gravitee 2026)
14.4%of agents go live with full formal security and IT approval — 85.6% launch without that sign-off (Gravitee 2026)

The confidence gap: executives believe they're protected; the logs say otherwise

The most revealing number in the Gravitee report isn't the incident rate — it's the contrast. 82% of executives say their policies protect them from unauthorized agent actions. At the same time, 88% report incidents. Both figures come from the same set of companies. The equation produces the most documented confidence gap of the year in enterprise AI: those defining strategy believe they're covered; those reading the production logs know they're not.

What 'agent sprawl' is — and why 94% of enterprises already have it

Sprawl is what happens when an organization deploys agents without a common framework: different teams build different agents with different tools, no shared standards, no central visibility, no clear owner. 94% of companies surveyed by OutSystems report they already have it. 38% mix homegrown and third-party platform agents without a common governance model — the same situation that produced “shadow IT” in the cloud a decade ago, now repeating with agents. Only 12% have a centralized platform to manage it.

The most dangerous agent isn't the one that fails — it's the one that works unsupervised

Only 21% of companies have real-time visibility into what their agents are doing. In the other 79%, an agent can make decisions — responding to customers, modifying records, sending information — without anyone being able to review what it did until hours or days later. The risk isn't the agent that answers a query poorly: that failure is visible and gets fixed. The risk is the one that works correctly 99% of the time but in the 1% acts outside its scope without leaving an auditable trail. Furthermore, only 22% treat their agents as independent identities — the rest assign them the same shared API keys used by the whole team, making it impossible to separate what the agent did from what a person did.

  • Independent identity per agent: each agent has its own permissions, not the team's shared API keys — this makes it possible to audit exactly what it did and revoke access if something fails.
  • Real-time visibility: someone in the organization reads conversation traces continuously, not retrospectively after a problem has already occurred.
  • Formal approval before production: the 14.4% that gets complete IT and security sign-off before activating an agent reports a significantly lower incident rate.
  • Named owner: one person with a name and accountability for each agent — not a department, not a support ticket opened after something goes wrong.
96% of companies already have agents. The question is no longer whether to adopt — it's whether whoever adopted knows what's running and who's watching it. An agent without oversight isn't a tool: it's an employee nobody sees working and nobody is responsible for when something goes wrong. The time to define that governance isn't after the first incident.
← All Insights

Which role in your company should an agent run?

Talk to Luz, our agent, instantly. No strings attached.

Free · instant · No commitment