Most enterprises have already put AI agents into production.
Far fewer have given those agents the identity controls a human employee would be required to have. New research from JumpCloud puts a number on that gap: 72% of organisations now run AI agents in production, yet 92% report some limit on how far they can scale them, and security concerns are the single largest reason why.
This is not a story about AI adoption stalling. It is a story about governance failing to keep pace with adoption, and about what happens to an enterprise’s risk profile when that gap is left open.
AI agents are already running the business, not just piloting it
Agentic deployment has moved well past the experimentation phase.
According to the report, of the 72% of organisations running agents in production, 31% have already deployed them into business-critical environments, covering financial reporting, HR provisioning, access management and customer-facing systems. Only 28% of organisations remain in testing.
The average organisation now runs 15.8 AI agents actively interacting with internal systems or APIs. Among organisations with business-critical deployments, that figure rises to 20.3, against 10.8 for organisations still in testing. Deployment maturity also tracks company size: JumpCloud found that 37% of large enterprises (1,000โ2,500 employees) run agents in business-critical workflows, compared with 17% of smaller organisations (200โ499 employees).
The effect on the identity landscape is structural, not incremental.
53% of organisations already have more non-human identities than human employees, and 23% report six times or more non-human identities than human users. Traditional identity infrastructure was built to manage people. In a majority of organisations, people are no longer the majority of the identity environment.
Access has already outpaced oversight
The report’s most consequential finding is about what agents are capable of doing once they’re in. 66% of organisations say their AI agents have equal or greater system access than human users, and 38% of organisations running business-critical deployments give agents significantly more access than the humans working alongside them.
Oversight is moving in the opposite direction from where risk is concentrating.
Among testing-stage organisations, 48% require human-in-the-loop approval before high-risk actions proceed. In business-critical environments, that figure falls to 29%, replaced by automated post-action review (39%) and fully autonomous action with zero human supervision (24%). Put plainly: the environments with the most access and the most consequence are the ones with the least human checkpoint before something happens.
JumpCloud frames this as the compounding risk of scale: business-critical organisations run nearly twice as many agents, on average, as testing-stage organisations, and are more likely to report much higher ratios of non-human to human identity.
When an organisation’s fastest-growing identity group is also its least supervised, scaling deployment means scaling the blind spot along with it.
Identity and authentication are still fragmented
Only 37% of organisations have fully integrated AI agents into formal identity and access management systems.
The remaining 63% are split between partial integration (42%), agents managed entirely outside formal IAM (17%), and organisations with no formal policy at all (4%).
Authentication practice reflects the same fragmentation. Organisations use an average of 2.2 authentication methods for agents, rising to 2.7 among business-critical deployers, spanning individually scoped machine identities (53%), long-lived API keys (49%), shared service accounts (37%), secretless access via a centralised gateway (36%) and just-in-time authorisation (26%). Notably, long-lived API keys, the least secure of the common methods, climb to 71% adoption among organisations running business-critical agent workflows. The most sensitive environments are, on current evidence, the most exposed.
There is also a visible perception gap between leadership and the practitioners closest to the problem.
68% of CIOs believe their AI agents are fully compatible with formal IAM policy. Among IT Managers and IT Team Leads, only 35% report the same. That 33-point gap matters, because a board that believes governance is solved has no reason to fund fixing it.
Visibility, control and ownership are the weakest links
Beyond access, JumpCloud’s data points to three specific control gaps that most organisations have not closed:
- 59% lack centralised visibility into agent activity
- 59% don’t maintain full audit trails
- 55% have no centralised kill switch for AI agents, and of those without one, a third say their only option is to disable agents manually, system by system
Accountability is similarly undefined.
Only 17% of organisations have a designated security leader accountable for AI agent actions, 47% default that responsibility to IT by default rather than design, and just 6% have a cross-functional governance committee. The pattern gets worse, not better, as deployment matures: in business-critical environments, IT alone absorbs accountability in 51% of organisations, versus a shared IT-security model in the testing phase.
Regionally, the report also identifies a speed-versus-control split. U.S. organisations are moving faster and granting broader access (44% grant greater-than-human access, versus 29% in the UK; 16% allow full autonomy for high-risk actions, versus 8% in the UK), while UK organisations are more likely to require human-in-the-loop approval (64% versus 52% in the U.S.) and maintain full audit trails (47% versus 34%).
Stronger governance doesn’t remove scaling barriers, but the data suggests it reduces their bite: UK organisations are twice as likely as their U.S. counterparts to report no current limits on scaling (10% versus 5%).
Why this is a Phase Zero problem, not a tooling problem
This is where the pattern in JumpCloud’s data lines up with what we see across enterprise AI programmes generally: organisations that treat governance as a retrofit consistently scale slower and carry more exposed risk than organisations that build the identity and access foundation before agents go into production.
JumpCloud’s own recommended framework moves through four stages: discover what agents are running, register each one against a named human owner, manage access on a least-privilege basis, and govern behaviour on an ongoing basis through logs, audit trails and scheduled review.
That sequence is close to what we call Phase Zero in enterprise AI delivery: establishing the identity, access, data and accountability foundation before scale, rather than trying to bolt governance onto an environment that already has 15 or 20 agents touching production systems with more access than the humans next to them.
The organisations in the report that have cleared this hurdle show what’s on the other side of it. Business-critical deployers are more than three times as likely as testing-stage organisations to report no current limits on scaling (13% versus 4%). Governance, done early, is not a brake on velocity. It’s the precondition for it.
The practical starting point
For CIOs and CDOs looking at this data and recognising their own organisation in it, the sequence that matters is straightforward, even if the execution isn’t:
- Inventory every agent, sanctioned or not, and what it can reach. Only 33โ43% of organisations currently have this.
- Assign a named human owner to each agent, not a department. Only 17% currently have designated security ownership.
- Move off long-lived credentials and shared accounts for anything touching business-critical systems, where they’re already running at 71% adoption.
- Build a single, centralised revocation point. More than half of organisations still can’t shut an agent down in one action.
- Require human approval on high-risk actions in business-critical environments specifically, since this is where oversight is currently weakest, not strongest.
None of this requires slowing deployment. It requires sequencing it correctly, which is the entire argument for treating agentic AI governance as infrastructure work rather than a policy document.
FAQ
What is the “agentic IAM governance gap”? It’s the difference between how quickly organisations are deploying AI agents into production and how far their identity and access controls have caught up. JumpCloud’s 2026 research found 72% of organisations have AI agents in production, but only 37% have fully integrated those agents into formal identity and access management systems.
What percentage of companies have AI agents with more access than human employees? 66% of organisations report their AI agents have equal or greater system access than human users, according to JumpCloud’s Agentic IAM Pulse Report. In business-critical environments specifically, 38% give agents significantly more access than the humans working alongside them.
Do most organisations have a kill switch for AI agents? No. 55% of organisations surveyed do not have a centralised kill switch for AI agents, and a third of those say their only option is to disable agents manually, system by system, rather than shutting them down in one action.
Who is accountable when an AI agent causes a security incident? In most organisations, nobody has been formally assigned that responsibility. Only 17% have a designated security leader accountable for AI agent actions; 47% default responsibility to IT by circumstance rather than design, and just 6% have a cross-functional governance committee.
Does stronger AI governance slow down deployment? The data suggests the opposite. Organisations with business-critical AI deployments are more than three times as likely as testing-stage organisations to report no current limits on scaling (13% versus 4%). Governance built early functions as the precondition for scale, not a brake on it.
What’s the first practical step toward closing the gap? Start with discovery: build a complete inventory of every AI agent operating in the environment, what systems and APIs it touches, and who owns it. JumpCloud’s data shows only 33โ43% of organisations currently have this visibility, and every other governance control depends on having it first.





