AI agents are spreading fast in workplaces — even though most IT experts think they’re risky.
A new report from data governance firm SailPoint shows that nearly every company using AI agents is aware of the risks, but that hasn’t slowed down adoption.
In a survey of over 350 IT professionals worldwide, 96% said AI agents pose security risks, yet 98% still plan to use more of them in the next year.
So why is everyone moving forward anyway?
AI Agents Are Useful — But Not Without Risks
AI agents aren’t like the usual chatbots. They’re designed to make decisions and take actions without human input.
That makes them super efficient — but also potentially dangerous.
Right now, 84% of companies say they already use AI agents in some form. However, only 44% have actual policies in place to manage what those agents can and can’t do.
That’s a pretty big gap.
What Could Go Wrong?

According to the report, 80% of companies have already had agents do something unexpected — including:
- Accessing systems they weren’t supposed to
- Sharing sensitive data they shouldn’t have
The irony? Most IT leaders (92%) say that governing AI agents is critical for keeping their companies secure. But many are still rolling the dice.
Why Companies Are Still Using Them
The reason is simple: pressure to keep up.
Since OpenAI’s release of ChatGPT in 2022, companies have been chasing the AI boom — eager to streamline tasks and stay ahead of the curve. AI agents promise to save time, reduce workload, and unlock new possibilities.
So despite the warnings, many businesses feel like they can’t afford to wait.
“These agents are changing how we work,” said Chandra Gnanasambandam, CTO at SailPoint. “But they also open the door to new kinds of security threats.”
How to Stay Safe
If AI agents are going to be part of the team, they need to be managed like real employees.
SailPoint recommends:
- Giving agents only the access they need
- Monitoring their actions in real time
- Applying the same identity checks you’d use with human staff
“You wouldn’t give a new employee keys to everything on day one,” Gnanasambandam noted. “The same rule should apply to AI agents.”
Final Thoughts
AI agents are clearly useful. They’re efficient, flexible, and can handle a lot of work. But without the right controls in place, they could become a big security headache.
Companies may be racing ahead, but it’s critical they slow down just enough to put safety first.