Enterprises Now Have One Agent Per Employee
Opsin Labs, the research arm of enterprise AI governance platform Opsin, analyzed production environments across eight industry verticals between March 2025 and June 2026 for its first State of Agentic Adoption report. The headline number is the scale itself: enterprise environments now average one AI agent — live or in draft — for every employee, a level of proliferation that outpaces almost every prior enterprise software rollout in speed.
That growth has been explosive even within 2026 itself. Opsin found workforce interactions with AI agents grew 14x between January and June 2026 — a six-month window in which agentic AI went from a pilot-stage curiosity to embedded infrastructure across the organizations studied. Opsin CEO and co-founder James Pham framed the core problem bluntly: “Agent creation outran security review months ago… Governance has to catch up.”
The Permissions Problem, By the Numbers
The report’s central finding is that scale outpaced scoping. Of agents provisioned beyond an organization’s default settings, 60% were granted “allow-all” access rather than being restricted to the specific permissions their task required. Separately, the report found that 60% of agents had configured capabilities exceeding their original stated intent — meaning even agents that started with a narrow scope drifted toward broader access over time, likely as employees iteratively expanded what the agent could do without revisiting the original permission grant.
Who’s building these agents compounds the risk. Opsin found 67% of agents are built by employees without an engineering background — staff in go-to-market, customer success, and operations roles who can now spin up an autonomous agent through no-code tooling, often faster than security teams can establish or enforce provisioning discipline. The report attributes this to a structural mismatch: the tooling that lets a non-technical employee build a working agent in minutes has outrun the governance processes built for a world where only engineers deployed software with system access.
Advertisement
A Second Report Confirms the Governance Gap Is Structural
Opsin’s findings land alongside a parallel report from AI security vendor Gravitee, whose 2026 State of AI Agent Security survey paints a consistent picture from a different angle. Gravitee found that while 80.9% of technical teams have moved past planning into testing or production, only 14.4% have full security or IT approval covering their entire agent fleet before going live — meaning the overwhelming majority of production AI agents are running with partial or no formal sign-off.
The identity layer is similarly underdeveloped. Gravitee found just 21.9% of organizations treat AI agents as independent, identity-bearing entities with their own credentials and audit trail, while 45.6% still rely on shared API keys for agent-to-agent authentication — a practice that makes it nearly impossible to attribute a specific action to a specific agent after the fact. More than a quarter of technical teams, 27.2%, have reverted to custom, hardcoded authorization logic rather than using a managed identity system, and 25.5% of deployed agents can create and task other agents — compounding the permissions problem recursively, since an over-permissioned agent that can spawn sub-agents can propagate its own excess access outward.
The consequences are already visible: Gravitee found 88% of organizations reported a confirmed or suspected AI-agent security incident, rising to 92.7% in healthcare specifically — yet 82% of executives said they were confident their existing policies protect against unauthorized agent actions, a confidence gap that suggests leadership visibility into actual agent behavior lags well behind the technical reality documented by both reports.
What This Means for Enterprise Security and AI Governance Teams
1. Treat every agent as a new identity requiring its own credential, not a feature of an existing app
With only 21.9% of organizations giving agents independent, identity-bearing credentials per Gravitee’s data, most enterprises are still treating agents as a configuration option inside existing software rather than as autonomous actors that need their own provisioning, audit trail, and revocation path. Security teams should build an agent identity registry now — before the current agent population doubles again — rather than retrofitting one after an incident forces the question.
2. Default every new agent to zero standing permissions, expand only on documented justification
Because 60% of non-default agents ended up with allow-all access per Opsin’s data, the root cause is almost certainly permissive defaults combined with no re-approval step when scope expands. Enterprises should flip the default: agents start with zero access, and every permission addition requires a logged justification tied to a specific task — making “why does this agent have this access” answerable by design rather than by forensic reconstruction after an incident.
3. Give non-engineering agent builders a governed no-code path, not an ungoverned one
Since 67% of agents are built by non-engineers, banning no-code agent creation outright is unrealistic — it’s already how the majority of agents get built. Instead, enterprises should route no-code agent builders through templates with pre-scoped, least-privilege permission sets baked in, so a GTM or customer success employee can still self-serve an agent without personally deciding what system access is “probably fine.”
The Governance Question Beneath the Adoption Numbers
What both reports converge on is a timing mismatch rather than a technology failure: the tooling for building autonomous agents matured faster than the organizational muscle for governing what those agents can touch. A 14x growth in agent interactions over six months is not, by itself, a security problem — but pairing that growth rate with 60% over-permissioning and just 14.4% full security approval turns rapid adoption into rapid, compounding exposure.
The 82%-executive-confidence-versus-88%-incident-rate gap that Gravitee documented is the most consequential number in either report, because it suggests the governance failure isn’t primarily technical — it’s a visibility failure at the leadership level. Enterprises don’t necessarily lack the tools to scope agent permissions correctly; they lack accurate information about how badly scoped their current agent fleet already is. Closing that visibility gap, through an agent identity registry and mandatory pre-production security review, is the prerequisite for any of the more sophisticated governance fixes both reports recommend.
Frequently Asked Questions
What is Opsin Labs’ State of Agentic Adoption 2026 report?
It is the inaugural research report from Opsin Labs, the research arm of enterprise AI governance platform Opsin, analyzing production AI agent deployments across eight industry verticals between March 2025 and June 2026. It found 60% of non-default agents had allow-all access and enterprises now average one agent per employee.
How much have AI agent security incidents grown?
Gravitee’s 2026 State of AI Agent Security report found 88% of organizations reported a confirmed or suspected AI-agent security incident, rising to 92.7% in healthcare specifically — even though only 14.4% of organizations have full security approval covering their entire agent fleet.
Who is building most of these over-permissioned agents?
According to Opsin Labs, 67% of AI agents are built by employees without an engineering background, typically in go-to-market, customer success, and operations roles, using no-code tools that let them deploy an agent faster than security teams can review its permission scope.
Sources & Further Reading
- Opsin Labs Report: 60% of Enterprise AI Agents Are Over-Permissioned as Adoption Accelerates 14x — AIThority
- Opsin Labs Report: 60% of Enterprise AI Agents Are Over-Permissioned as Adoption Accelerates 14x — Yahoo Finance
- State of AI Agent Security 2026 Report: When Adoption Outpaces Control — Gravitee
- Opsin Leads the Second Generation of Enterprise AI Security as Agents Move from Saying to Doing — Morningstar












