AI agents have quickly moved beyond experimental chatbots. They can retrieve data, call APIs, trigger workflows and act across cloud environments, often without someone supervising every individual action.
That makes them useful. It also gives them something many early AI conversations overlooked: identity, access and credentials.
To understand how organisations are managing this shift, Akeyless partnered with MRA Research on a study of 400 IT and security decision-makers. The research covered 300 respondents in the United States and 100 in the United Kingdom, exploring how AI agents are deployed, what they can access and where existing identity controls are starting to struggle.
The risk is already real
Among organisations using AI agents, 67% suspect that agents have already accessed data beyond their intended scope. More than six in ten, 61%, have revoked or rotated an AI agent credential because they believed it may have been exposed.
The financial and operational consequences are significant too. Organisations reported spending more than $1 million on average over the previous year responding to AI agent identity and security issues. When an agent is compromised, it takes an average of 14 hours to detect the problem, followed by nearly a week to contain and remediate it.
One of the most striking findings concerns the potential aftermath. Some 83% said that a single compromised AI agent credential could affect multiple major systems. Yet only 7% believed their current controls would actually prevent a compromised agent from continuing to operate.
Valid access can still be dangerous
The challenge is not simply that AI agents are “breaking in”. In many cases, they are entering systems using valid credentials and permissions that an organisation has deliberately provided.
Risk emerges when those credentials remain active for too long, when permissions are broader than the task requires, or when nobody has a complete view of what an agent can access.
Traditional identity and access management was largely designed around human users, recognisable sessions and relatively predictable roles. AI agents behave differently. They can act continuously, move between systems and complete chains of actions at machine speed. The research suggests that many organisations are trying to manage this new operating model with identity controls built for an earlier era.
Identity needs to become part of AI governance
Securing AI agents starts with treating each agent as an identity in its own right.
That means establishing a clear owner and purpose, issuing access that is limited to the task, replacing persistent credentials with shorter-lived alternatives and retaining an audit trail of what the agent actually did.
It also means moving from periodic access reviews towards continuous control. An agent’s authority should be able to change when its task, context or behaviour changes.
This is not just a security concern. Nearly three-quarters of organisations surveyed said that AI adoption could move faster if identity risks were better controlled. Identity security is therefore becoming part of the business case for AI, rather than a final check at the end of deployment.
The full 2026 State of AI Agent Identity Security report explores the findings in more detail, including the credential practices, governance gaps and operational controls organisations are putting in place.
To explore how AI identity and access risks are developing in your sector, contact Callum Budd at callum@mra-research.co.uk.