AI agents are, at the same time, the hottest enterprise investment right now and the newest attack surface many organizations have introduced in years. The Cloud Security Alliance's numbers leave no ambiguity.
According to the report "Autonomous but Not Controlled: AI Agent Incidents Now Common in Enterprises" from the Cloud Security Alliance (CSA) together with Token Security, between 65% and 68% of organizations had at least one cybersecurity incident caused by AI agents operating on their corporate network during the past year.
It's not the incident percentage — it's the visibility gap. 68% of organizations said they had high confidence in their visibility over the agents running in their infrastructure. But 82% discovered AI agents they didn't know existed, mainly in internal automation environments and LLM platforms. In other words: most companies believe they know what agents they have running, and most are wrong.
An AI agent isn't a passive API that responds when called — it has permissions, executes actions, and often chains calls to other tools without human oversight at each step. That means a misconfigured agent, with broader permissions than it needs, or without clear limits on what it can and can't touch, behaves like a service account with excessive privileges — the kind of setup traditional security has spent years trying to eliminate, now reintroduced at scale under a new name.
For any company evaluating deploying agents to production, the conclusion isn't "don't use agents" — it's treating them with the same access-governance rigor you'd give a new employee with access to critical systems: limited scope, explicit permissions, and constant visibility into what they're doing.
Carlos Montiel is an enterprise AI solutions architect. He implements LLMs, Agents, RAG, and orchestrators for companies across Guatemala and Latin America. Reach out for a consultation.
Contact Carlos Montiel