ChaptersEventsBlog
How is your organization adopting AI technologies? Take this short survey to help us identify key trends and risks across FSI →

Download Publication

Securing Autonomous AI Agents
Securing Autonomous AI Agents
Who it's for:
  • CISOs and security leaders
  • IAM professionals
  • AI security and governance professionals
  • GRC and compliance professionals

Securing Autonomous AI Agents

Release Date: 02/04/2026

Autonomous AI agents are being embedded across cloud, hybrid, and on-prem environments. However, most identity systems were built for humans, not for self-directed, API-driven agents operating continuously at runtime. This comprehensive survey report, commissioned by Strata, explores the current state of autonomous AI agent security in enterprises and the associated Identity and Access Management (IAM) challenges.

The report reveals a growing gap between agent adoption and enterprise readiness. Organizations are deploying hundreds of AI agents, yet they lack agentic identity governance policies to help manage them safely. The findings highlight widespread reliance on static credentials, fragmented authorization models, limited discovery, and weak traceability.

The report argues for securing autonomous agents with the same rigor historically reserved for human users. It examines confidence in IAM for agents, traceability and human-in-the-loop oversight, and emerging investment patterns. The results point to a “Time-to-Trust” phase, where organizations are balancing innovation with caution.

This research provides critical insight for organizations seeking to securely scale agentic systems while maintaining governance, compliance, and operational trust.

Key Takeaways:
  • 40% of organizations already have agents in production. Another 31% are running pilots or tests, with 19% planning deployment within the next year. 
  • Only 18% of respondents say they are “highly confident” their current IAM systems can manage agent identities effectively. 35% express only moderate confidence and 29% express slight confidence. Another 18% report no or uncertain confidence. 
  • Many organizations are still relying on outdated credentialing and access patterns. The most common authentication methods are static API keys, username and password combinations, and shared service accounts.
  • Only 21% of organizations maintain a real-time registry or inventory of their agents. 32% rely on non-real-time records, another 32% plan to build one within the next year, and 8% have no registry at all. 
  • 40% of organizations report increasing their overall identity and security budgets to accommodate AI agents. 34% are allocating a dedicated budget line and another 22% are reallocating funds from other security areas. Only 26% report no planned budget changes.
Download this Resource

Bookmark
Share
Related resources
The State of Non-Human Identity and AI Security
The State of Non-Human Identity and AI Security
SCC WG 2026 Charter
SCC WG 2026 Charter
Data Security within AI Environments
Data Security within AI Environments
Global Privacy Trends and Best Practices for Compliance in 2026
Global Privacy Trends and Best Practices for Compliance in 2026
Published: 02/04/2026
Why DNS TXT Records Deserve Governance in Security Programs
Why DNS TXT Records Deserve Governance in Security Programs
Published: 02/02/2026
The Agentic Trust Framework: Zero Trust Governance for AI Agents
The Agentic Trust Framework: Zero Trust Governance for AI Agents
Published: 02/02/2026
Zero Trust in the Cloud: Designing Security Assurance at the Control Plane
Zero Trust in the Cloud: Designing Security Assurance at the Contro...
Published: 01/30/2026
Cloudbytes Webinar Series
Cloudbytes Webinar Series
January 1 | Virtual

Interested in helping develop research with CSA?

Related Certificates & Training