Download Publication
Who it's for:
- CISOs and security leaders
- IAM professionals
- AI security and governance professionals
- GRC and compliance professionals
Securing Autonomous AI Agents
Release Date: 02/04/2026
Autonomous AI agents are being embedded across cloud, hybrid, and on-prem environments. However, most identity systems were built for humans, not for self-directed, API-driven agents operating continuously at runtime. This comprehensive survey report, commissioned by Strata, explores the current state of autonomous AI agent security in enterprises and the associated Identity and Access Management (IAM) challenges.
The report reveals a growing gap between agent adoption and enterprise readiness. Organizations are deploying hundreds of AI agents, yet they lack agentic identity governance policies to help manage them safely. The findings highlight widespread reliance on static credentials, fragmented authorization models, limited discovery, and weak traceability.
The report argues for securing autonomous agents with the same rigor historically reserved for human users. It examines confidence in IAM for agents, traceability and human-in-the-loop oversight, and emerging investment patterns. The results point to a “Time-to-Trust” phase, where organizations are balancing innovation with caution.
This research provides critical insight for organizations seeking to securely scale agentic systems while maintaining governance, compliance, and operational trust.
Key Takeaways:
- 40% of organizations already have agents in production. Another 31% are running pilots or tests, with 19% planning deployment within the next year.
- Only 18% of respondents say they are “highly confident” their current IAM systems can manage agent identities effectively. 35% express only moderate confidence and 29% express slight confidence. Another 18% report no or uncertain confidence.
- Many organizations are still relying on outdated credentialing and access patterns. The most common authentication methods are static API keys, username and password combinations, and shared service accounts.
- Only 21% of organizations maintain a real-time registry or inventory of their agents. 32% rely on non-real-time records, another 32% plan to build one within the next year, and 8% have no registry at all.
- 40% of organizations report increasing their overall identity and security budgets to accommodate AI agents. 34% are allocating a dedicated budget line and another 22% are reallocating funds from other security areas. Only 26% report no planned budget changes.
Download this Resource
Interested in helping develop research with CSA?
Related Certificates & Training
.png)
Learn the core concepts, best practices and recommendation for securing an organization on the cloud regardless of the provider or platform. Covering all 14 domains from the CSA Security Guidance v4, recommendations from ENISA, and the Cloud Controls Matrix, you will come away understanding how to leverage information from CSA's vendor-neutral research to keep data secure on the cloud.
Learn more
Learn more


.jpeg)
.jpeg)
.jpeg)
.jpeg)
