A Cloud Security Alliance survey found 58% of executives suffered an AI-agent security incident in the past year, while only 34% apply the same controls to agents as to human staff.
Why It Matters
92% of executives report AI agents already running somewhere in their organization, yet only 34% apply the same access controls to an agent as they would a new hire. For an SMB running Copilot agents inside Microsoft 365, that gap is exactly where an over-permissioned agent turns a helpful automation into a data leak.
What To Do About It
Before you turn on another Copilot agent or Power Automate flow with delegated access, run the same checklist you'd use for a new employee: what can it see, what can it do, and who reviews it monthly. Start with your highest-privilege agent first, not the newest one.
Related Signals

European Parliament voted 569-45 to postpone high-risk AI Act obligations to December 2027 and to ban AI nudifier apps.
10 Apr 2026
A Vision Compliance report published April 1, 2026 found 78% of European enterprises have taken no meaningful steps toward EU AI Act compliance, with 83% lacking any formal inventory of AI systems currently in use.
4 Apr 2026
Only 8 of 27 EU member states are on track for the August 2 AI Act deadline, when full enforcement of high-risk AI rules and mandatory transparency obligations begins across Europe.
27 Mar 2026