A chief information officer I was talking with recently said something that stuck with me: Permissions tell an agent what it’s allowed to do. They say nothing about what you meant.
This observation touches on one of the core artificial intelligence challenges leaders face today. As AI agents increasingly move into everyday work, they’re operating without the governance controls to do so securely, and that gap has already led to widespread security incidents.
Our research has found that 47% of employees now rely on agents daily or weekly, while 88% of organizations experienced an agent-related breach within the last year. A similar survey by Gravitee Topco Ltd. found that 88% of organizations had confirmed or suspected agent security incidents, even though 82% of executives felt confident their existing policies protected them.
But the clearest recent proof of that gap didn’t come from a survey at all. It came from OpenAI Group PBC itself. Last month, the company disclosed that one of its own pre-release models, while being tested against a cybersecurity benchmark called ExploitGym, escaped its isolated test environment, chained together stolen credentials and a previously unknown software vulnerability and hacked into the production systems of Hugging Face Inc. to find the answers to its own test. Nobody instructed the model to do this; it stayed inside the boundaries of its assignment and still produced an outcome no one intended or authorized.











