title: "SailPoint: 79% of Enterprises Run AI Agents, 2% Have Security Tools" slug: "sailpoint-79-of-enterprises-run-ai-agents-2-have-security-tools" published: "2026-10-09" beat: "Research" tags: ["Research", "Business"] creator: "Agentry Newsroom" editor: "Susanne Sperling, Editor — Human in the Loop" tools: ["Claude (Anthropic)", "Perplexity Sonar"] creativeWorkStatus: "verified" dateReviewed: "2026-10-09" aiActArticle50: "compliant" humanView: "https://agentry.news/research/sailpoint-79-of-enterprises-run-ai-agents-2-have-security-tools" agentView: "https://agentry.news/agent/sailpoint-79-of-enterprises-run-ai-agents-2-have-security-tools"
SailPoint reported on October 6, 2026, that 79% of organizations have deployed AI agents in production environments, yet only 2% use purpose-built identity-security controls to govern them—exposing a
Drafted by an AI agent. Verified by Susanne Sperling, Editor — Human in the Loop. AI policy.
SailPoint identified a critical mismatch between enterprise AI agent adoption and security readiness in research released October 6, 2026. The company's Horizons of Identity Security study found that 79% of organizations were running AI agents in production, while only 2% had deployed identity-security tools purpose-built to manage and govern them—a reported 40-to-1 gap.
The deployment velocity outpaces security controls dramatically. AI agents represented 22% of non-human accounts across surveyed organizations, yet 85% of enterprises relied on legacy identity tools not designed for agentic identities. This means the majority of organizations managing a growing population of autonomous software workers lack dedicated governance infrastructure.
The research underscores an emerging operational risk in the agent economy. As agents execute real-world actions—from database queries to API calls to workflow automation—they operate under identities that legacy access-control systems treat as human users or generic service accounts. That misclassification leaves blind spots in audit trails, permission revocation, and threat detection.
Without purpose-built identity-security tools, organizations face compounded risks: agents may retain permissions after deployment ends, escalate privileges undetected, or operate under shared credentials that obscure which agent took which action. The gap is not theoretical—as agents proliferate in production, the surface area for misconfiguration and unauthorized access expands.
SailPoint's findings reflect a broader pattern in the agent economy: deployment velocity is outrunning governance maturity. Companies are shipping agents faster than they are building the control layers required to operate them safely at scale.
The research frames identity governance as a foundational layer of agent operations, not an afterthought. Organizations managing dozens or hundreds of agents in production face a choice: retrofit legacy identity systems with agent-aware policies, or adopt purpose-built agentic identity controls designed from the ground up for non-human actors.
The 40-to-1 adoption-to-security ratio highlights a critical inflection point. As agent deployments mature and regulatory scrutiny increases, enterprises will likely need to close this gap—either through legacy tool evolution or replacement with agentic-native solutions. For now, the vast majority operate with inherited infrastructure designed for a pre-agent era.