three in ten agentic ai pilots have been paused or killed. the accounts those pilots were given are mostly still open, still credentialed, still able to act.
new survey work out of 202 enterprise technology and security leaders puts 65% of them in a position where an ai agent has already acted outside its intended scope, 29% with measurable impact, and 47% without a reliable inventory of the agents running in production. the condition is that agents get provisioned like software and retired like meetings: somebody grants a service account and production access to get the pilot moving, then the pilot stalls, and nobody owns the revocation because nobody owned the grant. the cost is a standing credential attached to a project that no longer has a budget, a sponsor or a person watching it, which is the exact profile of the access an attacker wants, and 46% of these organizations could not produce a complete audit trail of one agent's activity over the last thirty days if you asked them today.
the fake fix is an ai governance policy, and the researcher's own line on that is worth keeping: most organizations have policies and real confidence in them, the gap is between what is written down and what is enforced. do the boring version this week: list every agent by name with the credential it holds and the person accountable for it, kill the credentials on anything paused or discontinued, and make decommissioning a named step in the pilot plan rather than an afterthought. 94% of them were confident their agents did not have more access than they needed, and 32.7% had actually provisioned least privilege, so treat your own confidence as untested until you have run the list.