Skip to content

SecurityNot yet confirmed elsewhere1 publisher2 min readPublished

Most companies using AI agents have not fully folded them into identity management, JumpCloud survey finds

JumpCloud surveyed 250 IT leaders and found 59% of organisations using AI agents have not fully integrated them into identity and access management. For incident responders the harder number is the 36% that investigated an AI-related concern and could not establish what the AI had accessed.

The Watch · Security desk

How we use AISend a correction

Illustration accompanying Most companies using AI agents have not fully folded them into identity management, JumpCloud survey finds
Generated illustration
More Microsoft 365 users land in lowest AI audit tier Share of each platform's users that fell into the lowest AI auditability tier in JumpCloud's survey.

Bar comparison: 21% of Microsoft 365 users fell into the lowest AI auditability tier, against 11% of Google Workspace users, according to JumpCloud's survey.

Share of users in the lowest AI auditability tier, JumpCloud survey In % of users

More Microsoft 365 users land in lowest AI audit tier (Share of users in the lowest AI auditability tier, JumpCloud survey)
ItemValueClaim
Microsoft 365 users21 % of users2
Google Workspace users11 % of users2

What happened

  • Seventy-two percent of respondents reported substantial discrepancies between the permissions their AI systems hold and the access that is actually verified.
  • In the survey, 21% of Microsoft 365 users fell into the lowest auditability tier for AI, against 11% of Google Workspace users.
  • JumpCloud paired the findings with an Agentic IAM Lifecycle framework built on discovering, registering, managing and governing AI agents.
  • Channel Insider presented the gaps as a market for managed service providers selling AI identity management, access enforcement and incident response.

Why it matters

  • exposure Agents holding permissions that nobody checks against use are credentials outside the review cycle, so misuse of one would surface late or only during an incident.
  • constraint Organisations that cannot reconstruct an AI's access cannot bound an AI-related incident, leaving responders unable to say which data or systems were in reach.
  • decision Access reviews written for people and service accounts now need an agent inventory with a named owner for each entry, the ownership step JumpCloud's framework stresses.

Applied to the full sample, the 36% figure is roughly 90 of the 250 organisations [11]. Each looked into an AI-related concern and finished without knowing what the AI had accessed [6]. Incident scoping starts from an access list. Without one, a team cannot say which data an agent read or which systems it could reach at the time.

The 72% finding [5] describes the condition behind those dead-end investigations. In our view an agent whose permissions nobody checks against its use is an unreviewed service account. We think it needs the control already applied to service accounts: an entry in the access review, a named owner, and a log that someone reads.

As reported, the research measures security and governance gaps [3]. The brief describes no attack on an agent, and it does not define the auditability tiers, give field dates, or say how "fully integrated" was judged. We would schedule this with routine access-review work; it does not call for emergency change.

On the platform split [2], 21% against 11% is a ratio of about 1.9 [12]. Without tier definitions, we would read it as a reason for each tenant owner to check what agent activity their audit logs record. We would not read it as a ranking of Microsoft against Google.

JumpCloud measured the gap and introduced the framework meant to close it [7]. Its emphasis on clear ownership, appropriate access controls and continuous auditing [8] is ordinary identity hygiene, in our view, and would be sound advice with or without the survey. The figures come from one vendor's survey, reported by Channel Insider and summarised in an SC World brief [4][9].

We think the first step fits inside the access reviews organisations already run. A review that lists every agent, its owner, its granted permissions and where its activity is logged would answer the question 36% of respondents could not [6].

What to watch

  • A disclosed incident in which an attacker abused an AI agent's granted access would turn this governance finding into an exploitation pattern.
  • Survey data independent of JumpCloud that reproduces, or fails to reproduce, the 59% and 72% figures.
  • Changes by Microsoft or Google to what agent activity their admin audit logs capture.

Clarity's read

What the record supports and how the coverage leans. The claims behind it follow.

Reality

Evidence35
Adoption
Insufficient
Hype gap+20
Incentives75
Confidence40
Why these scores

Claim ledger

Ranked by verification strength, evidence, and original report placement.

  1. [1]

    59% of organizations using AI agents have not fully integrated them into existing identity and access management (IAM) policies.

  2. [2]

    21% of Microsoft 365 users fell into the lowest AI auditability tier, compared to 11% of Google Workspace users.

  3. [3]

    JumpCloud's research highlights security and governance gaps as enterprises increasingly adopt autonomous AI technologies.

    ReportedSupportedSource: SC World brief citing Channel Insider2 sources— create a free account to open themView cited source

Sources

1 independent publisher whose own reporting we read for this story.

  1. scworld.com

    1 article · October 11, 2026

    AI agent integration lags behind adoption, creating security gaps

Share your take

Let Clarity write the post for you.

Signed-in readers get a short post drafted on this story in the register they choose — narrative, analytical, or a direct position — editable to the last word before it goes anywhere. The share buttons at the top of this story work without an account.

Topics and entities

Follow any of these and your For You feed starts watching them — no settings page required.

Entities

Loading related stories