SecurityNot yet confirmed elsewhere1 publisher2 min readPublished
Most companies using AI agents have not fully folded them into identity management, JumpCloud survey finds
JumpCloud surveyed 250 IT leaders and found 59% of organisations using AI agents have not fully integrated them into identity and access management. For incident responders the harder number is the 36% that investigated an AI-related concern and could not establish what the AI had accessed.
The Watch · Security desk

Bar comparison: 21% of Microsoft 365 users fell into the lowest AI auditability tier, against 11% of Google Workspace users, according to JumpCloud's survey.
Share of users in the lowest AI auditability tier, JumpCloud survey In % of users
| Item | Value | Claim |
|---|---|---|
| Microsoft 365 users | 21 % of users | 2 |
| Google Workspace users | 11 % of users | 2 |
What happened
- Seventy-two percent of respondents reported substantial discrepancies between the permissions their AI systems hold and the access that is actually verified.
- In the survey, 21% of Microsoft 365 users fell into the lowest auditability tier for AI, against 11% of Google Workspace users.
- JumpCloud paired the findings with an Agentic IAM Lifecycle framework built on discovering, registering, managing and governing AI agents.
- Channel Insider presented the gaps as a market for managed service providers selling AI identity management, access enforcement and incident response.
Why it matters
- exposure Agents holding permissions that nobody checks against use are credentials outside the review cycle, so misuse of one would surface late or only during an incident.
- constraint Organisations that cannot reconstruct an AI's access cannot bound an AI-related incident, leaving responders unable to say which data or systems were in reach.
- decision Access reviews written for people and service accounts now need an agent inventory with a named owner for each entry, the ownership step JumpCloud's framework stresses.
Applied to the full sample, the 36% figure is roughly 90 of the 250 organisations [11]. Each looked into an AI-related concern and finished without knowing what the AI had accessed [6]. Incident scoping starts from an access list. Without one, a team cannot say which data an agent read or which systems it could reach at the time.
The 72% finding [5] describes the condition behind those dead-end investigations. In our view an agent whose permissions nobody checks against its use is an unreviewed service account. We think it needs the control already applied to service accounts: an entry in the access review, a named owner, and a log that someone reads.
As reported, the research measures security and governance gaps [3]. The brief describes no attack on an agent, and it does not define the auditability tiers, give field dates, or say how "fully integrated" was judged. We would schedule this with routine access-review work; it does not call for emergency change.
On the platform split [2], 21% against 11% is a ratio of about 1.9 [12]. Without tier definitions, we would read it as a reason for each tenant owner to check what agent activity their audit logs record. We would not read it as a ranking of Microsoft against Google.
JumpCloud measured the gap and introduced the framework meant to close it [7]. Its emphasis on clear ownership, appropriate access controls and continuous auditing [8] is ordinary identity hygiene, in our view, and would be sound advice with or without the survey. The figures come from one vendor's survey, reported by Channel Insider and summarised in an SC World brief [4][9].
We think the first step fits inside the access reviews organisations already run. A review that lists every agent, its owner, its granted permissions and where its activity is logged would answer the question 36% of respondents could not [6].
What to watch
- A disclosed incident in which an attacker abused an AI agent's granted access would turn this governance finding into an exploitation pattern.
- Survey data independent of JumpCloud that reproduces, or fails to reproduce, the 59% and 72% figures.
- Changes by Microsoft or Google to what agent activity their admin audit logs capture.
Clarity's read
What the record supports and how the coverage leans. The claims behind it follow.
Reality
- Evidence35
- Adoption
- Insufficient
- Hype gap+20
- Incentives75
- Confidence40
Claim ledger
Ranked by verification strength, evidence, and original report placement.
- [1]
59% of organizations using AI agents have not fully integrated them into existing identity and access management (IAM) policies.
ReportedSupportedSource: JumpCloud survey2 sources— create a free account to open themView cited source - [2]
21% of Microsoft 365 users fell into the lowest AI auditability tier, compared to 11% of Google Workspace users.
ReportedSupportedSource: JumpCloud survey2 sources— create a free account to open themView cited source - [3]
JumpCloud's research highlights security and governance gaps as enterprises increasingly adopt autonomous AI technologies.
ReportedSupportedSource: SC World brief citing Channel Insider2 sources— create a free account to open themView cited source - [4]
JumpCloud surveyed 250 IT leaders in the U.S. and U.K. about AI agents and identity and access management.
ReportedSupportedSource: JumpCloud research, via Channel Insider coverage summarised by SC WorldView cited source - [5]
72% of respondents report substantial discrepancies between AI system permissions and actual access verification.
- [6]
36% of surveyed organizations investigated AI-related concerns but could not determine what the AI had accessed.
- [7]
JumpCloud introduced an Agentic IAM Lifecycle framework focused on discovering, registering, managing, and governing AI agents.
- [8]
The Agentic IAM Lifecycle framework emphasizes clear ownership, appropriate access controls, and continuous auditing.
- [9]
The JumpCloud findings were reported by Channel Insider and summarised in an SC World brief.
- [10]
Channel Insider presented the gaps as opportunities for MSPs and security partners to offer new services in AI identity management, access enforcement, and incident response.
- [11]
The 36% who could not determine what the AI accessed equals roughly 90 of the 250 surveyed organisations.
- [12]
Microsoft 365 users fell into the lowest auditability tier at about 1.9 times the rate of Google Workspace users.
Sources
1 independent publisher whose own reporting we read for this story.
- scworld.comAI agent integration lags behind adoption, creating security gaps
1 article · October 11, 2026
Topics and entities
Follow any of these and your For You feed starts watching them — no settings page required.
Entities
- JumpCloudFollow
- Channel InsiderFollow
- Agentic IAM LifecycleFollow
- Microsoft 365Follow
- Google WorkspaceFollow