A Cloud Security Alliance survey found 58% of executives suffered an AI-agent security incident in the past year, while only 34% apply the same controls to agents as to human staff.
Why It Matters
92% of executives report AI agents already running somewhere in their organization, yet only 34% apply the same access controls to an agent as they would a new hire. For an SMB running Copilot agents inside Microsoft 365, that gap is exactly where an over-permissioned agent turns a helpful automation into a data leak.
What To Do About It
Before you turn on another Copilot agent or Power Automate flow with delegated access, run the same checklist you'd use for a new employee: what can it see, what can it do, and who reviews it monthly. Start with your highest-privilege agent first, not the newest one.
Related Signals
A WatchGuard survey of 684 SMB employees across the US, UK, Germany, France and Spain found 64% use unauthorized AI tools at work, and fewer than 3 in 10 employers can accurately track what software staff actually run.
30 Jul 2026Microsoft cut AI agent security out of standard Defender licenses on 1 July.
30 Jul 2026CoreView's July 2026 governance report finds two-thirds of organizations have delayed or cancelled Microsoft Copilot rollouts over fear it will surface overshared SharePoint files.
29 Jul 2026