Cequence Security report finds 65% of enterprises face agentic AI risks
A report from Cequence Security and Enterprise Management Associates indicates that 65% of enterprises have experienced AI agents operating outside their intended scope. The findings highlight a significant governance gap, noting that 92% of AI-driven traffic targets customer-facing applications and APIs while often lacking least-privilege access controls.
Key Takeaways
- 92% of AI-driven traffic now targets customer-facing applications and APIs, increasing exposure risks.
- Only 32% of organizations can detect and contain out-of-scope agent actions within minutes.
- 31% of AI pilots are abandoned or paused without revoking live system credentials or access.
- 14% of enterprises allow AI agents to connect to external tools via Model Context Protocol without restrictions.
Why It Matters
The disconnect between executive confidence and technical enforcement creates significant vulnerabilities for streaming platforms scaling automated workflows. As 92% of AI traffic hits customer-facing APIs, the lack of real-time authorization checks means agents could inadvertently expose sensitive subscriber data or disrupt delivery pipelines. For the broader ecosystem, the high rate of abandoned pilots with active credentials represents a growing, unmonitored attack surface that traditional security perimeters are not currently catching. Industry observers should monitor whether streaming providers adopt the Model Context Protocol with stricter auditing teams to prevent unauthorized external data connections.
Additional Context
Cequence Security has positioned itself at the intersection of API security and agentic AI governance, a space that is attracting increasing attention from enterprise security teams. In May 2025, Cequence launched its AI Agent Security solution to protect agentic workflows across APIs, targeting the exact class of risks the new report quantifies. The product monitors agent-to-agent and agent-to-API communication patterns, flagging anomalous behavior that falls outside declared intent. That launch came amid a broader wave of API security vendors adding agentic AI capabilities, with Salt Security and Noname Security (now part of Akamai) also expanding their platforms to cover autonomous agent traffic.
The business case for agentic AI governance is being reinforced by regulatory and standards-body activity. The Open Web Application Security Project (OWASP) published its Top 10 for LLM Applications in late 2024, which includes agentic AI risks such as excessive agency and insecure plugin design, giving security teams a shared taxonomy for the governance gaps Cequence identifies. Meanwhile, Gartner predicted that by 2028, at least 15% of day-to-day work decisions will be made autonomously through agentic AI, up from zero in 2024, underscoring the urgency of establishing access controls before deployment scales further. For streaming platforms specifically, the combination of high-volume API traffic and subscriber data sensitivity makes the governance gap a compliance risk as well as a technical one.
On the technical side, independent testing of agentic AI security tooling remains limited, but early benchmarks are emerging. Enterprise Management Associates, the same analyst firm behind the Cequence report, found in a separate 2025 survey that only 28% of organizations had deployed dedicated observability for AI agent behavior, suggesting that the 65% out-of-scope figure likely reflects a measurement and tooling deficit rather than purely malicious activity. The Model Context Protocol, originally developed by Anthropic and now gaining adoption across enterprise AI stacks, has been cited by security researchers as a potential framework for enforcing least-privilege boundaries between agents and external tools, though no streaming-specific implementation has been publicly documented. For Cequence, the challenge is converting awareness of the governance gap into platform adoption before larger security vendors bundle similar capabilities into existing API management suites.
Read full article at sourcesecurity.com
Enjoy our coverage?
Add StreamingMeme as a preferred source on Google to see more of our streaming news at the top of your Search results.
Add as preferred source