How AI agents are wrecking havoc in legacy security setups and enterprises are catching up
80% of Fortune 500 companies have unleashed AI agents into live environments. Unfortunately, only 14 percent have received full security approval, according to Mimecast at RSAC 2026.
That gap is not a compliance footnote; it is the defining security condition of the enterprise right now.
Those agents are in production, touching sensitive data, operating with persistent credentials, making autonomous decisions, and in the vast majority of cases, the security model governing them was designed for a world where only humans asked questions.
That mismatch is a problem.
Role-based security was built for humans. But AI agents aren't human
Traditional access control uses “role”: a user is in a group, the group has a permission, and the permission is reviewed once a year. That model worked reasonably well when the identities in question were people operating within predictable workflows.
But, AI agents break every one of those assumptions. They run...
Copyright of this story solely belongs to techradar.com. To see the full text click HERE