Enterprises are increasingly adopting artificial intelligence (AI) and generative AI (GenAI) across business processes, yet security controls often lag behind this expansion. The gap is particularly consequential with agentic AI—AI agents that can autonomously perform tasks, access data and interact with multiple applications without direct human intervention.
Decision-makers see elevated data-theft risk
Research commissioned by OpenText and conducted by the Ponemon Institute found that 55 percent of respondents believe malicious use of AI agents could moderately or significantly increase the risk of data theft. The study emphasizes the need to clearly define who or what can access data, with what privileges, for what purposes and for how long.
Adoption levels in organisations
According to the Ponemon survey, 38 percent of organisations have partially or fully implemented agentic AI. On average, 23 percent of employees use AI agents that execute tasks without human intervention—examples cited include writing code, replying to e-mails, or running queries.
Non-human identities are changing IAM
Traditional identity and access management (IAM) focused on managing human users’ identities and entitlements. The growth of AI agents introduces a rising number of digital, non-human identities that determine what applications, processes or agents can access and which operations they can perform. Central oversight and governance of these identities falls under IAM.
The Gartner 2026 cybersecurity trend report also highlights that IAM systems must evolve to securely support and manage AI agents.
Awareness vs. capability gaps
A Dark Reading report associated with OpenText notes that 70 percent of leaders rate their IAM capabilities as mature. However, nearly half of organisations cannot yet apply separate rules for managing non-human identities. Key figures from the surveys include:
- 93 percent of organisations apply a separate identity to at least some AI agents.
- Only 27 percent use separate identities for all or most AI agents.
- Continuous entitlement review is uncommon: 13 percent perform ongoing reviews, while 11 percent only re-evaluate access after an incident.
While 82 percent of respondents say they understand the security risks of AI agents, only 53 percent believe their current IAM systems are properly prepared for the expected growth in AI agent usage.
Main concerns for leaders
The Dark Reading report lists leaders’ top concerns:
- Excessive privilege and entitlement creep (51 percent).
- Managing short-lived or rapidly changing identities (49 percent).
- Current tools lacking sufficient control for the new environment (41 percent).
Because AI agents can evolve—connecting to new systems or accessing additional data over time—privileges that are not tightly aligned to actual tasks can lead to over-privileged agents.
Centralised control as a prerequisite for safe scaling
The reports argue that safely deploying AI agents requires a modern IAM infrastructure capable of regulating who or which AI system can use agents, with what privileges, for what purposes and under which conditions. OpenText’s Identity and Access Management portfolio is presented as a solution set that enables lifecycle management of identities and entitlements, regular access reviews, and centralised, risk-based access controls.
Such capabilities help organisations gain visibility into which users or AI systems are using AI agents, what systems those agents access, and when stricter controls or entitlement reviews are warranted.
Conclusion
While AI agents offer significant business potential, they introduce distinct security challenges. Surveys commissioned by OpenText and reported through Ponemon and Dark Reading indicate that a majority of decision-makers are concerned about heightened data-theft risk. Although many organisations have begun assigning non-human identities to AI agents, comprehensive, continuous and rules-based IAM practices are not yet widespread. Modernised IAM solutions and stronger access-review processes will be crucial to realise the benefits of AI agents securely as adoption expands.



