JumpCloud warns on ungoverned AI agents

JumpCloud warns on ungoverned AI agents

AI agents are scaling faster than governance controls, report says. JumpCloud’s latest research finds critical workflows increasingly rely on agents without matching oversight, accountability, or access controls.


The report said AI agents are already being used in areas such as financial reporting and HR provisioning, where decisions, access rights, and execution controls carry higher operational stakes. Among the findings, 66% of organisations said AI agents have equal or greater system access than human employees, while 38% said agents in business-critical environments receive significantly more access than their human counterparts.

Human-in-the-loop approvals fall from 48% in testing to 29% in key business deployments, while 24% of organisations said agents are allowed to execute high-risk actions with no human supervision at all. The report also points to what it calls an identity explosion: 53% of organisations now manage more non-human identities than human employees, and 23% report a ratio of six to one or higher. JumpCloud said the volume of machine identities is making manual management increasingly unrealistic.

Joel Rennich, senior vice president, product management, JumpCloud, said: “AI agent deployment has officially outrun the controls needed to manage it safely. We are seeing agents operate in sensitive workflows with fragmented identities and more access than human employees, yet they are the least supervised group in the enterprise. Because identity is now the only perimeter left for these agents, organisations must move towards a formal governance model that treats every agent as a first-class, governed identity to turn AI from a liability into a sustainable engine for growth.”

Only 17% of organisations said they have a designated security leader accountable for AI agent actions, while 51% said responsibility in business-critical deployments falls to IT teams alone. More than half, 55%, also said they lack a centralised kill switch to cut AI agent access across all systems.

JumpCloud has made the report available here.



  • Chilli relaunches with refreshed brand identity

    Chilli relaunches with refreshed brand identity

    Chilli has relaunched with a sharper visual identity and website. The Leeds agency says its in-house refresh updates how it presents FMCG client work across digital and print.


  • Brits swap screens for summer experiences

    Brits swap screens for summer experiences

    Britons are trading screens for shared summer experiences this year. Mastercard says spending is moving towards travel, food, and live events as consumers cut back on gadgets, streaming, and other purchases to spend more time offline.


  • Internal comms struggle to prove impact

    Internal comms struggle to prove impact

    Internal comms teams still struggle to prove commercial impact clearly. Oak Engage found strong respect for the function, but weak measurement, heavy information overload, and widespread use of unofficial channels across organisations.