AvePoint’s third annual State of AI report, conducted with Osterman Research across 750 people responsible for information management, data security or AI programmes, contains one finding that makes the other six worth reading.
More than four in five organisations say they are confident in their ability to prevent unauthorised data access. Among those reporting the highest confidence, 62% experienced an AI-related unauthorised access incident in the past year. Among those describing themselves as “very confident”, it rises to 72%.
The report calls this the Confidence-Incident Paradox. We would put it less gently: confidence is being measured against the wrong question.
Confidence in what, exactly
Ask a security team whether they can prevent unauthorised access and they will think about the controls they own. Can someone sign in who should not? No. Can someone query a warehouse table they have no grant on? No. Can a file leave the boundary without DLP seeing it? No.
Every one of those answers is correct, and every one is about a single system.
Now ask the question an agent actually poses: for one person, across every system at once, what could be assembled and returned? Nobody has an instrument for that, so it does not get asked — and confidence stays high, because it was measured on the questions that could be answered.
That is not complacency. It is a measurement problem, and the incident rate is what it looks like from the outside.
The agent numbers are worse than the AI numbers
88.4% of organisations experienced at least one security breach caused by AI agents in the past twelve months. Not an AI incident in general. Agents specifically.
The breakdown matters more than the total:
- 50.1% — sensitive or confidential data improperly exposed or retained by agents
- 49.6% — agents manipulated by malicious or untrusted inputs
- 34.1% — agents performing unauthorised actions
- 30.1% — unauthorised or shadow AI identities created or misused
- 7.1% — insufficient logging of agent actions hindered the investigation
That last one deserves more attention than its size suggests. Only 7.1% reported logging as a problem — which reads like good news until you consider what gets logged. Every system in the chain records the call it answered. What none of them records is the assembled answer. An investigation that never asks the cross-system question will not report a cross-system logging gap.
Visibility is going backwards
Up to one in five organisations do not know whether their employees are using unsanctioned AI tools — a figure the report says has nearly tripled since 2025 for generative AI, and is higher for agents.
Set that beside adoption: nearly half of employees already use AI agents weekly or daily, and 35.5% of enterprise data is now AI-generated, projected to reach 42.1% within a year.
Adoption is compounding while visibility is degrading. The report’s own framing is that this is a control problem rather than a model problem, and on the evidence it presents that is hard to argue with.
What the delays are really about
Nearly nine in ten organisations delayed both agentic and generative AI deployments, by an average of almost six months, driven primarily by unresolved data security and data management concerns.
We read that as the most expensive line in the report, and it is not a cost anyone has invoiced. Six months of a programme the business is demanding, held in review because security cannot approve what they have no way to assess.
Everyone in that room is behaving correctly. Security is not being obstructive — they are being asked to sign off on an exposure surface nobody can describe. The programme owner is not being reckless — the business case is real. The delay is what happens when a decision needs evidence that does not exist.
And a delay only holds until somebody helpful builds their own. That is where the shadow AI number comes from.
Where the money is going next
The report’s seventh finding is that third-party governance tools which monitor agent actions for policy alignment top the planned investment list for the coming year.
We would gently push back on the framing, while agreeing with the direction. Monitoring agent actions produces a description of what happened. It does not change what comes back. The organisations in the 62% were not short of monitoring — they were short of a decision point.
The useful version of that investment is authorization: a verdict computed per call, against the person the agent is acting for, before the answer is assembled rather than after it has been returned.
The caveat
This is vendor-sponsored research. AvePoint commissioned it, Osterman Research conducted it, and AvePoint sells governance tooling — so finding number seven, that the market is about to invest in governance tooling, deserves the scepticism any such finding does.
The methodology is stated plainly, the sample is a reasonable size for the claims, and the numbers that matter here — the incident rates and the confidence gap — are not the ones a sponsor would have chosen to lead with. They make the market look unprepared rather than well-served.
The question it leaves you with
If your organisation is in the four in five who are confident, it is worth asking what that confidence was measured against.
For each agent running in your environment, on behalf of each person it acts for: what could it return, from every system at once? If that question has no owner and no instrument, the confidence is real and it is answering something else.