Nearly six in 10 organizations using AI agents have not fully integrated them into existing identity and access management (IAM) policies, according to new research from JumpCloud, exposing security and governance gaps as enterprises expand their use of autonomous AI.
JumpCloud’s Enterprise AI Access Is Outpacing Control report, based on a survey of 250 IT leaders in the U.S. and U.K., found that 59% of organizations using AI agents lack full IAM integration, while 72% report significant gaps between what AI systems are permitted to access and what they can verify those systems actually accessed.
The findings highlight growing challenges for enterprise IT teams tasked with securing AI-driven workflows and suggest emerging opportunities for managed service providers (MSPs) and security partners to help customers manage AI identities, enforce access controls, and maintain accountability.
JumpCloud finds widespread AI agent identity security gaps
As AI agents gain access to sensitive systems, organizations are facing challenges in applying existing identity controls and tracking agent activity. The findings are based on a study of 250 IT leaders across the U.S. and U.K.
“AI agents are quickly becoming another class of identity in the enterprise. They can access sensitive systems, change records, trigger workflows, and act on behalf of people, but many organizations still aren’t governing them with the same rigor they apply to human users,” said Joel Rennich, senior vice president of advanced technologies and innovation at JumpCloud.
“Every agent needs clear ownership, appropriate access, and controls that follow it throughout its lifecycle. As agents become more autonomous, that foundation is what allows organizations to scale AI without losing accountability.”
The study also found differences in AI auditability across workplace software platforms. According to JumpCloud, 11% of organizations that primarily use Google Workspace fall into the lowest auditability tier, compared with 21% of organizations that primarily use Microsoft 365.
AI-related incidents expose auditability challenges
Alongside the findings, JumpCloud detailed an Agentic IAM Lifecycle framework designed to help IT teams discover, register, manage, and govern AI agents alongside human employees.
The framework outlines four stages of AI identity management, each addressing gaps identified in the company’s research:
- Discover: With 30% of respondents reporting shadow AI that IT could not fully monitor, JumpCloud recommends identifying all AI agents in use and maintaining an inventory across devices, browsers, and on-premises environments.
- Register: With 59% of organizations using agents lacking full integration into IAM policies for human users, the framework calls for a formal identity record for each agent, including its purpose, intended scope, and an accountable human owner.
- Manage: Nearly half (49%) of organizations report AI permissions that are broad, difficult to review, or inconsistent. JumpCloud recommends provisioning and right-sizing access, setting entitlements, and using controls such as time-bound permissions.
- Govern: Only 14% of organizations review AI permissions continuously or automatically, while 18% require prior human approval for high-risk agent actions. The framework emphasizes continuous activity auditing, updated entitlements, and human oversight for high-impact actions.
According to JumpCloud, effective AI governance requires organizations to identify AI actors, limit their access, reconstruct their actions, and revoke access quickly.
The company said these controls should extend across productivity platforms, third-party tools, developer agents, and internally built systems, giving IT teams a clearer record of AI activity for security investigations, audits, and compliance reviews.
AI identity governance creates opportunities for MSPs
For MSPs, MSSPs, and other IT solution providers, the findings point to a potential expansion of traditional identity and access management services as customers deploy AI agents across their environments.
The research also highlights a potential role for managed security providers in AI-related incident response and compliance. More than one-third of surveyed organizations (36%) investigated an AI-related concern but could not determine what the AI had accessed, underscoring the importance of audit trails and activity monitoring.
For channel partners already delivering IAM, security monitoring, and compliance services, AI agent governance could become an additional managed service offering. However, providers will need to develop capabilities to manage non-human identities and validate AI access controls as customers move toward more autonomous workflows.
11:11 Systems has acquired select IBM VMware enterprise customers, expanding its global VMware business and creating new partner opportunities around VMware Cloud Foundation services. Read more about the deal and what it means for the evolving VMware service provider ecosystem.



