Enterprise AI Access Is Outpacing Control
Why accountable AI relies on identity, permissions, and evidence.
-
Your organization probably believes it can audit AI activity. But could it actually prove what an AI tool or agent accessed, changed, or shared, and who authorized it?
JumpCloud surveyed 250 IT decision-makers in the United States and United Kingdom, evenly split between Google Workspace and Microsoft 365-primary organizations, to find out how prepared IT teams actually are to answer that question.
Nearly every respondent (99%) is confident in their ability to audit AI activity, yet only 37% are fully prepared with the records, logs, and evidence an audit would require. That disconnect is becoming more consequential as AI moves from assisting users to acting on their behalf.
More than half of organizations (55%) use or test agents that can change systems, permissions, records, or workflows, while 34% report AI access to IAM systems. When AI can act inside systems that control access and other critical business processes, IT needs a reliable record of what happened, what permissions were used, and who was accountable.
Organizations are not equally prepared to provide that proof. 21% of Microsoft 365-primary organizations show low preparedness for auditing AI, nearly double the rate for Google Workspace-primary organizations (11%).
As AI becomes more embedded in everyday operations, effective oversight depends on connecting access, action, identity, and policy so IT can reconstruct what happened and determine whether it should have happened.
Key Takeaways
-
Most Organizations Can’t Fully Prove What AI Has Accessed
72% report a moderate-to-large gap between what AI is permitted to access and what they can prove it accessed.
-
Most AI Agents Aren’t Fully Integrated Into IAM
Among organizations using agents, 59% have not fully integrated them into the IAM policies used for human users.
-
Google Workspace Organizations Show Stronger Auditability Readiness
Microsoft 365-primary organizations are nearly twice as likely to rank in the lowest tier for AI auditability, at 21% compared with 11% of Google Workspace-primary organizations.
-
The Productivity Suite No Longer Describes the Full AI Environment
Organizations use an average of 2.7 AI tools across 3 types of company systems or data, making AI activity harder to track in one place.
Most IT leaders believe they can audit AI activity. But doing so requires knowing what AI was allowed to access, what it actually did, which identity was behind the action, and which policies were applied. Most organizations cannot connect all of those pieces.
Even among IT leaders who are very confident in their ability to audit AI, 89% show at least two weaknesses across evidence, permissions, governance, or audit readiness.
One of the clearest problems is the difference between permitted access and provable activity. 72% report a moderate-to-large gap between what AI is permitted to access and what they can prove it accessed. Only 4% report no meaningful gap. That gap carries through to audit readiness: just 37% are fully prepared with the records, logs, and evidence an AI-related audit would require.
Proving what AI actually did is even harder. Fewer than half of organizations can fully document any of the AI activities measured, and only 34% can fully prove how AI interacted with sensitive data.
What Stronger AI Auditability Looks Like
To assess how prepared organizations are to audit AI in practice, JumpCloud developed the AI Auditability Maturity Model. The model considers evidence, permission controls, governance, security layers, and audit readiness.
The model groups organizations into three levels of audit maturity:
-
Low (16% of respondents)
These organizations have less complete evidence, less consistent permission controls, and tend to review access reactively. They are also less prepared for an audit.
-
Moderate (64% of respondents)
These organizations have evidence and governance controls in place, but gaps remain. Proof, permissions, security layers, or audit preparedness are inconsistent enough that problems surface under audit or after an incident.
-
High (20% of respondents)
These organizations can produce stronger evidence, scope and review permissions clearly, and apply governance and security layers consistently. They are prepared to reconstruct AI activity when asked.
Four in five organizations remain below high maturity. Most have some of the pieces needed for AI auditability, but have not yet connected them consistently.
Strong AI auditability depends on evidence, permission controls, governance, security layers, and audit readiness working together. Google Workspace-primary organizations are more likely to have at least some of those pieces in place.
Only 11% of Google Workspace-primary organizations fall into the lowest auditability tier, compared with 21% of Microsoft 365-primary organizations.
AI Access Has Outgrown the Audit Trail
Organizations are managing AI across more tools and more of the IT environment. They use an average of 2.7 AI tools, with Microsoft Copilot and ChatGPT among the most widely used or tested at 40% each, and Gemini at 29%. More than one in three organizations are already using developer and coding agents, adding to the mix of vendors and applications IT teams need to govern.
AI access is also extending deeper into the business. Organizations report AI has access to an average of 3 types of company systems or data, including ITSM, CRM, financial systems, endpoint management, and identity and access management.
One-third of organizations (34%) report AI access to IAM systems. Because those systems control how access is assigned, enforced, and revoked, IT needs to know which human or non-human identity is behind an AI action and whether that access was appropriate. That challenge is particularly important for agents: among organizations using them, 59% have not fully integrated agents into the IAM policies used for human users.
Google Workspace-primary organizations show broader AI reach into some business systems.
AI has access to financial, billing, or procurement systems at 42% of Google Workspace-primary organizations, compared with 30% of Microsoft 365-primary organizations. For documents, files, or shared drives, the figures are 38% and 26%, respectively.
That broader reach strengthens the need for governance. As AI activity extends beyond the primary productivity suite, so does the audit trail. The evidence IT needs to reconstruct activity may be spread across native controls, third-party applications, connected systems, identities, and permissions, making it harder to maintain consistent visibility and control across the tools and systems where AI operates.
AI Access Is Changing Faster Than IT Can Review It
As AI connects to more systems, permission management becomes a moving target. IT teams need to know what AI can access, whether that access is still appropriate, and how permissions have changed over time. For many organizations, the review process is struggling to keep up.
AI Permissions Are Already Difficult to Review
Only 12% of organizations describe their AI permissions as tightly scoped and easy to review. Nearly half say permissions are broad, difficult to review, or inconsistent. The challenge is not just how permissions are configured, but how often anyone checks them. Only 14% of organizations review AI permissions continuously or automatically. Yet access can change between reviews as new integrations are added, systems are connected, and agent permissions evolve.
The two problems often go together. Among organizations with weaker or reactive review practices, 61% also report broad or inconsistent permissions. That leaves IT trying to manage changing AI access without a consistently current view of who or what can reach which systems.
Governance Controls Have More Catching Up to Do
Permission reviews are only one part of the challenge. Organizations have implemented an average of just 3 AI governance and security controls, and no individual control has reached majority adoption. Only 29% have a formal AI usage policy, while 26% govern non-human identities such as bots, service accounts, API keys, or AI agents.
As AI gains more access and autonomy, IT teams need controls that make it easier to review permissions, investigate activity, and respond when something goes wrong.
-
Regional Snapshot: Controls for Acting on AI Risk
In the U.S., centralized revoke or rollback (48%), approval workflows for high-risk actions (42%), and non-human identity governance (31%) are among the more widely adopted controls.
In the U.K., shadow AI monitoring (45%) and formal AI usage policies (32%) stand out.
The findings point to two sides of AI risk management: controls that help IT act on risk, and policies and monitoring that help identify it.
What Happens When IT Can’t Prove What AI Did?
The consequences of incomplete audit trails become clear when something goes wrong. 92% of organizations report at least one AI-related incident or exposure in the past 12 months, and 36% have investigated a concern without being able to determine what AI accessed.
For IT teams, that turns an auditability problem into an operational one. If evidence is spread across identities, permissions, tools, and systems, reconstructing an incident takes more time and may still leave basic questions unanswered: What did AI access? What did it do? And was that activity authorized?
AI Incidents Look Different Across Productivity Environments
The incident patterns vary between productivity environments, with permissions, data leakage, unauthorized access, and other exposures appearing at different rates across the two, reinforcing that AI risk does not take a single form.
Regardless of productivity suite, IT teams need the identity, access, and evidence controls to understand what AI can access, identify when activity moves outside intended boundaries, and reconstruct what happened when it does.
-
Regional Snapshot: AI-Related Exposure in the U.K.
U.K. organizations report higher exposure across several AI-related incidents than the U.S. sample, with three affecting more than four in ten organizations:
- Data leakage into an AI tool or workflow: 41%
- Confirmed breach or exfiltration: 44%
- Permissions broader than intended: 46%
JumpCloud’s earlier research found IT teams focused on gaining visibility into AI use and controlling unsanctioned activity.1 Six months ago, 60% said AI was outpacing security defenses, while 61% reported unsanctioned AI use.2 Uncertainty about AI readiness was also growing, with the share describing their organizations as AI mature falling from 40% six months ago to 23% three months ago.3
Those challenges haven’t disappeared. Now IT teams also need to prove what happened after AI activity occurs.
Agents Turn an Evidence Problem Into an Action Problem
AI agents raise the stakes because they can do more than access information. They can change systems, permissions, records, and workflows. More than half of organizations (55%) use or test agents capable of taking these kinds of actions.
When an agent acts, IT needs to know which identity initiated the action, what permissions the agent had, and who was accountable for it. Without those connections, an incomplete audit trail becomes an access and accountability problem.
Most Agents Aren’t Fully Integrated Into IAM
Among organizations using agents, only 41% fully integrate them into the same IAM policies used for human users. That leaves 59% of organizations partially integrating or managing agents through separate policies or tools.
Full integration stands at 45% among Google Workspace-primary agent users and 36% among Microsoft 365-primary agent users.
For IT teams, that distinction matters. When agents sit outside established IAM policies, it becomes harder to connect their access and actions to an accountable owner, team, or business process.
Agent use is already associated with access to sensitive parts of the IT environment. Among Google Workspace-primary organizations, 45% of those using developer agents report AI access to code or production systems, compared with 16% of those not using developer agents. Among Microsoft 365-primary organizations, 40% of those using custom agents report this access, compared with 21% of those not using custom agents.
Agents Often Act Before a Human Reviews Them
For high-risk agent actions, 46% allow the action to happen automatically and log it for later review, while only 18% require human approval beforehand.
That puts more pressure on the audit trail. Only 38% can fully identify the identity that authorized an AI action, and 36% can fully prove AI had only the permissions it needed. When review happens after the action, IT needs reliable evidence to reconstruct what happened and determine whether the action was appropriate.
-
46% Allow High-Risk Agent Actions Before Human Review
Nearly half of organizations allow high-risk actions to happen automatically and rely on logs for review afterward. Only 18% require human approval before the action is completed.
Agent Identity Governance Is Still Catching Up
JumpCloud’s AI Agent Identity Risk Index looks at four aspects of agent governance: non-human identities, high-risk actions, IAM integration, and authentication.
Three in four agent environments fall into the moderate- or higher-risk tiers. Only 26% fall into the lower-risk tier.
For most organizations, agent adoption is moving faster than consistent identity and access governance.
Authentication Is Improving, but Inconsistently
Organizations are adopting stronger authentication methods for AI agents, but their use is not yet consistent. Only 37% of agent environments rely exclusively on stronger methods, while 63% also use higher-risk approaches such as shared service accounts or long-lived API keys. That inconsistency can make it harder for IT to reliably attribute agent actions to the right identity.
-
Regional Snapshot: Agent Controls Vary Across the U.S. and U.K.
U.S. organizations report greater adoption of several controls that govern agents before they act, including human approval for high-risk actions (23% vs. 14%), full integration into human IAM policies (45% vs. 38%), and exclusive use of stronger authentication methods (42% vs. 33%).
In the U.K., 35% allow high-risk agent actions with limited or no review, compared with 23% in the U.S., while 8% rely exclusively on higher-risk authentication methods, compared with 3% in the U.S.
Provable Control Has to Extend Across the AI Environment
AI activity already extends beyond the primary productivity suite. Auditing it requires identity, access, and evidence controls that extend across the tools, agents, identities, and systems where AI operates.
If their productivity suite could not reliably audit AI activity, 55% of organizations would keep the platform and strengthen controls around it, while 45% would reassess the suite or consider migrating.
The approaches differ by productivity environment. Google Workspace-primary organizations lean more toward adding an identity or security layer, while Microsoft 365-primary organizations more often favor tightening permissions within the existing platform (35% vs. 21% among Google Workspace-primary organizations).
-
30% of Google Workspace-primary organizations would add an identity or security layer, compared with 24% of Microsoft 365-primary organizations.
For IT teams managing AI across multiple tools and systems, identity and security controls need to extend beyond the productivity suite. A layer that spans human and non-human identities, agent permissions, connected systems, and activity records can help IT apply controls consistently and preserve the evidence needed to reconstruct AI actions.
JumpCloud’s Agentic IAM lifecycle gives IT teams a practical framework for managing agents from discovery through ongoing governance.
JumpCloud’s Agentic IAM Lifecycle
-
Discover: 30% report shadow AI that IT could not fully monitor.
Identify every AI agent in use and maintain an inventory across devices, browsers, and on-prem environments.
-
Register: 59% of organizations using agents haven’t fully integrated them into IAM policies used for human users.
Create a formal identity record for each agent, including its purpose, intended scope, and an accountable human owner.
-
Manage: 49% report AI permissions that are broad, difficult to review, or inconsistent.
Provision and right-size access, set entitlements, and use controls such as time-bound permissions so agents have only the access they need.
-
Govern: Only 14% review AI permissions continuously or automatically, and 18% require prior human approval for high-risk agent actions.
Continuously audit activity, keep entitlements current, and use human-in-the-loop checkpoints for high-impact actions.
Provable Control Makes AI Accountable
Organizations are better positioned to expand AI when they can identify AI actors, constrain their access, reconstruct their actions, and revoke access quickly.
That control has to work across productivity platforms, third-party tools, developer agents, internally built systems, and the identities connecting them. When identity, access, activity records, and ongoing review work together, IT gains a defensible record of AI activity and a stronger foundation for responsible expansion.
When an auditor, regulator, customer, or security team asks what happened, the organization can answer with evidence.
Methodology
This report is based on a survey of 250 IT decision-makers at organizations with 200–2,500 employees in the United States and United Kingdom. Respondents included IT managers and team leads, directors of IT or technology, VPs of IT or technology, CIOs, CTOs, and CISOs, with a minimum 20% quota for VP and C-suite respondents. The study was fielded July 8–20, 2026, at a 95% confidence level with a ±6.1% margin of error.
The sample was evenly split between the U.S. and U.K. and between organizations that primarily use Google Workspace and Microsoft 365. All respondents were currently using or testing embedded AI assistants, AI agents that can take action, or both.
Key Demographics
-
Geography:
-
- United States: 50% (125)
- United Kingdom: 50% (125)
-
-
Company size:
-
- 200–499 employees: 24%
- 500–999: 50%
- 1,000–2,500: 26%
-
-
Primary productivity suite:
-
- Google Workspace-primary: 50% (125)
- Microsoft 365-primary: 50% (125)
-
-
Current AI use:
-
- AI assistants only: 45%
- AI agents: 42%
- Both: 12%
-
-
Agent-user base:
-
- Findings on high-risk action handling, IAM integration, and authentication are based only on organizations using or testing AI agents (137).
-
Sources
- 1 JumpCloud, Why a Unified Platform Is the Only Path to Controlling Complexity, Q3 2025 IT Trends Report, 2025.
- 2 JumpCloud, The Dual Disconnect: Why Your AI Maturity Now Fails To Scale, Q1 2026 IT Trends Report, 2026.
- 3 JumpCloud, AI Agents Are Entering Critical Workflows. Who’s Governing Them?, Q3 2026 IT Trends Report, 2026.
About JumpCloud®
JumpCloud® is the AI-powered identity infrastructure that unifies lifecycle management for humans, devices, and autonomous agents. JumpCloud gives IT teams complete visibility and control over every identity and every access point. JumpCloud helps organizations cut complexity, automate secure workflows, and put AI to work safely. Secure every identity. Human or not. Intelligent, secure IT for the agentic era.
About Google Workspace
Google Workspace is a suite of productivity apps, including Gmail, Drive, Calendar, Docs, Meet, Vids, and more, that are trusted by over 11 million paying customers. Google Workspace helps people and teams do their best work across any device, from anywhere. AI has been used in Google Workspace for years to improve grammar, efficiency, security, and more with features like Smart Reply, Smart Compose, and malware and phishing protection in Gmail. Now, Google Workspace with Gemini brings AI into the entire suite.