Six months ago, the AI question top of mind across most IT teams was about visibility. What are people using, is it sanctioned, and how much of it do we not know about?
That question hasn’t gone away. But a harder one has landed on top of it. It’s not about visibility. It’s not simply about control. It’s about proof.
This question is the subject of our new research report, Enterprise AI Access Is Outpacing Control. In it, we surveyed 250 IT decision-makers across the U.S. and U.K., evenly split between Google Workspace and Microsoft 365 organizations. We wanted to know how ready IT teams are to answer an audit question about AI. The TL;DR is that almost everyone believes they’re ready, but only about a third are.
You can get the full picture in the report. But let’s walk through the key points you’ll want to remember if you’re scoping out your team’s AI auditability strategy in the next year.
4 Findings Worth Your Time
Confidence Runs Well Ahead of Readiness
The vast majority of the IT leaders we surveyed said they were confident in their ability to audit AI activity. Only 37% said they were fully prepared.
Prepared means something specific here. It means having the records, logs, and evidence on hand to reconstruct an AI action.
Even the most confident leaders have a gap between their confidence and how prepared they actually are. 89% of respondents who described themselves as very confident still showed at least two weaknesses across evidence, permissions, governance, or audit readiness.
Most Organizations Can’t Fully Prove What AI Accessed
72% of the leaders we surveyed report a moderate-to-large gap between what their AI may access and what they can prove it accessed. Only 4% report no meaningful gap.
This shows up in the specifics. Only 34% can fully prove how AI touched sensitive data. In the past 12 months, 92% reported at least one AI-related incident or exposure. And 36% looked into a concern without ever learning what the AI had accessed.
AI Agents Still Aren’t Fully Governed by the Policies That Cover Employees
More than half of organizations, 55%, use or test agents that can change systems, permissions, records, or workflows. Across the organizations that are running agents, only 41% have fully integrated those agents into the same IAM policies used for human users.
The other 59% manage agents partially, or through separate policies and tools. 63% of agent environments still mix in higher-risk authentication, including shared service accounts and long-lived API keys. This is what can make agent actions hard to trace later.
AI Has Spread Further than the Tools Most Teams Watch
Organizations run an average of 2.7 AI tools that reach across three types of company systems. Not three applications. Three categories, spanning ticketing, customer records, financial systems, endpoint management, and identity. One in three organizations say AI can reach their identity and access management systems, which decide who gets access to everything else.
That spread is why auditability is hard. The evidence sits in several places at once:
- The AI tool’s own console.
- The connected system it reached.
- The directory that holds the identity.
Readiness varies by environment. Google Workspace-primary organizations are less likely to land in the lowest tier of auditability maturity, at 11% against 21% for Microsoft 365-primary organizations. They’re also further along on agent governance.
But there’s still work to do across the board. Only 20% of the organizations we surveyed have reached high maturity.
How We Scored Auditability Maturity
To make the findings comparable, we built an AI Auditability Maturity Model. It weighs evidence, permission controls, governance, security layers, and audit readiness together. A team strong in one and weak in another isn’t mature.
The model sorts organizations into three tiers:
- Low maturity (16% of respondents): Evidence is less complete, permission controls are less consistent, and access reviews tend to happen reactively.
- Moderate maturity (64% of respondents): The controls exist but coverage is uneven, and gaps surface under audit or after an incident.
- High maturity (20% of respondents): Evidence is stronger, permissions are scoped and reviewed clearly, and governance applies consistently across tools.
Four in five organizations remain below high maturity. The shortfall is rarely a missing control. It’s that the controls cover the sanctioned tools and not the connected ones, or the employees and not the agents. It’s that coverage is incomplete.
What Mature Teams Do Differently
The report closes on a framework for IT teams: an agentic IAM lifecycle running from discovery through ongoing governance. This lifecycle lets every AI action be traced back to a moment in time, a clear access scope, and a human who’s responsible.
It’s made up of four key stages:
- Discovering every agent operating in the environment, including the ones no one officially told IT about
- Registering each agent with a purpose, a scope, and an accountable human owner
- Managing access by right-sizing it and letting it expire when the work does
- Governing on a continuous basis, because agents move quickly along with their access needs
The survey results suggest most teams stop after the first stage or two. 30% report shadow AI they could not fully monitor. 49% describe their AI permissions as broad, hard to review, or inconsistent, and only 14% review those permissions continuously or automatically.
Read the Full Report
The findings above are just the tip of the iceberg. The report has the rest: complete evidence data across every AI activity we measured, incident breakdowns by suite, and regional splits between the U.S. and U.K.
If you’re planning how much AI autonomy to grant next quarter, this is the data to make that call against. Get the Q4 Pulse Report.