AI

Companies now run about one AI agent per employee. Six in ten were handed the keys to everything.

Two reports published August 5 put numbers on enterprise agent sprawl. Opsin Labs found that 60% of AI agents provisioned beyond their default settings were granted allow-all access rather than permissions scoped to the task, and that workforce interactions with agents grew 14x between January and June 2026. Snyk, reviewing 3,044 enterprise environments, found the real AI footprint is roughly three times what a model inventory shows. Both firms sell the fix.

N Noah · The Sharp Brief · August 9, 2026 · 4 min read

The interesting number in enterprise AI stopped being how many models a company runs. It is now how many things those models are allowed to do — and who, if anyone, decided.

Two reports landed on August 5 with uncomfortably compatible answers. Opsin Labs published its first State of Agentic Adoption, drawn from enterprise production environments across eight verticals between March 2025 and June 2026. Its headline finding: of the agents that had been provisioned beyond their default settings, 60% were granted allow-all access rather than permissions scoped to the task they were built for. Workforce interactions with agents grew 14x in the first six months of 2026 alone. Opsin puts the current density at roughly one agent — live or sitting in draft — for every employee.

The detail underneath is the one worth sitting with. Opsin found 67% of agents were built by people without an engineering background — go-to-market, customer success, operations. Teams that would never be handed production credentials through any other route are building software that quietly asks for the equivalent.

Snyk’s 2026 State of Agentic AI Adoption, published the same day, comes at it from the inventory side. Across 3,044 enterprise environments and 1.39 million code repositories, it found 46.9% of organisations using AI have adopted agentic architectures — agents, Model Context Protocol servers, or both — a share that has nearly doubled since Snyk’s January report. Count the whole system rather than the models and the AI footprint is about three times larger than a model-only list suggests, because the agent frameworks, MCP servers, retrieval layers, vector stores and datasets never made anybody’s spreadsheet. Most security programmes, on Snyk’s reading, see roughly a third of what their organisation actually runs.

Our take: Read both reports with the label showing — Opsin and Snyk each sell products that solve the problem they just measured, and vendor research reliably finds a crisis shaped like its own roadmap. But the two datasets are independent, they were built with different methods, and they converge. And the convergence points somewhere less dramatic than a security story: this is an ownership story. An agent built by a customer success manager in an afternoon has no on-call rotation, no deprecation date, and no name attached to it. It does not get reviewed, because reviewing it is nobody’s job. The permissions are over-broad for the same boring reason most permissions are over-broad — scoping them takes twenty minutes and allow-all takes none.

The direction of travel was already priced in. Gartner projected that 40% of enterprise applications would ship with task-specific AI agents by the end of 2026, up from under 5% in 2025 — meaning much of the agent estate now arrives inside software bought for other reasons, and never gets provisioned by anyone at all. That compounds the visibility problem: see the 143,000 vulnerabilities found across 25,000 MCP servers, and the point at which most of Cloudflare’s traffic stopped being human.

What is new is that the cost side and the control side arrived in the same fortnight. Microsoft putting a meter on its own engineers and Opsin counting allow-all agents are one governance reflex reaching two departments. Finance found the token bill first. Security is finding the permissions now.

What to watch

None of this argues for fewer agents. It argues that the provisioning discipline every company already applies to human access has not been extended to the software those humans now build in an afternoon — and that the gap is measured in multiples, not percentage points.

Advertisement

Get the day, decoded — at 7 PM ET

The Sharp Brief: AI, money, business & performance in five sharp minutes. Free.

Free bonus: subscribe today and The 2026 AI Playbook lands with your welcome email.

Recommended by 5+ newsletters across AI, markets & business.