Subscribe to Our Newsletter

Success! Now Check Your Email

To complete Subscribe, click the confirmation link in your inbox. If it doesn’t arrive within 3 minutes, check your spam folder.

Ok, Thanks

Microsoft warns enterprises to treat AI agents like employees in new security report

The company said 29% of workers have turned to unsanctioned AI agents, raising governance and security concerns

Defused News Writer profile image
by Defused News Writer
Microsoft warns enterprises to treat AI agents like employees in new security report
Photo by Alex Knight / Unsplash

Microsoft has published a Cyber Pulse report urging enterprises to apply the same security standards to AI agents as they do to employees and service accounts.

The report found that more than 80% of Fortune 500 companies use active AI agents built with low-code or no-code tools, and that 29% of employees have adopted unsanctioned AI agents for work tasks.

Microsoft said agents now appear across sales, finance, security, customer service and product teams.

The report argues that longstanding Zero Trust security principles, an approach that assumes no user or system should be trusted by default, must be extended to AI agents, with emphasis on least privilege access, explicit verification and designing systems on the assumption that compromise can occur.

Cyber Pulse outlines five core capabilities that Microsoft considers essential for agent observability and governance: a centralised registry of all agents, identity and policy-driven access control, real-time visualisation and telemetry, interoperability across platforms and frameworks, and built-in security protections.

"AI becomes more than a breakthrough in technology; it becomes a breakthrough in human ambition," wrote Vasu Jakkal, corporate vice president of Microsoft Security.

The report's industry and regional metrics on agent usage are drawn from Microsoft's own first-party telemetry, measuring agents built with Microsoft Copilot Studio or Microsoft Agent Builder that were active during the last 28 days of November 2025.

The Recap

  • Microsoft published Cyber Pulse on AI agent governance.
  • More than 80% of Fortune 500 use active agents.
  • Report based on Microsoft telemetry from November 2025.
Defused News Writer profile image
by Defused News Writer

Read More