AvePoint Research Finds AI Visibility Gaps Have Nearly Tripled as Agents Scale
AvePoint has released its third annual State of AI Report, and the findings point to a widening blind spot: organizations now have less visibility into employee AI use than they did a year ago, even as adoption accelerates. The share of organizations unable to determine whether employees are using unsanctioned generative AI tools has nearly tripled, climbing from 6.3% in 2025 to 17.6% in 2026. For AI agents specifically, that blind spot runs even deeper, with 21.1% of organizations unable to account for unsanctioned agent activity.
The study, titled The State of AI 2026: Scaling Trust, Control, and Readiness in the Agentic Era, was conducted with Osterman Research and surveyed 750 enterprise leaders across the Americas, EMEA, and APAC who hold direct responsibility for information management, data security, or AI programs. Its central theme: enterprises are deploying AI agents faster than they are building the trust infrastructure needed to govern them safely.
"The constraint on enterprise AI is no longer model capability, but whether organizations have built a trust layer."
— Dr. Tianyi Jiang (TJ), CEO & Co-Founder, AvePointAgents Are Scaling Faster Than Governance
Nearly half of global employees, 46.9%, now rely on AI agents on a daily or weekly basis, and organizations expect the number of work processes involving agents to double within the next year. Yet that growth is outpacing the ability of security and governance teams to track it: 88.4% of organizations experienced at least one agent-related security incident in the past twelve months, a figure driving renewed investment in third-party governance tools.
The report also highlights a gap between confidence and actual control. More than four in five organizations say they are confident in their ability to prevent unauthorized AI-related data access, yet as many as 72% of those confident organizations still experienced an unauthorized access incident during the same period. Nearly nine in ten organizations delayed both generative and agentic AI deployments, by an average of almost six months, citing data security and governance concerns as the primary cause.
"Trust in AI cannot be measured by confidence alone. It requires operational foundations."
— John Peluso, Chief Technology Officer, AvePointData Growth Is Expanding the Governance Surface
Compounding the visibility problem is the sheer volume of data AI systems now generate. AI-created content already accounts for 35.5% of enterprise data, a figure expected to climb to 42.1% within the next twelve months. AvePoint's Chief Risk, Privacy and Information Security Officer, Dana Simberkoff, noted that accelerating adoption is outpacing organizational readiness, and that visibility into unsanctioned tools continues to weaken even as agentic AI spreads further into daily operations.
Despite the risks uncovered, organizations aren't pulling back from AI investment. Securing the data used for AI training ranked as the top future investment priority, cited by 79.5% of respondents, alongside growing demand for third-party governance tools capable of monitoring agent actions for policy alignment.
Visibility gap nearly tripled. Organizations unable to detect unsanctioned generative AI use rose from 6.3% to 17.6% year over year; for AI agents, the gap is 21.1%.
Agent adoption is accelerating. 46.9% of employees now use AI agents daily or weekly, with agent-driven processes expected to double within a year.
Confidence outpaces competence. 88.4% of organizations suffered an agent-related security incident in the past year, even where confidence in controls was high.
Deployments are slowing down. Nearly 90% of organizations delayed AI rollouts by an average of six months over data security and governance concerns.
AI-generated data is expanding fast. AI-created content already makes up 35.5% of enterprise data and is projected to reach 42.1% within 12 months.
