There is a particular kind of organisational risk that doesn’t show up on a dashboard because nobody built the dashboard. That is precisely the situation many enterprises now find themselves in with AI agents — autonomous systems that browse the web, query databases, execute code, send emails, and call APIs on behalf of users. According to new survey data published via PR Newswire, organisations broadly acknowledge that these systems are causing problems. They are deploying them anyway.
What the Survey Actually Says
The findings paint a picture of accelerating adoption outpacing governance. Enterprises report that AI agents are already breaking workflows, producing unexpected outputs, and accessing data in ways that were not explicitly sanctioned. Yet deployment timelines are not slowing. The pressure to capture productivity gains — faster decision-making, automated customer interactions, streamlined internal operations — is overriding the instinct to pause and instrument these systems properly before scaling.
This is not recklessness in isolation. It reflects a broader dynamic in enterprise AI adoption: the competitive cost of waiting feels higher than the security cost of moving fast. The problem is that this calculus ignores a threat model that is genuinely novel.
Why Agentic Systems Create a Different Kind of Risk
Traditional enterprise software has a relatively legible security surface. You can audit API calls. You can log database queries. You can trace which user account triggered which action. The controls are imperfect, but the architecture assumes human-initiated actions at the root of most consequential operations.
AI agents break that assumption. A single agent, given a goal and a set of tools, may chain together dozens of actions — reading a file, querying a CRM, drafting and sending a message, updating a record — without a human reviewing any intermediate step. The action log exists, technically, but few organisations have built the tooling to parse it meaningfully in real time.
The attack surface this creates is not just technical. It is invisible in the operational sense: security teams often do not know what an agent accessed, what it inferred from that access, or what downstream systems it touched. When the agent is operating on behalf of multiple users or across multiple integrated platforms, the blast radius of a compromise — or even an unintended behaviour — expands dramatically.
The Prompt Injection Problem Is Not Solved
One of the most underappreciated vectors in agentic deployments is prompt injection — the ability for malicious content in the environment to hijack an agent’s instructions. An agent tasked with summarising incoming emails, for instance, could be redirected by a crafted message to exfiltrate data, forward sensitive information, or take actions the user never intended.
Unlike traditional injection attacks, prompt injection does not require access to a code repository or a network vulnerability. It requires only that an attacker can place content somewhere the agent will read. In an enterprise environment where agents are ingesting documents, emails, web pages, and database records, that is an enormous and largely unguarded perimeter.
The security industry has begun naming this problem clearly, but production-grade mitigations remain immature. Sandboxing agent actions, enforcing least-privilege tool access, and implementing semantic monitoring of agent behaviour are all technically feasible — but they require deliberate architectural choices that most rapid deployments are not making.
Monitoring Is the Missing Layer
What distinguishes the current moment from previous waves of enterprise software risk is the absence of a mature observability ecosystem. When organisations deployed cloud infrastructure at scale, a robust tooling market emerged quickly around logging, tracing, and anomaly detection. That market for agentic AI is nascent at best.
Most enterprises deploying agents today are working with one of three inadequate approaches: relying on the logging native to the underlying model provider, building bespoke internal monitoring with limited coverage, or doing nothing systematic at all. None of these provide the kind of real-time behavioural visibility that would allow a security team to detect, for instance, that an agent has begun accessing data stores outside its normal operational scope.
This gap is partly a tooling problem and partly an organisational one. Agentic deployments frequently sit at the intersection of IT, data engineering, and business unit ownership — which means accountability for monitoring is diffuse. When something goes wrong, it is often unclear who owns the incident.
The Canadian Enterprise Context
For Canadian organisations, the stakes carry additional regulatory texture. Enterprises operating under PIPEDA — and those anticipating stronger obligations under proposed federal privacy reform — face specific accountability requirements around automated decision-making and data access. An AI agent that touches personal data as part of its task chain without adequate logging is not just a security risk; it is a potential compliance exposure.
Canadian financial institutions, healthcare organisations, and public sector bodies that are evaluating or piloting agentic systems need to treat monitoring infrastructure as a first-class requirement, not an afterthought. The question is not whether an agent accessed sensitive data — in many deployments, it will. The question is whether the organisation can demonstrate what was accessed, by which process, and under what authorisation.
The Path Forward Is Not Slower Deployment
The survey’s finding that organisations are deploying despite known risks is not, by itself, cause for alarm. Mature risk management has always involved accepting some uncertainty in exchange for strategic advantage. What matters is whether organisations are accepting informed risk with compensating controls, or uninformed risk with no visibility at all.
The practical minimum for responsible agentic deployment includes granular action logging at the tool level, not just the model output level; defined and enforced scope boundaries for each agent’s data and system access; explicit human-in-the-loop checkpoints for high-consequence actions; and regular behavioural audits that compare actual agent activity against intended task parameters.
None of this eliminates the risk. But it makes the attack surface visible — which is the necessary first step before you can defend it.
Related InsightTrack Analysis
- AI Agent Orchestration Frameworks for Workflow Automation
- Agentic AI Benefits and Risks for Canadian Enterprises
- Local AI Deployment in Canada: Business Benefits
Source
AI agents are breaking things and organisations know it. They are deploying more anyway.

