73% of companies can't restrict what their AI agents do — and that's a budget problem too

Kiteworks' Data Security and Compliance Risk 2026 Annual Survey Report, surveying 459 security and compliance leaders in July 2026, found 73% of organizations have no purpose binding deployed on their AI agents. Among those running agents in production, 13% reported one exceeding its authorized scope in the past year. An agent with no defined scope doesn't just create a security exposure — it creates an API bill with no ceiling.

What purpose binding actually means

Purpose binding is the constraint that says: this agent exists to do this task, using these tools, within these limits — and nothing else. Without it, an agent authorized for one workflow can call any tool it has credentials for, chain actions across systems it was never explicitly scoped to touch, and keep going as long as it judges the task incomplete. 73% of organizations have deployed agents with no such constraint in place.

Scope creep is a cost mechanism, not just a security one

Among organizations running AI agents in production, Kiteworks found 13% reported an agent exceeding its authorized scope within the past 12 months, and 19% discovered shadow AI usage as a distinct incident type. Every one of those incidents is also a spend event: an agent operating outside its intended boundary is, by definition, making calls nobody planned to pay for. A support agent that starts querying systems outside its assigned domain isn't just a compliance finding — it's tokens and tool calls accumulating against a budget that was sized for the narrower, intended job.

A different failure mode than the other two agent problems

This isn't the same gap as an orphaned agent identity nobody remembers creating, and it isn't a personal account bypassing IT. It's an agent everyone knows exists, doing more than it was supposed to — the scope was never defined tightly enough to catch the difference between "working as intended" and "quietly expanding." That distinction matters for the fix: an inventory of identities won't catch scope creep, and blocking unsanctioned tools won't catch an agent misusing the tools it's already authorized to use.

Security is already treating this as its job

A separate SANS Institute survey of 536 cybersecurity and IT practitioners, also fielded in July 2026, found 76% of security teams now hold formal governance roles for enterprise AI, up from 68% a year prior. Security ownership of AI governance is growing — but purpose binding, the specific control that would catch scope creep before it becomes either an incident or a cost overrun, still isn't deployed at nearly three-quarters of organizations that have that ownership in place.

What to check before your next agent deployment

The bottom line

Purpose binding is framed as a security control, and it is one — but the same gap that lets an agent exceed its authorized scope also lets it exceed its authorized budget, because those are the same event viewed from two departments. At 73% of organizations, that gap is still open. The fix isn't a different tool from the one security already needs; it's recognizing that scope and spend are the same boundary.

Catch scope creep as a cost anomaly, the moment it starts spending.

AIntOps connects to OpenAI, Anthropic, and Gemini in under a minute and flags unusual spend patterns per agent and per feature — so an agent operating outside its intended scope shows up as an anomaly alert, not a line item discovered three weeks later. Join the beta and get Pro free for 3 months.

Try AIntOps Free →

No credit card required · Setup in 30 seconds · Free up to $500/mo AI spend