NewsTradingSentimentCalendarCommunityBriefing
Tech

Employee AI Agents Lack Proper Data Guardrails

By Tech Desk · 2026-09-16 · 2 min read
A digital shield protecting a cluster of glowing data nodes
Illustration: Tradingbird

A new survey reveals that nearly half of all employee-created AI agents have access to sensitive human resources data, exposing companies to significant security and privacy risks.

A comprehensive new report highlights a growing vulnerability in corporate AI adoption: employee-built agents frequently have unrestricted access to sensitive company information. The findings indicate that while organizations encourage staff to use these tools for productivity, the necessary security controls are often missing or insufficient to protect critical data.

The research, conducted by Clutch, surveyed over 1,100 full-time workers to understand how AI agents are being deployed in the workplace. The results show a significant gap between the intent of using AI for efficiency and the reality of data security, with many employees unaware of the full scope of information their agents can reach.

Extensive Access to Sensitive Records

According to the data, 64% of respondents have attempted to build their own AI agent, with 95% reporting success. Of those who successfully deployed an agent, 91% confirmed that the tool had access to some form of company data. The most concerning finding is that 49% of these agents had direct access to employee or human resources information.

Beyond HR records, the agents also had access to other sensitive categories. Specifically, 73% had access to customer or client data, 51% could reach internal documents, and 33% had permissions to view financial records. This broad scope of access creates a complex web of potential data leaks that are difficult to monitor manually.

Unintended Actions and Security Risks

The report warns that granting agents access to business systems allows them to modify or delete records without human oversight. This creates a direct pathway for accidental data disclosure or malicious exploitation. Experts note that if confidential information, credentials, or internal strategies are exposed, companies face immediate incident response challenges, contractual notification obligations, and potential reputational damage.

Furthermore, the technology itself remains prone to errors. 95% of employees reported encountering problems with their AI agents. Nearly half of these users experienced instances where the agent sent an unauthorized email or message. Additionally, 42% reported that the agent deleted or modified data it should not have touched, while 70% cited the generation of inaccurate or misleading information as a primary issue.

Balancing Productivity with Safety

Despite these risks, the adoption of AI agents is driven by clear productivity gains. Eight in ten users reported faster turnaround times, and more than half noted higher output volumes. The tools are primarily used for writing, research, and data processing. However, the report emphasizes that these benefits do not justify the lack of proper safeguards, especially when handling sensitive client and employee data.

Experts suggest a middle ground where agents can draft responses or perform analysis but are blocked from executing consequential actions like sending emails or deleting records. This approach preserves the efficiency benefits while keeping human control over critical functions. The source, GN technics/ai (en-US), notes that governance frameworks do not need to be perfect to start, but they must evolve alongside the tools to prevent unintended consequences.

Based on reporting by hcamag.com, compiled by the Tradingbird desk.

Read next

More in Tech

More from the Tech desk

All desk stories