AvePoint, the global leader in AI data protection, unifying data security, governance, and resilience, today released its third annual State of AI Report: Scaling Trust, Control, and Readiness in the Agentic Era. The report finds that AI has scaled into everyday work, and organizations have less visibility into what employees are using than they did a year ago. The percentage of organizations unable to determine whether employees are using unsanctioned AI tools has nearly tripled, from 6.3% in 2025 to 17.6% in 2026. For AI agents specifically, that blind spot is higher still, at 21.1%.
AI visibility gaps nearly tripled from 6.3% to 17.6% for generative AI; 21.1% for AI agents.
46.9% of employees use AI agents weekly or daily.
88.4% of organizations experienced at least one agent-related security incident.
86.9% delayed AI deployments by average of nearly six months due to data security concerns.
35.5% of enterprise data is now AI-generated, expected to reach 42.1% within 12 months.
72% of "very confident" organizations still experienced unauthorized access incidents.
46.9% of global employees utilize AI agents on a weekly or daily basis, and work processes that incorporate AI agents are expected to double in the next 12 months. At the same time, organizations anticipate that AI agents will replace more than 25% of human work within 12 months and nearly half within five years. Notably, reducing headcount ranks last among reasons for adopting AI agents, with ROI measured by cost displacement: reducing manual efforts, compressing process times, and reallocating human capacity to higher-value work. However, 21.1% of organizations do not know whether employees are using unsanctioned tools to create AI agents, higher than the 17.6% who lack visibility into unsanctioned generative AI use.
Organizations are misjudging their own exposure to unauthorized AI data access. 82.7% of respondents report being "very" or "extremely" confident in their ability to prevent unauthorized data access, yet 72% of the "very confident" group and 62% of the "extremely confident" group have experienced an AI-related unauthorized access incident in the last 12 months. In 2025, 75.1% of organizations reported at least one generative AI-related security breach. In 2026, that figure rose to 89.5%. For AI agents, 88.4% experienced at least one security breach in the past 12 months.
86.9% of organizations delayed generative AI deployments by an average of nearly six months due to data security and management concerns. For AI agents, the figure is nearly identical at 86%. The governance challenge is compounded by a structural shift in how enterprise data is being created. On average, 35.5% of enterprise data is now generated by AI assistants—expected to reach 42.1% within 12 months. 84.1% of organizations manage at least 1 petabyte of data, up from 79.2% last year.
Dr. Tianyi Jiang (TJ), CEO and Co-Founder of AvePoint, stated: "Nearly half of global employees are already relying on AI agents weekly or daily, and organizations are deploying agents faster than they are building the foundations required to trust them. The constraint on enterprise AI is no longer model capability, but whether organizations have built a trust layer: the data visibility, governance, and enforceable control required to scale AI with confidence. Without it, speed of deployment becomes speed of exposure."
John Peluso, Chief Technology Officer at AvePoint, added: "Trust in AI cannot be measured by confidence alone. It requires operational foundations: visibility into what AI systems are doing, enforceable governance over the data they consume and create, and the ability to audit and correct outcomes when something goes wrong. This is what distinguishes a trust layer from a trust score."
Despite widespread breaches and deployment delays, organizations are making targeted investments. Securing data used for AI training is the top-rated future investment priority (79.5%). Third-party governance tools that monitor agent actions for policy alignment top the planned investment list for the next 12 months. 95.5% of organizations have taken one or more actions to mitigate AI agent security concerns, with the percentage doing nothing decreasing from 8.3% in 2025 to 2.5% in 2026.
About AvePoint
AvePoint is the global leader in data protection, unifying data security, governance, and resilience to provide a trusted foundation for AI. More than 28,000 customers rely on the AvePoint Confidence Platform to secure, govern, and rapidly recover data across Microsoft, Google, Salesforce, and other cloud environments. With a single platform for lifecycle control, multicloud governance, and rapid recovery, AvePoint prevents overexposure and sprawl, modernizes legacy data, and minimizes data loss. Our global partner ecosystem includes approximately 6,000 MSPs, VARs, and SIs, and our solutions are available in over 100 cloud marketplaces.