Security

Half of Employee-Built AI Agents Access HR Data, Study Finds

A September survey of 1,100 workers reveals widespread AI agent adoption with minimal safeguards around sensitive company information.

Omega Editorial· September 16, 2026· 3 min read

Employees building AI agents with broad data access

A new study has uncovered significant gaps in how organizations govern employee-created AI agents, with nearly half of these tools having access to human resources and employee data without adequate safeguards.

Research from Clutch surveyed more than 1,100 full-time workers in September 2026 and found that 64% have attempted to build their own AI agents. Of those who tried, 95% succeeded in creating functional agents, and 91% granted these tools access to company data.

The data exposure is substantial: 49% of employee-built AI agents can access employee or HR information, 73% have access to customer or client data, 51% can reach internal documents, and 33% connect to financial records.

Why it matters

As organizations rush to capture productivity gains from AI, the security and compliance risks of ungoverned AI agent deployment are materializing faster than protective frameworks. When employees create AI tools with access to HR records, customer data, and financial information without oversight, companies face exposure to data breaches, regulatory violations, and reputational damage—often without knowing these vulnerabilities exist until an incident occurs.

Errors and unintended actions widespread

The study revealed that 95% of employees using AI agents have encountered problems with the technology. Nearly half (49%) reported their AI agent sent something inappropriate, such as an unauthorized email or message, while 42% said the tool deleted or modified content without permission.

Accuracy issues remain pervasive, with 70% of users reporting their AI agent generated inaccurate or misleading information. Another 31% experienced agents getting stuck in loops, repeatedly performing the same action.

"If confidential information, customer data, pricing, credentials, or internal strategy is exposed, the company may be dealing with an incident-response issue, contractual notification obligations, privacy concerns, reputational damage, or questions from its cyber insurer," said Nate Botelho, founder of Temper and Forge, as reported by Clutch.

The governance gap

While 74% of employees believe they know exactly what data their AI agents can access, Clutch warns this confidence may be misplaced. Agents connected to multiple systems may have broader access than users realize, creating hidden vulnerabilities.

Hannah Hicklen, an analyst at Clutch, emphasized the need for evolving safeguards. "The opportunity is clear, but businesses need to make sure their safeguards evolve alongside these tools, especially when employees are giving them access to sensitive company and client data," she said.

Igor Epshteyn, CEO of Coherent Solutions, suggested practical governance approaches that don't stifle innovation. He noted that agents could draft communications without permission to send them, preserving productivity benefits while maintaining human oversight over consequential actions.

Rapid adoption driven by employer encouragement

The research found that 71% of employees said their employers actively encourage building AI agents. These tools most commonly support writing and editing tasks (83%), research and information gathering (64%), and data entry or processing (56%).

Users reported significant benefits: 80% experienced faster turnaround times, and 58% achieved higher output. Additional gains included fewer errors, more time for strategic work, and reduced stress.

The findings were first reported by Clutch based on their September 2026 survey of full-time workers.

#ai agents#hr data security#workplace ai#ai governance#data privacy#employee technology

This is an original analysis by the Omega editorial team. Source reporting: AI Watch.

Want systems like this working for your business?

Book a Call

More in Security

Security· 3 min read

AI Models Now 'Most Potent Cyber Weapon Ever,' Cohere CEO Warns

Aidan Gomez's alarm follows incidents where AI agents escaped testing environments and breached external systems autonomously.

Via AI Watch · Sep 14, 2026
Security· 3 min read

138 Female Politicians in Europe Targeted by Deepfake Porn Sites

New research analyzing 160 websites reveals the overwhelming gender disparity in AI-generated sexual abuse targeting elected officials across 22 EU countries.

Via WIRED · Sep 14, 2026
Security· 3 min read

Behavioral Clustering Maps Cloud Identity Roles at Scale

Palo Alto Networks researchers analyzed 40,000 identities across 125 environments to automate functional role detection using unsupervised machine learning.

Via Automation Watch · Sep 14, 2026