Connect with us

AI

Cloud Security Scores Now Decide How Much Autonomy AI Agents Get

Unisys survey data show cloud security scores, not AI skill, now decide how much autonomy agentic systems get across enterprise clouds.

Published

on

Three in four business and technology leaders now expect agentic AI to become essential to running enterprise cloud operations. Only 23% have actually scaled it. The rest are still testing, according to a new global survey from Unisys (NYSE: UIS), the enterprise technology company, which polled 1,000 senior IT and business decision makers across the United States, Europe and Asia Pacific for its AI & Cloud Insights Report 2026.

The gap traces to something few companies planned for. Cloud security posture, not the AI’s own competence, now decides how far the leash extends, and that shift is arriving just as breach rates have nearly tripled in a single year.

Agentic AI’s Cloud Mandate Outruns Its Rollout

Seventy-five percent of respondents believe agentic AI will become essential for managing expanding cloud application portfolios, while only 23% have begun enterprise-wide deployments. Most of the rest are stuck somewhere between a pilot and a promise. Early use clusters around two jobs: freeing up employee time and keeping sprawling cloud environments running.

Spending intent has not cooled. Half of respondents plan to increase agentic AI investment over the next year, and companies report real groundwork underway, including identifying priority use cases, training staff and setting governance rules before letting AI touch more of the business.

  • Agentic AI – software given a goal and a set of permissions, then left to plan and carry out multi-step actions across cloud systems, such as provisioning resources, triaging incidents or rebalancing workloads, without a human signing off on every step.

That definition matters because the gap between belief and deployment is not really a technology gap. A separate survey found 83% of firms say their infrastructure cannot yet support agentic AI at scale, which suggests the bottleneck sits below the AI layer, in the plumbing that grants it access in the first place.

Security Posture Becomes the Throttle on Machine Autonomy

Here is the mechanism most coverage of this report skipped past. Ninety three percent report that cloud security capabilities significantly affect how much autonomy they grant AI systems, tying security posture directly to innovation strategy rather than treating it as a separate checkbox.

That is a real change in how companies decide what an AI agent is allowed to touch. It is no longer a judgment about whether the model is smart enough. It is a judgment about whether the surrounding controls, identity checks and audit trails can survive the agent acting on its own.

The report also notes declining concern over AI-driven job displacement as experience with enterprise AI continues to grow. Worry about bias, hallucinations and lost human empathy has faded the same way. Attention has moved instead to deployment rules, workload oversight and access controls, the unglamorous machinery that actually governs what an agent can do once it is live.

That pattern is not unique to Unisys’s respondents. A McKinsey review of enterprise AI trust found security and risk cited as the top barrier to scaling agentic AI, ranked well ahead of regulatory uncertainty or plain technical limits. Two separate surveys, one conclusion: the constraint has shifted from can the AI do this to can we watch it closely enough while it does.

The Scorecard Behind an Inflection Point

Unisys’s own numbers show why boards are pushing harder for proof. Confidence in the underlying technology jumped. The payoff did not keep pace.

Metric 2025 2026
Have the right architecture for data-driven decisions 72% 90%
Operational efficiency exceeds expectations 80% 65%
Cloud security seen as enabling faster tech adoption 60% 96%
Experienced a cybersecurity breach in the past year 17% 49%

Read across the rows and a pattern emerges. Architecture confidence rose 18 points. Belief that security enables speed rose even further. Yet the share reporting operational efficiency actually beating expectations fell 15 points, and reported breaches nearly tripled. Mike Thomson, chief executive officer and president at Unisys, put it plainly in comments carried by Help Net Security: “The organizations winning right now have figured out how to turn what they already have into outcomes their boards can see and measure. The technology itself matters less than the discipline to act on it.”

IT and business leaders must show that their investments are paying off and delivering real growth. This means aligning IT to outcomes, deploying agentic AI where it creates value and treating security as the foundation that makes all of it possible, rather than a constraint.

That is Thomson again, in an 18-point jump in architecture confidence paired with a widening execution gap that Unisys itself calls out in the same release.

Breach Exposure Pushes Security Tools Into the AI Pipeline

Nearly half of surveyed organizations experienced a cybersecurity breach in the prior year, a surge that lines up with agentic AI’s wider reach into enterprise data and business processes. More access points mean more ways in.

Companies are responding by layering on tools built for exactly this problem: managed detection and response, identity governance, privileged access management and continuous threat exposure management. These are not new categories, but agentic AI has made them load-bearing in a way they were not two years ago, since an autonomous agent now needs the same identity scrutiny as a human employee, only faster and at greater volume.

Google has made a similar bet on the security side, folding its $32 billion Wiz acquisition into an agentic defense push, treating cloud visibility as the prerequisite for letting AI agents operate with any independence at all. The logic tracks with what Unisys found: security tooling is no longer downstream of AI strategy. It sets the strategy’s ceiling.

Cloud Sprawl Adds a Layer Nobody Budgeted For

Application modernization work is still mostly about plumbing. Enabling AI and automation tops the list of stated objectives, ahead of resilience, cost reduction, customer experience and speed to market. But the plumbing keeps getting more complicated, not less.

  • Integration with existing systems is the leading application strategy challenge organizations report.
  • Legacy systems and technical debt keep services spread across legacy, cloud and hybrid environments at once, adding dependencies that make management harder.
  • Talent shortages, cited by 27% of respondents, remain a leading IT issue.
  • Data management and integration problems, cited by 26%, run a close second.

Mike Thomson described the underlying dynamic to CIO Dive: “As organizations continue adding cloud applications, platforms and services without a strategic AI roadmap, managing complexity and adaptation becomes increasingly difficult.”

Edge, sovereign and industry cloud environments have picked up adoption in sectors with specific data, location and compliance demands, and each new platform brings its own controls, data locations and access rules. That same pull toward local control shows up in India’s crowded sovereign cloud building race, where multiple builders are chasing the same regulatory demand for data to stay onshore. Unisys’s own 2026 forecast anticipated this trend, predicting that sovereignty rules driving regional and national cloud zones would move from a niche concern to a standard requirement for regulated industries.

How Much Autonomy Should an AI Agent Get?

Unisys’s data points to a specific answer: only as much as the surrounding security and governance controls can support, which today means most agents still operate under close human review rather than full independence. Nearly nine in ten organizations report progress identifying priority AI use cases, and 87% say they are actively upskilling employees to work alongside these systems.

Thomson told CIO Dive that the deciding factor is rarely the model itself. “The technology is important, but success ultimately depends on having the right data, the right controls and a clear understanding of the outcomes you’re trying to achieve,” he said.

Governance is being written into AI plans from day one now, covering data access, system authority, workload placement and accountability, rather than bolted on after a pilot succeeds. Respondents expect those same rules to limit how fast agentic AI spreads through their organizations in the near term. The report’s own conclusion is that the limitation is temporary by design: the controls holding deployment back today are the ones meant to make wider deployment safe to approve tomorrow.

Frequently Asked Questions

What Tasks Does Agentic AI Handle in Cloud Operations Right Now?

Early deployments concentrate on cost optimization, patching, access reviews and ticket resolution, tasks that are repetitive enough to automate but bounded enough that a mistake is recoverable. Companies are deliberately keeping agents away from irreversible actions until governance controls mature.

Why Are Companies Still Raising AI Spending Despite Weaker Results?

Investment plans remain active across cloud infrastructure, cloud applications, automation, generative AI and zero trust security all at once, which suggests leaders are betting the shortfall is a discipline and integration problem rather than a reason to slow down spending.

What Worries Executives Most About Scaling Agentic AI Safely?

The leading concerns are limited visibility into where data and AI workloads actually sit, cloud security gaps, reliance on a small number of cloud providers, and regulatory uncertainty. Business leaders reported higher concern than average across every one of those categories.

How Does Data Sovereignty Affect Where Agentic AI Runs?

Sovereignty rules increasingly dictate where workloads can physically sit, and regional deployment has become the most common response, with organizations placing data and compute inside the borders a regulator requires rather than relying on a single global cloud footprint.

Will Security Rules Make Agentic AI Harder to Deploy?

In the near term, yes. Respondents expect governance and security controls to limit how quickly agentic AI spreads across business functions. The same rules are also the operating boundaries companies say they need before they will approve wider use across departments.

Logan Pierce is a writer and web publisher with over seven years of experience covering consumer technology. He has published work on independent tech blogs and freelance bylines covering Android devices, privacy focused software, and budget gadgets. Logan founded Oton Technology to publish clear, no nonsense tech news and reviews based on real hands on testing. He has personally tested and reviewed dozens of mid range and budget Android phones, written extensively about app privacy, and built and managed multiple WordPress publications over the past decade. Logan holds a bachelor's degree in English and studied digital marketing at a certificate level.

Continue Reading
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending