AI confidence among IT leaders just fell sharply. Here is why that is good news.

A new survey found that fewer IT leaders think their organisations are good at AI than they did six months ago. The reason tells you everything about where AI is actually headed.

AI2Day NewsdeskUpdated Editor: Lee Brown3 min read
AI agents in a digital network with security icons
Share

Key points

  • The share of IT leaders who called their organisations "mature" at deploying AI fell from 40% to 23% between early 2025 and Q3 2026, according to a JumpCloud survey of 800 IT leaders in the US and UK.
  • 84% of those same leaders plan to expand AI use in IT operations over the next six to 24 months, so the drop isn't a retreat.
  • Only 21% of organisations have formal governance for non-human AI agents, the lowest adoption rate of any AI security practice measured.
  • In 83% of organisations, AI agents and automated software identities now outnumber human employees on their systems.

Six months ago, four in ten IT leaders said their organisations were genuinely good at deploying AI. Today fewer than one in four say the same. That sounds bad. It isn't.

JumpCloud, a company that sells software for managing IT access and security, surveyed 800 IT leaders across the US and UK for its Q3 2026 trends report, first covered by VentureBeat. The leaders who revised their confidence downward are, overwhelmingly, the ones who moved AI agents, software programs that carry out tasks on their own without a human approving each step, from small test projects into live production environments. Real work, real systems, real problems.

Pilots are tidy. Production is not.

In a controlled test, an AI agent does one thing in a safe setting. A live environment is different: it connects to real company data, makes decisions that change how work gets done, and runs around the clock, often with nobody watching. The governance infrastructure for that is far more demanding than what it takes to run a pilot.

What happens to ordinary workers when AI agents go unsupervised?

The risk lands on everyone in the building, not just the IT team. JumpCloud's data identifies a specific failure point it calls "zombie agents": AI programs that were set up for a task, then never properly switched off or reviewed. They keep running, keep accessing files, and accumulate permissions with no named owner to answer for them.

Our 14 July story "AI agents are being trusted with more decisions than companies can actually verify" found that half of enterprises had already shipped an agent that passed internal tests and then broke something for a real customer. The JumpCloud numbers show why: the governance layer that should catch those failures barely exists yet.

Non-human identities, any software program or agent that logs into company systems the way a person would, now outnumber human users in 83% of organisations. Yet only 21% have formal governance covering them. No defined limits on access, no process to shut them down when the job is done.

When a human employee does something unexpected, there's an accountability trail. When an autonomous agent does, that trail doesn't exist unless someone built it deliberately. Most organisations haven't built it yet.

The ones that have closed that gap treat AI agents the same way they treat human employees: registered, limited to the access they actually need, removed from systems when their purpose expires. The payoff is concrete. Organisations in the top tier of JumpCloud's maturity model are five times more likely to report no barriers to expanding their AI programs than the average organisation.

Watch the governance number, not the confidence number. Confidence built on a real foundation is worth having. Confidence built on a pilot that hasn't met the real world yet is a liability dressed up as progress. The leaders dropping their scores are doing the honest accounting, and that's the leading indicator that actually matters.

© 2026 AI2Day