Research

    Andeavour Research: Agent Discovery, Privilege & Principal Data

    Andeavour research studies how AI agents and AI Principals appear, accumulate privilege and behave inside enterprise environments. This page states what we measure, where the data comes from, and — just as importantly — which widely quoted figures are external and which are ours.

    What we study

    Our research programme covers four questions: how many AI agents exist in an environment compared with the documented inventory; how much privilege those agents hold relative to the task they perform; how many distinct AI Principals — the programs, orchestrators and pipelines that create, train and command agents — are operating; and how quickly an agent population can be revoked once compromise is suspected.

    Data sources

    Findings are drawn from customer and design-partner environments where Andeavour AgentGuard performs discovery, from controlled lab environments where we build and attack agentic systems, and from published external research. Customer data is used in aggregate only, with explicit consent, and is never republished in a form that can be attributed to an organization.

    External figures quoted anywhere on this site — for example industry survey results on unsanctioned AI in production, or platform-reported agent growth rates — are attributed to their publisher at the point of use and are not presented as Andeavour measurements.

    Attack classes we test

    Lab testing covers direct and indirect prompt injection, tool and connector abuse, memory and retrieval-corpus poisoning, non-human identity misuse and impersonation, multi-agent cascade failures, and compromise of the creation layer, including agent templates and fine-tuning pipelines. Test cases are mapped to OWASP GenAI agentic threat classes and MITRE ATLAS techniques so results are comparable with public work.

    Reporting standards

    Every published statistic carries its sample definition, collection window and measurement method, and is labelled as either an Andeavour measurement or an external citation. When a figure cannot be independently verified or the sample is too small to generalize, we say so rather than rounding the caveat away.

    Limitations

    Discovery findings reflect the environments we can observe, which skew toward enterprises already investing in agentic AI; they are not a random sample of all organizations. Lab results demonstrate feasibility of an attack class rather than its prevalence in the wild. Agent counts are point-in-time and change quickly, because the populations themselves change quickly.

    Methodology and corrections

    Full measurement definitions are documented on the methodology page. If you believe a figure we publish is wrong, write to info@andeavour.io with the detail; corrections are made in place and noted with the date of the change.