Employee-built AI agents have access to HR data, report finds

New report flags the risk of letting AI agents access sensitive company information without guardrails

Employee-built AI agents have access to HR data, report finds

Nearly half of employee-built AI agents have access to employee or HR data, according to a new report, which warned employers about AI guardrails falling short of protecting potentially sensitive company information.

Fresh findings from Clutch, which surveyed over 1,100 full-time workers in September 2026, found that 64% of them have tried to build their own AI agent.

Among them, 95% were successful in building an AI agent, where 91% said their agents had access to company data, including employee or HR information (49%). Other data that AI agents have access to include:

  • Customer or client data (73%)
  • Internal documents (51%)
  • Financial records (33%)

Nearly three in four employees (74%) have stated that they know exactly what data their AI agents have access to, but Clutch argues that an AI agent's access to information may not always be straightforward.

"An agent connected to multiple tools or systems may have access to more information than an employee realises," the report said.

It pointed out that an agent having access to company data risks the accidental disclosure of sensitive information.

Granting AI agents access to edit business systems could also allow them to modify or delete records without an employee realising it, or create another potential entry point for cyberattackers.

"If confidential information, customer data, pricing, credentials, or internal strategy is exposed, the company may be dealing with an incident-response issue, contractual notification obligations, privacy concerns, reputational damage, or questions from its cyber insurer," said Nate Botelho, founder of Temper and Forge, in the report.

AI agents need guardrails

Hannah Hicklen, an analyst at Clutch, urged employers to ensure that safeguards are in place amid growing deployment of AI agents.

"The opportunity is clear, but businesses need to make sure their safeguards evolve alongside these tools, especially when employees are giving them access to sensitive company and client data," Hicklen said.

The call comes as the report found that deployed AI agents remain vulnerable to mistakes, with 95% of employees reporting problems with their technology.

Nearly half (49%) of employees reported that their AI agent sent something that they shouldn't have, such as an email or message, while another 42% said the technology deleted or modified something that it shouldn't have.

Most employees (70%) reported that their AI agent's error involved generating inaccurate or misleading information, while 31% said it got stuck in a loop and kept repeating the same action.

Igor Epshteyn, CEO of Coherent Solutions, said in the report that governance frameworks are critical, but they don't need to be perfect before employees can experiment.

"For example, an agent can be allowed to draft an email or Slack response without being permitted to send it — preserving much of the productivity benefit while keeping consequential actions under human control," Epshteyn said.

Widespread AI agent adoption

The rise of AI agents in workplaces comes in the wake of strong company support, as 71% of employees said their employers are encouraging them to build their own AI agents.

Among the top processes that AI agents support include:

  • Writing, editing, or summarising content (83%)
  • Research and information gathering (64%)
  • Data entry or data processing (56%)
  • Reporting or analytics (31%)
  • Email drafting or inbox management (20%)

Eight in 10 users of AI agents said it gave them faster turnaround, while more than half (58%) said it gave them higher output.

Other gains from AI agent deployment include fewer work errors, more time for strategic or creative work, better consistency in outputs, as well as reduced stress or workload.

LATEST NEWS