Artificial Intelligence

The AI agent security gap: 54% of enterprises have already suffered an incident, and most still share credentials

Published

on

AI agents are everywhere. Security isn’t.

Enterprises are deploying autonomous AI agents at a breakneck pace. But the controls meant to keep those agents in check? They’re playing catch-up — badly.

New research from VentureBeat’s Pulse series, based on a June 2026 survey of 107 enterprises (all with 100+ employees), paints a sobering picture. More than half — 54% — have already experienced a confirmed AI agent security incident or a near-miss that was caught just before damage occurred. Only 42% report no problems at all.

The core issue isn’t a lack of monitoring. It’s something more fundamental: identity. Just 32% of organizations give every agent its own scoped, managed identity. The rest allow agents to share credentials — a practice that turns a single compromised agent into a potential disaster.

This is the agent security gap: autonomy is racing ahead, while identity, isolation, and enforcement controls lag far behind.

The identity problem: shared credentials, wide blast radius

When you ask how enterprises manage agent identity, the answers reveal a structural weakness. Only about a third (32%) issue every agent its own credentials. Nearly half (48%) say some agents have scoped identities, but many still share. Another 32% report that agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could select multiple patterns, so these figures overlap.)

The consequence is direct. A single over-permissioned or compromised agent — sharing credentials with others — can act across systems with far more reach than intended. Forensics become murky: if something goes wrong, you can’t cleanly tell which agent did what.

The data backs this up. Organizations with credential sharing anywhere in the fleet reported an incident or near-miss at a rate of 63.5%. Among those where every agent carries its own scoped identity, that rate dropped to 40.9%. That’s a 23-point gap. The fully-scoped group is small, so it’s an association rather than proven causation, but the signal is strong: dedicated agent identity matters.

Isolation is rare — and that’s a problem

Even when enterprises have some controls in place, they’re often the wrong ones. Roughly half of organizations monitor agent activity (47%) or enforce scoped permissions at runtime (49%). But only 30% isolate their highest-risk agents in sandboxes.

That’s backwards from a defense-in-depth perspective. Monitoring tells you what happened. Enforcement tries to prevent it. But isolation is what limits damage when prevention fails — and it’s the control enterprises have adopted least. Combined with the identity gap, you get agents that are watched and permissioned but rarely boxed in. That’s the exact configuration where a single failure propagates.

Borrowed security: provider guardrails dominate

So what tooling are enterprises using? Mostly what came in the box. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls, and Anthropic’s managed-agent offerings. When asked to name their single primary security layer, 82% point to one of these provider-native tools.

Dedicated agent-security vendors — like Palo Alto Networks‘ Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, or Okta for AI Agents — barely register, each in the low single digits. Only 5% run no dedicated tooling at all.

The pattern is consistent across two survey waves. Enterprises default to the solutions their platform ships. The independent security layer that would address the identity and isolation gaps hasn’t yet been adopted at scale.

High satisfaction, thin budgets, and an arms race

Here’s the uncomfortable part: despite all these gaps, satisfaction with current agent security tooling averages 4.2 out of 5. That’s among the highest readings in this entire research series.

But look closer. Spending on agent security is still a thin slice of the overall security budget. The most common allocation is 6–10% (46%), and a third of enterprises spend 5% or less. Only a quarter devote more than a tenth.

And when asked whether their AI defenses are ahead of AI-enabled attackers, only 35% say yes. Another 32% call it roughly even, 21% think attackers are ahead, and 21% say it’s too early to tell. A clear majority rate the balance as even or tilted toward the offense.

Enterprises are content with tools they’re simultaneously unconvinced are winning. That’s a fragile comfort.

A reshuffle is coming — but identity is still overlooked

Perhaps the strongest signal that the current stack is provisional: 59% of enterprises plan to adopt, add, or replace agent security tooling within the next twelve months. 29% plan to do so within the next quarter.

Incidents drive urgency. Among organizations that have been hit, 42.1% plan to change tooling within ninety days, compared to just 14.0% of those with no incident. After a confirmed incident, it becomes majority behavior at 52.6%.

The consideration set still leans provider-native — OpenAI (34%), Google (30%), Anthropic (29%), Azure (25%). But dedicated security vendors like Cloudflare, Cisco, Palo Alto, and Okta draw early interest in the mid-to-high single digits, more than their current footprint.

Yet one thing is largely missing from purchase plans: the identity layer itself. Only 12% of respondents include an agent-identity product — like Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set. Among credential-sharing organizations that have already had an incident, that figure is essentially unchanged, at roughly one in ten.

The control most directly implicated by the incident data is the one largely absent from the shopping list.

The bottom line: autonomy is testing security first

This research is directional — 107 respondents in a single wave, skewed toward the mid-market. But the direction is unmistakable: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least.

The agent security gap isn’t a coverage problem that a provider guardrail will close on its own. It’s a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them.

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending

Exit mobile version