Ads

Breaking News

AI Agent Security Gap: 54% of Enterprises Report Incidents

Enterprises are grappling with a significant cybersecurity challenge as artificial intelligence (AI) agents gain unprecedented access to sensitive systems and data, according to recent VentureBeat Pulse Research. More than half of organizations surveyed, 54%, have already experienced a confirmed AI agent security incident or a near-miss, yet most continue to operate with critical security gaps, including widespread credential sharing. The report, based on a June 2026 survey of  107 enterprises with over 100 employees, reveals a growing disconnect between the autonomy granted to AI agents and the robust controls necessary to contain potential threats. This emerging "agent security gap" highlights a structural weakness in how businesses are deploying and managing their AI infrastructure. While AI agents are being integrated into core operations, the specialized identity, isolation, and enforcement controls required to secure them are lagging significantly behind.

Escalating Risks: The Pervasive Threat of AI Agent Incidents

By Decode Today News

The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials AI
The findings underscore an urgent need for enhanced security measures. A staggering 54% of organizations reported an AI agent security event, comprising 18% confirmed incidents and 36% near-misses caught before any harm occurred, the report said. This prevalence of near-misses is particularly telling, indicating that while enterprises are detecting problems, they are often doing so at the precipice of a full-blown breach. The scale of this exposure correlates directly with company size. The incident or near-miss rate rises from 49% in mid-market companies (101-1,000 employees) to 63% at larger enterprises (over 1,000 employees). Alarmingly, larger organizations, which typically run more agents across more systems, exhibit a reduced adoption of critical containment strategies, such as sandbox isolation for high-risk agents, which falls from 35% in the mid-market to just 20% in larger enterprises.

Understanding AI Agent Identity and Isolation

A core vulnerability contributing to these incidents is the management of AI agent identity. The research indicates that only about a third of enterprises, 32%, provide every AI agent with its own scoped, managed identity. This fundamental practice is a precondition for implementing "least-privilege access," which ensures agents only have access to the resources absolutely necessary for their function, and "clean attribution," which is vital for forensic analysis after an incident. The pervasive alternative is credential sharing. Across the surveyed enterprises, an overwhelming 69% report some form of credential sharing within their AI agent fleets. Nearly half, 48%, stated that while some agents have scoped identities, many still share credentials, and another 32% admitted that agents primarily operate on shared API keys or borrowed human and service-account credentials. 

The consequence of this shared credential posture is direct and severe: a single compromised or over-permissioned agent can gain far more reach than intended, exponentially increasing the potential "blast radius" of an attack. Furthermore, in the aftermath of an incident, the lack of distinct identities makes it nearly impossible to precisely attribute actions to specific agents, hindering effective incident response and compliance security. The report identified this "non-human identity problem" as the single largest unfinished piece of enterprise agent security. The correlation between credential posture and incident rates is stark. Organizations where credential sharing exists anywhere in the fleet experienced an incident or near-miss at a rate of 63.5% over the past twelve months, compared to 40.9 for organizations where every agent possesses its own scoped identity. While the fully-scoped group remains small, this 23-point difference strongly suggests the significance of robust identity management in mitigating cybersecurity risk.

Lagging Defenses: Isolation and Borrowed Security Stacks

Beyond identity, the report highlighted a critical deficiency in agent isolation. While roughly half of enterprises monitor agent activity (47%) or enforce scoped permissions at runtime (49%), only 30% isolate their highest-risk agents in sandboxes. Sandbox isolation is a crucial control that limits the damage when other preventative measures fail, bounding the "blast radius" of a compromised agent. This prioritization of observation and enforcement over isolation is described as "backwards from a defense-in-depth standpoint," creating a configuration where a single security failure can easily propagate. The security stack used by most enterprises is predominantly borrowed rather than purpose-built for AI agents. Provider-native controls from major model providers and hyperscalers dominate. OpenAI's guardrails lead at 51% usage, followed by Google's and Microsoft's cloud-native controls, and Anthropic's managed-agent controls. 

When asked to identify their primary security layer, 82% of respondents named one of these provider-native offerings. Dedicated agent-security specialists, such as Palo Alto's Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, and Okta for AI Agents, barely register in usage, each in the low single digits. Paradoxically, despite the high incident rates and identified security gaps, enterprises express considerable satisfaction with their current, often borrowed, security tooling. Overall satisfaction stands at a high 4.2 out of 5, with value for money rated at 4.1. 

This "false comfort," as the report terms it, appears to stem from the convenience and low friction of provider-native controls, rather than from demonstrated containment efficacy. This comfort is particularly striking given that a clear majority of these same enterprises are planning to change their tooling within the year.

Budgetary Disconnect and Future Outlook

Despite the escalating cybersecurity risk associated with AI agents, budgetary allocations remain modest. The report found that spending on agent security is still a "thin slice" of the overall security budget. The most common allocation is 6-10% of the security budget (46% of enterprises), while a third, 34%, spend 5% or less. Only a quarter, 24%, devote more than a tenth of their security budget to AI agent security. This suggests that funding has not kept pace with the rapid emergence of AI agent-related risks. 

Enterprises are also split on their ability to counter AI-enabled threats. Only about a third, 35%, believe their AI-enabled defenses are ahead of AI-enabled attackers. The rest are less confident: 32% consider it roughly even, 21% believe attackers are ahead, and another 21% deem it too early to tell. This means a clear majority, 53%, rate the balance as even or tilted towards the attacker, an uncomfortable position in an evolving "arms race" where offensive capabilities are also compounding with AI. 

The apparent satisfaction with current tooling belies a widespread intention to change. A clear majority, 59%, plan to adopt a new, additional, or replacement agent security solution within twelve months, with 29% intending to do so within the next quarter. This planned security reshuffle is strongly influenced by direct experience: among organizations that have experienced an incident, 42.1% plan to adopt, add, or replace tooling within 90 days, compared to just 14.0% of organizations without an incident. A confirmed incident escalates this to a majority behavior, at 52.6%. Experiencing an incident also shifts threat assessment, with 33.3% of affected organizations believing AI-armed attackers are ahead, versus 8.0% of unaffected ones. Here are key takeaways from the VentureBeat Pulse Research:
  • Incident Rate: 54% of enterprises experienced an AI agent security incident or near-miss.
  • Identity Gap: Only 32% give every agent its own scoped identity; 69% experience credential sharing.
  • Isolation Failure: Only 30% isolate high-risk agents in sandboxes.
  • Tooling Reliance: Security largely relies on provider-native controls (e.g., OpenAI, Google, Microsoft), with specialist vendors in low single digits.
  • Budget Lag: Most spend 10% or less of their security budget on AI agents.
  • Confidence vs. Reality: High satisfaction (4.2/5) with current tooling, yet 59% plan to change solutions within a year.
  • Threat Perception: Only 35% believe their AI defenses are ahead of AI-enabled attackers.
While the consideration set for new tooling still leans towards provider-native solutions (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), dedicated security vendors are drawing increased interest. However, a significant gap remains in the planned adoption of specific identity layer products, even among organizations with credential sharing that have already faced incidents. The research suggests that the current "agent security gap" is not merely a coverage problem that a default provider guardrail can resolve.

It represents a fundamental challenge in establishing robust identity, isolation, and enforcement mechanisms specifically designed for autonomous software. The critical question for the future of AI infrastructure and enterprise integration is whether organizations will proactively close this gap through deliberate investment in purpose-built controls, or if further confirmed incidents will force their hand.

More coverage from Decode Today