54% of enterprises have already experienced an AI agent security incident or near-miss, according to new research from VentureBeat surveying 107 organizations with more than 100 employees.
The study reveals a critical "agent security gap" — autonomous AI systems proliferating faster than the identity and isolation controls needed to contain them. Of the incidents reported, 18% were confirmed breaches while 36% were near-misses caught before causing harm.
The structural weakness lies in identity management. Only 32% of enterprises give each AI agent its own scoped, managed identity. The remaining 68% report that agents share credentials or run on shared API keys and human service accounts.
When agents share credentials, a single compromised system creates a wide blast radius across enterprise infrastructure. Yet only 30% of organizations isolate their highest-risk agents in sandboxes to limit potential damage.
Security controls lag behind deployment
The research exposes how enterprises are comfortable operating within this security gap. Most rely on provider-native tools — OpenAI's guardrails (51%), Google and Microsoft cloud controls, and Anthropic's managed-agent systems dominate the security stack.
Dedicated agent security specialists barely register in enterprise deployments. Despite this reliance on borrowed controls, satisfaction averages 4.2 out of 5 among the 82 respondents who provided ratings.
Spending on agent security remains a thin slice of overall security budgets. Only one-third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a majority plan to change their security tooling within the year.
The incident rate correlates directly with identity practices. Companies with credential sharing anywhere experienced incidents at a 63.5% rate, compared to 40.9% for organizations with fully scoped agent identities.
Larger enterprises face higher exposure but weaker containment. The incident rate rises from 49% at mid-market companies (101-1,000 employees) to 63% at larger organizations, while sandbox isolation drops from 35% to 20%.
The survey, conducted in June 2026, focused on organizations actively deploying AI agents in production environments. Technology and software companies comprised 23% of respondents, followed by manufacturing (15%) and retail (14%).
💬 Discussion
Sign in to join the discussion.
Sign in →No comments yet — be the first.