54% of enterprises have already experienced an AI agent security incident or near-miss, according to new research from VentureBeat surveying 107 organizations with more than 100 employees.

The study reveals a critical "agent security gap" — autonomous AI systems proliferating faster than the identity and isolation controls needed to contain them. Of the incidents reported, 18% were confirmed breaches while 36% were near-misses caught before causing harm.

The structural weakness lies in identity management. Only 32% of enterprises give each AI agent its own scoped, managed identity. The remaining 68% report that agents share credentials or run on shared API keys and human service accounts.

When agents share credentials, a single compromised system creates a wide blast radius across enterprise infrastructure. Yet only 30% of organizations isolate their highest-risk agents in sandboxes to limit potential damage.

Security controls lag behind deployment

The research exposes how enterprises are comfortable operating within this security gap. Most rely on provider-native tools — OpenAI's guardrails (51%), Google and Microsoft cloud controls, and Anthropic's managed-agent systems dominate the security stack.

Dedicated agent security specialists barely register in enterprise deployments. Despite this reliance on borrowed controls, satisfaction averages 4.2 out of 5 among the 82 respondents who provided ratings.

Spending on agent security remains a thin slice of overall security budgets. Only one-third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a majority plan to change their security tooling within the year.

The incident rate correlates directly with identity practices. Companies with credential sharing anywhere experienced incidents at a 63.5% rate, compared to 40.9% for organizations with fully scoped agent identities.

Larger enterprises face higher exposure but weaker containment. The incident rate rises from 49% at mid-market companies (101-1,000 employees) to 63% at larger organizations, while sandbox isolation drops from 35% to 20%.

The survey, conducted in June 2026, focused on organizations actively deploying AI agents in production environments. Technology and software companies comprised 23% of respondents, followed by manufacturing (15%) and retail (14%).