Popular Posts

AI Agent Security Gap: Enterprises Face Rising Incidents While Controls Lag Behind

A recent VentureBeat Pulse Research study reveals a significant "agent security gap" across 107 enterprises, where autonomous AI agents are being granted extensive access to systems and data, yet the essential controls meant to contain them are critically underdeveloped. The research, focused on enterprise agent security, including tooling, identity management, isolation strategies, and enforcement controls, paints a concerning picture: over half of surveyed organizations have already experienced a confirmed agent security incident or a near-miss, signaling that the proliferation of autonomous agents is outpacing the foundational identity, isolation, and enforcement mechanisms needed for their secure operation.

The comprehensive study, conducted in June 2026, delves into how organizations with over 100 employees are securing their AI agents. It investigates the types of tools deployed, methods for managing agent identity and isolation, the prevalence of security incidents, budget allocations, and leadership confidence in their defenses against AI-enabled attackers. The findings highlight a paradoxical situation where enterprises express high satisfaction with their current, often borrowed, security stacks, even as vulnerabilities lead to frequent security events and a planned overhaul of their tooling.

Methodology: A Deep Dive into Enterprise Agent Security

VentureBeat’s Pulse Research series specifically focused this instrument on the practical aspects of enterprise agent security. The survey targeted organizations with more than 100 employees, yielding 107 qualified responses from a single wave. This cross-sectional data provides a directional signal, particularly reflecting the perspective of mid-market organizations actively deploying agent security, rather than a precise statistical measurement or a trend analysis over time.

The respondent sample was designed to be senior and buyer-credible, with 45% of participants identified as final decision-makers for AI purchases and an additional 30% serving as recommenders or influencers. The seniority mix included managers (43%), individual contributors (24%), VPs and directors (15%), and C-suite executives (11%). Organizationally, the sample was weighted towards mid-market companies: 42% had 251-1,000 employees, and 25% had 101-250 employees. Larger enterprises, with 1,001-5,000 employees, constituted 19%, while those with 5,001-10,000 and 10,001+ employees represented 8% and 7%, respectively. Key industries represented included Technology/Software (23%), Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).

It’s important to note that the sample is self-selected and not a probability sample, meaning results should be interpreted as directional insights rather than definitive measurements. Several questions allowed for multiple selections, so some percentages may sum to more than 100%. Satisfaction ratings were calculated based on 82 of the 107 qualified respondents, providing an average score on a five-point scale.

Finding 1: Incidents Are Already a Reality

A defining revelation of the report is the widespread occurrence of agent security incidents. More than half of organizations (54%) that run agents in production have already experienced an agent security event. This includes 18% reporting a confirmed incident and a substantial 36% experiencing a "near-miss" that was caught before causing harm. Only 42% reported no such incidents, with a small remainder either not running agents in production or not tracking such events. The high number of near-misses is particularly telling, indicating that while enterprises are detecting problems, these detections are often happening perilously close to the point of potential damage. The effectiveness of future controls, such as identity, isolation, and enforcement, will determine whether these near-misses escalate into confirmed breaches.

Furthermore, exposure to incidents appears to scale with company size, but containment measures do not. Larger enterprises (over 1,000 employees) reported a higher incident-or-near-miss rate of 63%, compared to 49% in the mid-market (101-1,000 employees). Alarmingly, sandbox isolation for high-risk agents actually decreased in larger enterprises (20%) compared to the mid-market (35%), while satisfaction with security tooling also dropped. This suggests that the organizations with the most agents and systems are facing more incidents while implementing fewer of the critical controls designed to limit damage.

Finding 2: The Critical Identity Gap

A fundamental structural weakness underpinning these incidents is the management of AI agent identities. Only about a third of enterprises (32%) provide each agent with its own scoped, managed identity, which is crucial for implementing least-privilege access and ensuring clean attribution in the event of a security event. The overwhelming majority, a combined 69% of enterprises, exhibit some form of credential sharing within their agent fleet. Nearly half (48%) acknowledge that while some agents have scoped identities, many still share credentials. An additional 32% reported that their agents primarily operate on shared API keys or borrowed human/service-account credentials.

This pervasive credential sharing has direct and severe consequences: a compromised or over-permissioned agent can operate with an unacceptably wide "blast radius," enabling extensive unauthorized actions. Moreover, post-incident forensics become significantly more challenging, if not impossible, to accurately attribute specific actions to individual agents. The report identifies this "non-human identity problem"—the failure to provide every agent with its own governed identity—as the single largest unresolved challenge in enterprise agent security. The data further supports this, showing that organizations with any credential sharing in their fleet had an incident or near-miss rate of 63.5%, significantly higher than the 40.9% for organizations where every agent has a scoped identity.

Finding 3: Observation and Enforcement Prevail, Isolation Lags

While approximately half of enterprises monitor agent activity (47%) and enforce scoped permissions at runtime (49%), a crucial defense-in-depth control remains largely unadopted: isolation. Only 30% of organizations isolate their highest-risk agents in sandboxes designed to bound the blast radius when other controls inevitably fail. From a robust security posture perspective, this ordering is inverted. Observation provides post-event insights, and enforcement attempts prevention, but isolation is the ultimate safeguard that limits damage when prevention mechanisms are breached. The low adoption of isolation, coupled with the prevalent identity gap, creates a dangerous configuration where a single failure can propagate widely.

Finding 4: Reliance on Borrowed, Provider-Native Controls

Enterprises overwhelmingly secure their AI agents using tools bundled with their core models and cloud platforms. OpenAI’s built-in guardrails lead in usage (51%), followed closely by Google Cloud controls (36%), Microsoft Azure’s Purview/Copilot Studio DLP (35%), and Anthropic’s managed-agent controls (29%). When asked to identify their primary security layer, a staggering 82% named one of these provider-native offerings. This widespread reliance on "provider bundles" means that purpose-built agent-security specialists—such as Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, or Okta for AI Agents—barely register, each appearing in low single digits. Only 5% reported using no dedicated tooling. This trend, consistent across multiple survey waves, suggests that enterprises are defaulting to convenient, platform-native solutions, overlooking independent security layers that could specifically address the identified identity and isolation gaps.

Finding 5: High Satisfaction Despite Mounting Incidents

A striking contradiction emerges: enterprises express high satisfaction with their current agent security tooling, averaging 4.2 out of 5 overall, and 4.1 for value for money. This comfort, however, stands in stark contrast to the high incidence of security events and the significant identity and isolation gaps identified. The report suggests this satisfaction may stem from the convenience and low friction of provider-native controls, rather than from their demonstrated efficacy in containing advanced threats. This "false comfort" is further underscored by the fact that the same satisfied enterprises are, as later findings reveal, actively planning to replace their current tooling, indicating a latent awareness of its provisional nature.

Finding 6: Budgets Yet to Catch Up with Risk

Despite the clear and present risks, budget allocation for agent security remains modest. The most common allocation is 6-10% of the overall security budget (46%), with a third of enterprises (34%) spending 5% or less. Only a quarter (24%) dedicate more than 10%. This conservative spending appears to be a lagging indicator, failing to keep pace with the rapid emergence of AI agent risks and confirmed incidents. Enterprises dedicating more than a tenth of their security budget are likely the minority actively building the robust scoped-identity and isolation controls that the majority still lack.

Finding 7: An Even Arms Race, At Best

Confidence in the ongoing cybersecurity arms race against AI-enabled attackers is far from settled. Only about a third of enterprises (35%) believe their AI-enabled defenses are ahead. The remaining majority are either unsure (32% believe it’s roughly even, 21% believe attackers are ahead, and 21% say it’s too early to tell). Cumulatively, 53% rate the balance as even or tilted in favor of attackers. This uncertainty is incongruous with the high satisfaction reported earlier, highlighting a disconnect between perceived tooling effectiveness and the harsh reality of an evolving threat landscape where offense is also powered by AI. An "even race" in such a dynamic domain is inherently precarious.

Finding 8: A Security Reshuffle Is Imminent

Despite high satisfaction, the agent security stack is far from settled, indicating a widespread acknowledgment of its provisional nature. A clear majority (59%) of enterprises plan to adopt a new, additional, or replacement agent security solution within the next twelve months, with 29% intending to do so within the next quarter. This strong signal suggests that incidents are a primary catalyst for change. Organizations that have experienced an incident are significantly more likely to plan tooling changes within 90 days (42.1%) compared to those without incidents (14.0%), with this figure rising to 52.6% after a confirmed incident. Experience also correlates with increased pessimism, as 33.3% of hit organizations believe AI-armed attackers are ahead, versus 8.0% of unhit organizations.

While the consideration set for new tooling still leans towards provider-native solutions (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), dedicated security vendors like Cloudflare, Cisco, Palo Alto, Okta, and Check Point’s Lakera are drawing early interest in the mid-to-high single digits, indicating potential for increased market penetration. Crucially, however, the "identity layer"—products like Okta for AI Agents, Microsoft Entra Agent ID, or non-human identity platforms—remains largely absent from these purchase plans, with only 12% including such solutions in their consideration set. Even among credential-sharing organizations that have already experienced an incident, interest in identity-specific solutions remains low, around one in ten. This suggests a persistent oversight of the control most directly implicated by the incident data.

The Bottom Line: An Autonomy-Driven Security Gap

The VentureBeat Pulse Research report unequivocally concludes that enterprises are granting AI agents significant autonomy and access to critical systems and data while relying on security controls ill-suited for the unique challenges of autonomous software. The pervasive "agent security gap" is characterized by frequent incidents, a widespread failure to implement scoped agent identities, a critical lack of isolation for high-risk agents, and an overwhelming dependence on borrowed, provider-native security tools.

This uncomfortable combination of high confidence and high exposure, coupled with modest security budgets and an uncertain outlook on the AI arms race, paints a picture of vulnerability. While enterprises are planning a significant reshuffle of their security tooling, the critical identity and isolation controls, which are most essential when autonomous systems fail, are still not adequately prioritized in these future plans. The open question for future research is whether organizations will proactively address this security gap through purpose-built solutions for identity, isolation, and enforcement, or if a further wave of confirmed incidents will ultimately force their hand.

Tagged:

Leave a Reply

Your email address will not be published. Required fields are marked *