The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials
Summary
A VentureBeat Pulse Research survey of 107 enterprises, conducted in June 2026, reveals a significant "agent security gap" where AI agents are granted extensive system and data access without adequate controls. Over half (54%) of organizations have already experienced an agent security incident (18% confirmed, 36% near-miss). A critical weakness is identity management, with only 32% of enterprises giving every agent its own scoped identity, and most agents still sharing credentials. Furthermore, only 30% isolate their highest-risk agents in sandboxes. The security stack predominantly relies on provider-native guardrails like OpenAI's (51%), Google's, and Microsoft's cloud controls, with dedicated agent-security specialists barely registering. Despite high satisfaction (4.2 out of 5) with these borrowed controls, spending on agent security remains low (most allocate 6-10% of their security budget), and 59% plan to change tooling within a year, indicating a recognition of underlying issues.
Key takeaway
For Directors of AI/ML evaluating agent deployment strategies, recognize that current enterprise agent security practices are insufficient. Your reliance on shared credentials and provider-native guardrails significantly increases incident risk, as 54% of organizations have already experienced issues. Prioritize implementing scoped identities for every agent and sandboxing high-risk agents to contain potential breaches. This proactive approach will mitigate the "agent security gap" before a confirmed incident forces a reactive and costly overhaul.
Key insights
Enterprises face a critical AI agent security gap due to insufficient identity management and isolation controls, despite high satisfaction with borrowed tooling.
Principles
- Shared agent credentials expand incident blast radius.
- Isolation bounds damage when other controls fail.
- Provider-native controls often lack agent-specific depth.
In practice
- Implement scoped, managed identities for each AI agent.
- Sandbox high-risk agents to limit potential damage.
- Evaluate dedicated agent security solutions beyond provider defaults.
Topics
- AI Agent Security
- Identity Management
- Sandbox Isolation
- Credential Sharing
- Enterprise AI
- Security Incidents
Best for: CTO, VP of Engineering/Data, Executive, AI Security Engineer, Director of AI/ML, Consultant
Related on AIssential
See Counsel's argued verdicts on the open AI decisions leaders are weighing →
Editorial summary, takeaway, and curation by AIssential. Original article published by VentureBeat.