The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials

· Source: VentureBeat · Field: Technology & Digital — Artificial Intelligence & Machine Learning, Cybersecurity & Data Privacy, Robotics & Autonomous Systems · Depth: Intermediate, long

Summary

A VentureBeat Pulse Research survey of 107 enterprises, conducted in June 2026, reveals a significant "agent security gap" where AI agents are granted extensive system and data access without adequate controls. Over half (54%) of organizations have already experienced an agent security incident (18% confirmed, 36% near-miss). A critical weakness is identity management, with only 32% of enterprises giving every agent its own scoped identity, and most agents still sharing credentials. Furthermore, only 30% isolate their highest-risk agents in sandboxes. The security stack predominantly relies on provider-native guardrails like OpenAI's (51%), Google's, and Microsoft's cloud controls, with dedicated agent-security specialists barely registering. Despite high satisfaction (4.2 out of 5) with these borrowed controls, spending on agent security remains low (most allocate 6-10% of their security budget), and 59% plan to change tooling within a year, indicating a recognition of underlying issues.

Key takeaway

For Directors of AI/ML evaluating agent deployment strategies, recognize that current enterprise agent security practices are insufficient. Your reliance on shared credentials and provider-native guardrails significantly increases incident risk, as 54% of organizations have already experienced issues. Prioritize implementing scoped identities for every agent and sandboxing high-risk agents to contain potential breaches. This proactive approach will mitigate the "agent security gap" before a confirmed incident forces a reactive and costly overhaul.

Key insights

Enterprises face a critical AI agent security gap due to insufficient identity management and isolation controls, despite high satisfaction with borrowed tooling.

Principles

In practice

Topics

Best for: CTO, VP of Engineering/Data, Executive, AI Security Engineer, Director of AI/ML, Consultant

Related on AIssential

Open in AIssential →

Editorial summary, takeaway, and curation by AIssential. Original article published by VentureBeat.