VentureBeat Pulse Research Reveals Agent Security Gap: 54% of Enterprises Report AI Agent Incidents While Core Controls Lag
Key Takeaways
- •More than half of surveyed enterprises (54%) have already experienced a confirmed agent security incident or a near-miss intercepted before harm occurred.
- •Only 32% of organizations assign every AI agent its own scoped, managed identity, while 69% report some degree of credential sharing across their agent fleet.
- •Just 30% of enterprises isolate their highest-risk agents in sandboxes, making it the least adopted of the core controls despite being the most effective at limiting blast radius.
- •Provider-native tools from OpenAI, Google, Microsoft, and Anthropic serve as the primary security layer for 82% of organizations, while dedicated agent-security specialists remain in the low single digits.
- •A majority of enterprises (59%) intend to adopt or replace agent security tooling within twelve months, with organizations that have suffered incidents showing the greatest urgency to act.

Across 107 enterprises surveyed by VentureBeat, AI agents are being granted real access to systems and data while the controls designed to contain them remain underdeveloped. The research reveals a persistent agent security gap: autonomous agents are proliferating faster than the identity, isolation, and enforcement controls required to manage them securely. Unlike traditional software, agents act with limited human oversight — making decisions, calling tools, and moving laterally across systems — which expands the attack surface beyond what conventional application security was designed to cover.
This installment of VentureBeat Pulse Research examines how enterprises secure their AI agents — covering the tooling they deploy, how they handle agent identity and isolation, what has already gone wrong, budget allocations, and whether organizations believe their defenses are keeping pace with AI-enabled attackers.
The Central Finding: An Agent Security Gap
The report's defining statistic is that more than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm occurred (36%). The structural weakness underlying these figures is identity management. Only about a third of enterprises (32%) assign every agent its own scoped, managed identity — a prerequisite for least-privilege access and clean attribution. The remainder report that some agents share credentials or that agents predominantly operate on shared API keys and borrowed human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent can affect a wide blast radius, yet only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to contain that risk.
What makes the gap particularly notable is how comfortable enterprises appear within it. The security stack is overwhelmingly provider-native — OpenAI's guardrails (51%), Google's and Microsoft's cloud controls, and Anthropic's managed-agent controls dominate, while dedicated agent-security specialists barely register. Satisfaction with this borrowed stack averages 4.2 out of 5. However, spending on agent security remains a thin slice of overall security budgets, only a third of enterprises believe their AI defenses outpace AI-enabled attackers, and a clear majority plan to switch tooling within the year. Organizations are expressing satisfaction with controls they are simultaneously preparing to replace.
Methodology
VentureBeat conducted this survey as part of its ongoing Pulse Research series, with this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses were filtered to organizations with more than 100 employees (n=107; the survey's smallest size band of 1–100 employees was excluded), drawn from a single June 2026 wave. Because this represents one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, allowing shares to sum to more than 100%.
By role, the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases, and another 30% are recommenders or influencers. The seniority mix comprises managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%). By organization size, the sample is mid-market-weighted: 251–1,000 employees (42%) and 101–250 employees (25%) lead, followed by 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%). Technology/Software is the largest industry represented at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).
At 107 respondents, the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement. It is self selected and not a probability sample, and it skews toward the mid-market — making it best read as the view from organizations actively standing up agent security rather than from the largest operators. Satisfaction ratings were computed on respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents.
Finding 1: Incidents Are Already Occurring
Organizations were asked whether they had experienced an agent security incident — either a confirmed breach or a near-miss intercepted before harm. The majority that run agents in production reported they had.
More than half of organizations (54%) have already experienced an agent security event — 18% a confirmed incident and 36% a near-miss caught before causing harm. Only 42% reported nothing, with a small remainder either running no agents in production or not tracking such events. The prevalence of near-misses over confirmed incidents is itself revealing: enterprises are catching problems, but often close to the point of failure. The controls examined throughout this report — identity, isolation, and enforcement — determine whether the next near-miss remains contained.
Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% among mid-market companies (101–1,000 employees) to 63% at larger enterprises (above 1,000 employees). Over the same range, sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and employ the least of the one control that bounds an incident's blast radius.
Finding 2: The Identity Gap
Enterprises were asked how they manage AI agent identity — whether each agent holds its own credentials or agents share them. Full per-agent identity remains the exception rather than the rule.
Taken together, the overlapping responses show that 69% of enterprises (74 of 107) have some degree of credential sharing within their agent fleet. Only about a third (32%) give every agent its own scoped, managed identity — the foundation for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% report that agents mostly run on shared API keys or borrowed human and service-account credentials. Respondents could describe more than one pattern across their fleet, so these figures overlap.
The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can operate with far more reach than intended, and post-incident forensics cannot cleanly distinguish which agent performed which action. Non-human identity management — providing every agent with its own governed identity — represents the single largest unfinished element of enterprise agent security. Industry frameworks including OWASP's Top 10 for LLM Applications have flagged excessive agency and inadequate identity controls as a top risk class, and analyst firms such as Gartner have identified non-human identity governance as a fast-emerging discipline that existing IAM tooling does not fully address.
The data also reveals a correlation between credential posture and incidents. Organizations with credential sharing anywhere in the fleet experienced an incident or near-miss in the past twelve months at a rate of 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three-point difference in incident rate suggests significance.
Finding 3: Observation and Enforcement Without Isolation
Organizations were asked about their agent security posture in practice — whether they observe, enforce, isolate, or combine these approaches. The control that most effectively bounds damage is the least commonly deployed.
Monitoring and enforcement are reasonably widespread: roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%). However, only 30% isolate their highest-risk agents in sandboxes designed to limit the blast radius when other controls fail. This ordering runs counter to a defense-in-depth approach: observation reveals what happened, enforcement attempts to prevent it, but isolation is what limits damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap, the resulting picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration where a single failure can propagate widely.
Finding 4: Provider-Native Controls Dominate
Enterprises were asked which agent security tooling they use and which serves as their primary layer. The results favor model providers and hyperscalers over dedicated security vendors.
Organizations are securing agents primarily with tools bundled into their model and cloud platforms. OpenAI's guardrails lead at 51%, followed by Google's and Microsoft's cloud-native controls and Anthropic's managed-agent controls. When asked to name their single primary security layer, 82% identified one of these provider-native offerings. The purpose-built agent-security category — including Palo Alto's Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point's Lakera, Okta for AI Agents, and non-human identity platforms — barely registers, with each vendor in the low single digits. Only 5% reported running no dedicated tooling at all. The provider bundle is winning the default position: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address identity and isolation gaps has not yet achieved meaningful adoption.
This default-to-provider pattern echoes the early trajectory of cloud security, where organizations initially relied on native cloud-provider controls before specialized vendors such as Wiz, Orca, and Lacework established the cloud-native application protection platform (CNAPP) category. Whether agent security follows the same arc — from provider convenience to purpose-built tooling — is a question the consideration data in Finding 8 begins to answer.
This provider-default pattern is consistent across both Q2 survey waves. In the April–May wave (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below, and one in ten using no dedicated tooling. The consistent finding across both surveys: enterprises default to solutions provided by their existing platform, and specialist category vendors have not yet established significant presence.
A note on reading these shares: the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place, so figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages carry the usual sample caveats. However, the structural pattern held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits.
Finding 5: High Satisfaction Despite Exposure
Enterprises were asked how satisfied they are with their current agent security tooling. The reported comfort level is notably inconsistent with the documented exposure.
Satisfaction with agent security tooling is high — 4.2 out of 5 overall and 4.1 for value for money — among the most positive readings in this research series. Enterprises are expressing high satisfaction with a stack composed mostly of borrowed provider guardrails, despite more than half having already experienced an incident or near-miss and only a third granting their agents scoped identities. The comfort appears rooted in the convenience and low friction of provider-native controls rather than in demonstrated containment effectiveness. As Finding 8 reveals, the same enterprises expressing satisfaction include a clear majority planning to change tooling within the year, suggesting their confidence may be thinner than the satisfaction score implies.
Finding 6: Budgets Lag the Risk
Enterprises were asked what share of their security budget they allocate to securing AI agents. For a rapidly emerging risk category, the allocation remains modest.
The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less. Only a quarter (24%) devote more than a tenth. Given the incident rate and the identity and isolation gaps documented above, the budget appears to be a lagging indicator — the risk has materialized faster than the funding to address it. Enterprises spending more than a tenth of their security budget on agent security are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls that others have not yet deployed.
Finding 7: The Arms Race Is Even at Best
Enterprises were asked how they assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled.
Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers. The remainder are less certain: 32% call it roughly even, 21% think attackers hold the advantage, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. This uncertainty sits uneasily alongside the high satisfaction reported in Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where offensive capabilities are also compounding with AI, an even race represents a vulnerable position.
Finding 8: A Security Reshuffle Is Coming
Enterprises were asked whether they plan to adopt a new, additional, or replacement agent security solution, and which vendors they are considering. Few intend to maintain the status quo.
While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, despite high satisfaction scores, enterprises recognize their current stack is provisional.
Incidents appear to be the primary catalyst for the buying cycle. Among organizations that have experienced an incident, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, compared to 14.0% of organizations with no incident. After a confirmed incident, this becomes majority behavior at 52.6%. Getting hit also shifts threat assessment: 33.3% of affected organizations say AI-armed attackers are ahead of their defenses, versus 8.0% of unaffected organizations. In this data, experience is the strongest predictor of both urgency and pessimism.
The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, and Check Point's Lakera — are drawing early interest in the mid-to-high single digits, exceeding their current installed footprint.
Notably absent from the shopping list is the identity layer specifically. Twelve percent of respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set. Among credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from purchase plans. Whether this wave solidifies the provider-native default or opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is a question this research series will continue to track.
The Bottom Line: A Security Gap That Autonomy Will Test First
Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for other purposes. More than half have already had an incident or near-miss. Only a third give every agent its own scoped identity, and most still share credentials. Only three in ten isolate their highest-risk agents. The stack performing this work is overwhelmingly borrowed from model providers and hyperscalers rather than purpose-built for agents.
The uncomfortable pairing of confidence with exposure is striking: satisfaction with current tooling is among the highest in this research series, yet spending remains a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave, this is a directional read skewed toward the mid-market — but the direction is clear. Agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have deployed least.
The agent security gap is not a coverage problem that a provider guardrail will close on its own. It is fundamentally a problem of identity, isolation, and enforcement designed for autonomous software. The open question for later waves is whether enterprises close this gap deliberately — or whether a confirmed incident closes it for them.
Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it is best read as the view from organizations actively establishing agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.