54% of enterprises hit by AI agent incidents while 4.2/5 satisfaction persists

The agent security gap is a real and measured phenomenon, not a prediction. More than half of enterprises running AI agents in production have already had an incident or a near-miss, according to a VentureBeat Pulse Research survey of 107 organizations with more than 100 employees. The structural weakness the data points to is identity: only about a third give every agent its own scoped identity, and most agents still share credentials. The open question is whether enterprises close this gap deliberately or through the next incident.

The headline finding is the incident rate. More than half the organizations surveyed, 54%, report a confirmed security event or a near-miss caught before harm: 18% confirmed incidents and 36% near-misses. That near-misses outnumber confirmed incidents is worth sitting with. It suggests enterprises are catching problems close to the edge, which means the identity, isolation, and enforcement controls the rest of the survey examines are doing the work of deciding whether the next near-miss stays a near-miss. Exposure scales with size: the incident-or-near-miss rate rises from 49% at mid-market (101 to 1,000 employees) to 63% at larger enterprises, while sandbox isolation of high-risk agents falls from 35% to 20%. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident blast radius.

The identity gap is the structural vulnerability beneath those numbers. Only 32% of enterprises give every agent its own scoped, managed identity, the precondition for least-privilege access and clean attribution. Nearly half report that some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. When agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly determine which agent did what. The non-human identity problem is the single largest unfinished piece of enterprise agent security. The correlation in the data is suggestive: organizations with credential sharing were hit at 63.5%, while organizations where every agent carries its own scoped identity were hit at 40.9%. The fully-scoped group is small (22 of 107), so this reads as association rather than proven causation, but a twenty-three-point difference in incident rate within a single survey is worth treating as a signal rather than noise.

The isolation gap compounds the identity problem. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes. The ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits damage when prevention fails, and it is the control enterprises have adopted least. Combined with the identity gap, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates.

On tooling, the survey finds that enterprises are overwhelmingly using what their model providers and cloud vendors ship. OpenAI's guardrails lead at 51%, followed by Google and Microsoft's cloud-native controls and Anthropic's managed-agent controls. When asked to name their single primary security layer, 82% point to one of these provider-native offerings. Purpose-built agent-security specialists, including Palo Alto Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point's Lakera, and non-human identity platforms, register in the low single digits each. The provider-default pattern held across two survey waves in Q2 with differently worded questions, which strengthens confidence in the structural finding even though individual vendor shares carry the usual caveats for a self-selected, mid-market sample.

The paradox is in the satisfaction data. Overall satisfaction with agent security tooling averages 4.2 out of 5, and 4.1 for value for money, among the most positive readings in the Pulse Research series. That score sits alongside 54% incident rates and 69% credential sharing. The source frames this as false comfort developing: the comfort appears to rest on convenience and low friction rather than demonstrated containment. The source adds that this reading has a built-in instability, because 59% of the same respondents plan to adopt, add, or replace their agent security tooling within twelve months, with 29% within the next quarter. Getting hit changes the behavior: 52.6% of organizations after a confirmed incident plan to change tooling within the next ninety days, against 14% of organizations with no incident.

Budget allocation reflects the gap between posture and risk. The most common allocation is 6-10% of the security budget (46%), and a third of enterprises spend 5% or less. Only a quarter devote more than a tenth. Given the incident rate and the identity and isolation gaps, the budget reads as a lagging indicator, the risk arriving faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are likely the ones building the scoped-identity and isolation controls the rest have not.

Confidence in the defensive race is similarly mixed. Only 35% believe their AI-enabled defenses are ahead of AI-enabled attackers; 32% call it roughly even, 21% think attackers are ahead, and 21% say it is too early to tell. Taken together, a majority (53%) rate the balance as even or tilted toward the attacker. This sits uneasily beside the high satisfaction scores. In a domain where offense is also compounding with AI, an even race is not a comfortable place to be.

The tooling consideration set shows early interest in switching toward specialist vendors (Cloudflare, Cisco, Palo Alto, Okta, Check Point's Lakera) in the mid-to-high single digits, more than their current footprint. But the identity layer specifically is largely absent from purchase plans: 12% of all respondents include an agent-identity product anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the shopping list.

The bottom line the source draws is accurate to the data: agent adoption is running ahead of agent security, and the controls that matter most when something fails, scoped identity and isolation, are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail closes on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The unresolved question the survey cannot answer is whether the next wave shows enterprises deliberately closing the gap or a confirmed incident closing it for them.

The directional findings hold with the standard caveats for this type of survey: 107 respondents from a single June 2026 wave, self-selected and mid-market-weighted, best read as the view from organizations actively standing up agent security rather than from the largest operators. The pattern held across two waves with differently worded questions, which gives the structural findings more weight than the individual shares warrant.

Subscribe to AI Enthusiast Log

Don’t miss out on the latest issues. Sign up now to get access to the library of members-only issues.
jamie@example.com
Subscribe