Enterprise AI agent security lags as sharing hits 69%, survey finds
A VentureBeat Pulse Research survey of 107 enterprises puts numbers behind a feeling many security teams already have: AI agents are operating in production with controls that were not designed for them. More than half of respondents (54%) have already had a confirmed agent security incident (18%) or a near-miss caught before harm (36%). Only about a third (32%) give every agent its own scoped identity, and the rest report credential sharing somewhere in their agent fleet. The picture is of autonomy expanding faster than the controls meant to contain it.
The 54% number is what the source builds its case around, but the structural pattern beneath it carries the practical consequence: 69% of enterprises (74 of 107) run agents on shared or borrowed credentials somewhere in their fleet. When a single over-permissioned agent shares credentials with the rest, blast radius expands and forensics after an incident cannot tell which agent did what. The source frames this as the largest unfinished piece of enterprise agent security: only a third of organizations have the precondition for least-privilege access and clean attribution.
The second structural problem is isolation. Roughly half of enterprises (47%) observe agent activity and 49% enforce scoped permissions at runtime, but only 30% sandbox their highest-risk agents. Observation tells you what happened; enforcement tries to prevent it; isolation is what limits damage when prevention fails. Adoption of the last control is the lowest of the three, which inverts the standard defense-in-depth ordering. The source does not specify what tooling the sandboxed enterprises use, but the direction of the gap is consistent across both Q2 waves the source describes.
A separate finding sharpens the pattern. The source reports satisfaction dropping from 4.36 to 3.97 between mid-market and larger enterprises, while sandbox isolation of high-risk agents falls from 35% to 20%. The enterprises running the most agents across the most systems are carrying the most incidents and the least of the one control that bounds blast radius. The incident-or-near-miss rate itself rises from 49% in mid-market to 63% at larger enterprises. Containment does not scale with exposure.
On tooling, the provider-native pattern dominates. OpenAI's guardrails lead at 51%, with Google's and Microsoft's cloud controls and Anthropic's managed-agent controls close behind; when asked for their primary security layer, 82% of enterprises name one of these provider-native offerings. The purpose-built agent-security category (Palo Alto's Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point's Lakera, Okta for AI Agents) registers in the low single digits individually. The default reach is the platform the model already ships with; independent security layers built for non-human identity and runtime isolation have not been adopted at scale.
The source describes the high comfort as resting on the convenience and low friction of provider-native controls rather than on demonstrated containment, and enterprises are simultaneously preparing to replace the stack: 59% plan to adopt, add, or replace tooling within twelve months, and 29% within the next quarter. Overall satisfaction with agent security tooling is 4.2 out of 5, and 4.1 for value for money, among the highest readings in the source's series. Buying cycles start with incidents.
The planned reshuffle does not yet include the missing control. The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), and only 12% of respondents include an agent-identity product (Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform) anywhere in their consideration set. Among credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged at roughly one in ten. The structural weakness the source identifies as largest is the one the planned purchases leave largely untouched.
Budgets explain part of this. Most enterprises (46%) spend 6-10% of the security budget on agents; a third (34%) spend 5% or less; only 24% devote more than a tenth. The enterprises spending more than a tenth of their security budget on agents are likely the ones building the scoped-identity and isolation controls the rest have not, but the source does not break this out explicitly. Confidence in the contest is equally split: 35% believe their AI-enabled defenses are ahead of AI-enabled attackers, 32% call it even, 21% think attackers are ahead, and 21% say it is too early to tell.
The methodology section flags limits a reader should hold in mind. At 107 respondents in a single June 2026 wave, the survey is a directional read, not a precise measurement. The sample is self-selected, mid-market weighted (42% have 251-1,000 employees), and not a probability sample. Several questions were multiple-select, so their shares can sum past 100%. The credential-sharing-versus-incident relationship is a 23-point gap in incident rate between fully-scoped and partially-scoped organizations, but the source treats it as association rather than proven causation, and the fully-scoped group is small (n=22). What the survey supports is a directional pattern: agent autonomy is outrunning identity, isolation, and enforcement.
The agent security gap will be tested first where the data points that way: larger enterprises, where incident rates reach 63% and sandbox isolation drops to 20%. Whether the planned tooling shift actually brings identity and isolation in alongside the provider guardrails, or simply rotates among provider bundles, the next survey wave will need to show.