The ReadJuly 16, 2026via VentureBeat AI

The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials

Why it matters

Agent adoption is outpacing security controls. A new VentureBeat survey of 107 enterprises reveals that while AI agents proliferate, only a third give every agent its own identity, only three in ten isolate high-risk agents, and incident rates climb with company size even as containment controls decline—exposing a structural gap between autonomy granted and controls in place.

Key signals

  • 54% of enterprises (107 surveyed) have experienced an agent security incident (18%) or near-miss (36%)
  • Only 32% of enterprises give every agent its own scoped, managed identity; 69% have credential sharing somewhere in the fleet
  • Credential-sharing organizations hit at 63.5% incident rate vs. 40.9% for fully-scoped-identity organizations
  • Only 30% isolate highest-risk agents in sandboxes
  • 47% observe agent activity, 49% enforce scoped permissions, but isolation (30%) lags both
  • 82% rely on provider-native controls (OpenAI guardrails 51%, Google/Microsoft/Anthropic cloud controls); dedicated agent-security vendors in low single digits
  • Satisfaction with tooling at 4.2/5 despite incident exposure and identity gaps
  • Spending on agent security: 46% allocate 6–10% of security budget, 34% allocate 5% or less
  • Only 35% believe AI-enabled defenses are ahead of AI-enabled attackers; 53% rate balance as even or tilted toward attackers
  • 59% plan to adopt, add, or replace agent security tooling within 12 months; 42.1% of hit organizations within 90 days
  • Only 12% include agent-identity products in consideration set
  • Incident rate rises from 49% (mid-market: 101–1,000 employees) to 63% (enterprises 1,000+); sandbox isolation falls from 35% to 20%
  • Survey: n=107 (self-selected, mid-market weighted, June 2026 single wave); 45% final decision-makers, 30% recommenders/influencers

The hook

54%. That's the share of enterprises that have already had an AI agent security incident—and most still let their agents share credentials.

Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them. This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers. The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius. What makes the gap notable is how comfortable enterprises are inside it. The security sta...

The week's key stories, every Friday.

For practitioners and enthusiasts — free, in your inbox.

Free forever. No spam.