The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials
Back to Home
news

The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials

July 16, 202612 views2 min read
A recent survey has revealed a significant disconnect between the rapid adoption of AI agents in enterprises and the security measures in place to protect them. Out of 107 enterprise respondents with more than 100 employees, over half have already experienced an incident or near-miss involving their AI agents. Despite this exposure, only a third of organizations provide each agent with a scoped identity, and just 30% isolate their highest-risk agents. The survey, conducted in June 2026, highlights that while enterprises are highly satisfied with their current AI security tooling—rating it 4.2 out of 5—their investments in securing AI agents remain minimal. The most common allocation to AI agent security is between 6–10% of the overall security budget, with only a quarter spending more than 10%. "The comfort with current tooling appears to rest more on convenience than containment," said a spokesperson for the research team. "Enterprises are defaulting to guardrails provided by their platform vendors, which are not built to address the core issues of identity and isolation." Despite the high satisfaction scores, a clear majority (59%) of organizations plan to adopt or switch to new agent security solutions within the year. This trend is particularly pronounced among those who have already been hit by incidents—42% of these organizations intend to make changes within 90 days. The findings suggest that while enterprises are aware of the risks, they have yet to invest adequately in purpose-built solutions that can provide the necessary identity and isolation controls. Vendor usage still heavily favors platform-native offerings such as OpenAI's guardrails, Google’s cloud controls, and Microsoft’s Azure security features. Dedicated agent-security vendors like Palo Alto, CrowdStrike, and Cisco are gaining early interest but remain in the low single digits. "The question now is whether enterprises will proactively close the security gap or wait for a confirmed incident to force action," noted the report. "The stakes are high, especially as AI-powered attacks become more prevalent and sophisticated." As the AI landscape continues to evolve, the need for robust, dedicated agent security solutions is becoming increasingly urgent. Organizations that fail to address the identity and isolation gaps risk significant exposure as AI agents become more autonomous and pervasive in enterprise environments.

Related Articles