TLDRocket
Sign in

The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials

VentureBeat AI Covered by 4 sources

54% of enterprises have experienced AI agent security incidents or near-misses, with 69% allowing credential sharing among agents and only 30% isolating high-risk agents in sandboxes. Enterprises rely primarily on provider-native security controls from OpenAI, Google, and Microsoft rather than purpose-built agent security tools, with satisfaction averaging 4.2 out of 5. Despite high satisfaction with current controls, organizations with credential sharing face incident rates 23 percentage points higher than those with per-agent scoped identities, driving most enterprises to plan tooling changes within the year.

Why it matters

Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them.This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong,

Also covered by

Related stories

The daily briefing

Every AI story that matters, in your inbox by 8am.

TLDRocket reads 60+ sources, removes duplicate coverage, and summarises the day in two minutes. Free, no spam, unsubscribe anytime.