Jul 22, 2026
ManyPress

Advertisement

Artificial Intelligence

A new survey of 107 enterprises reveals that most organizations struggle with AI agent security, frequently relying on shared credentials and provider-native tools rather than dedicated defenses.

ManyPress

ManyPress

ManyPress Editorial

3 min readSource:VentureBeat AI
VentureBeat Research Finds 54% of Enterprises Experienced AI Agent Security Incidents

Key facts

  • 54% of enterprises reported a confirmed AI agent security incident (18%) or a near-miss (36%).
  • Only 32% of organizations provide every AI agent with its own scoped, managed identity.
  • Credential sharing is prevalent, with 69% of enterprises reporting that agents share credentials somewhere in their fleet.
  • 82% of enterprises identify a provider-native tool from companies like OpenAI, Google, or Microsoft as their primary security layer.
  • Organizations using scoped identities for every agent reported an incident rate of 40.9%, compared to 63.5% for those using shared credentials.

A June 2026 survey of 107 enterprises found that 54% of organizations have experienced a confirmed AI agent security incident or a near-miss. The research highlights a significant 'agent security gap,' where the autonomy granted to AI agents outpaces the identity and isolation controls used to manage them. While most enterprises report high satisfaction with their current security stacks, many continue to use shared credentials and provider-native guardrails rather than specialized security tools.

By the numbers

54%
enterprises with a confirmed incident or near-miss
32%
enterprises assigning each agent a unique identity
30%
enterprises using sandboxes for high-risk agents
82%
enterprises naming provider-native tools as primary security
4.2 out of 5
average satisfaction with agent security tooling

Identity and Isolation Weaknesses

The report identifies identity management as a primary structural weakness. Only 32% of surveyed enterprises assign every AI agent its own scoped, managed identity. The remaining organizations rely on shared API keys or human and service-account credentials, which increases the potential blast radius if an agent is compromised. Furthermore, only 30% of enterprises isolate their highest-risk agents in sandboxes to contain potential damage.

Reliance on Provider-Native Security

Enterprises are largely securing their AI agents using tools bundled by model providers and hyperscalers. OpenAI’s guardrails are used by 51% of respondents, and 82% of enterprises name a provider-native offering as their primary security layer. In contrast, dedicated agent-security specialists currently see low adoption rates. Despite this reliance on bundled tools, only one-third of enterprises believe their defenses are currently ahead of AI-enabled attackers.

Incident Rates and Company Size

Security exposure appears to scale with company size. Larger enterprises with more than 1,000 employees reported an incident or near-miss rate of 63%, compared to 49% for mid-market organizations. Paradoxically, larger companies are less likely to use sandbox isolation for high-risk agents, with usage dropping from 35% in the mid-market to 20% in larger firms.

Advertisement

This article was independently rewritten by ManyPress editorial AI from reporting originally published by VentureBeat AI.

Artificial Intelligence