A July 2026 VentureBeat Pulse survey of 116 enterprises (each with more than 100 employees) examined how organizations secure autonomous, agentic AI systems. The central takeaway is straightforward: agents are in production and incidents are occurring, but controls focus on observation and permission enforcement while the containment control that limits damage is uncommon.
Agents are live and incidents are arriving
Among respondents, 53% run agentic AI systems in production today, 27% are piloting or running limited rollouts, and only 3% have no plans to deploy within the next 12 months. Security exposure has followed deployment: 53% of organizations reported an agent security event or near‑miss — 19% a confirmed incident and 38% a near‑miss caught before it caused harm.
That near‑misses outnumber confirmed incidents two to one indicates organizations are detecting problems but often only just in time; a near‑miss is a control that worked once, not evidence it will work reliably every time.
Identity is improving but sharing persists
Per‑agent identities are now the most commonly cited pattern: 49% of enterprises say each agent has its own scoped, managed identity. This is progress toward least‑privilege access and clean attribution. Yet the responses overlap: 63% of enterprises report credential sharing somewhere in their fleets — either predominantly shared API keys and borrowed human or service‑account credentials (37%) or a mixed fleet where some agents are scoped and many are not (34%). Only 29% describe a fleet with scoped identities and no sharing at all.
Among enterprises with agents in production, 60% report per‑agent identity, so the improvement concentrates where agents are actually deployed. Still, where credentials are shared, a compromised or over‑permissioned agent can act with outsized reach and post‑incident forensics cannot cleanly assign actions to a single agent.
The containment gap: isolation is rare
On posture questions (93 respondents who described their stance), 65% enforce scoped permissions at runtime and 56% observe and log agent activity, but just 18% isolate high‑risk agents with sandboxing. Only 8% combine enforcement and isolation.
Isolation rises modestly with maturity — 21% among enterprises with agents in production versus 13% among pilots — but even among fleets that share credentials, isolation is only 15%. The ordering is backward from a defense‑in‑depth perspective: observation tells you what happened, enforcement tries to prevent it, and isolation limits the blast radius when prevention fails. An environment that watches and permissions agents but does not box them in lets a single control failure propagate widely.
Most organizations rely on provider‑native security layers
Agent security tooling remains overwhelmingly provider‑native or hyperscaler‑bundled. OpenAI guardrails are present in 44% of stacks, Microsoft Azure in 42%, Anthropic’s managed‑agent controls in 37%, and Google Cloud in 31%. When asked to name a single primary security layer, 92% selected a model‑provider or hyperscaler‑native offering, led by Azure (27% of those naming a primary layer) and Anthropic (26%).
Purpose‑built agent‑security vendors exist but remain marginal: Cloudflare (11%) and Cisco (9%) are the largest specialists in the sample; dedicated runtime sandboxing tooling appears in just 3% of stacks.
High satisfaction and high churn intent coexist
Respondents rate their current agent security tooling a series‑high 4.29 out of 5 for both overall satisfaction and ease of implementation; value for money scores 4.11. Despite that, 74% plan to adopt, add, or replace agent security tooling within 12 months, with 30% planning changes in the next quarter. The apparent paradox suggests satisfaction is driven by the convenience and low friction of provider‑native controls rather than confidence that those controls contain damage.
Budgets are shifting but remain modest for many
The most common budget allocation to agent security is 6–10% of the security budget (44%); 35% now allocate more than 10%, while 28% spend 5% or less. Organizations spending above 10% are more likely to have resources to build scoped identity and isolation controls rather than rely solely on provider guardrails.
The arms race perception has shifted
When asked whether AI‑enabled attackers or AI‑enabled defenses are ahead, 30% said attackers are ahead, 30% said defenses are ahead, 33% judged the balance roughly even, and 24% said it was too early to tell. Overall, 63% rate the balance as even or worse. Organizations that have experienced a confirmed incident or near‑miss are more pessimistic: 39% of them say attackers are ahead, compared with 20% among those without incidents.
Purchasing intentions broaden but identity and sandboxing lag
Incidents drive urgency: 38% of organizations that have had a confirmed incident or near‑miss plan to adopt, add, or replace agent security tooling within 90 days (41% after a confirmed incident specifically). Consideration sets still lean provider‑native (OpenAI 38%, Microsoft Azure 37%, Anthropic 35%, Google Cloud 28%), while specialists such as Cisco, Cloudflare, Zenity, CrowdStrike and others draw growing interest.
However, agent identity products are included in only 10% of consideration sets (Okta for AI Agents, Microsoft Entra Agent ID, or non‑human identity platforms), and runtime sandboxing tooling appears in 6% — despite incident data pointing directly at those two controls.
Bottom line: deployment is ahead of containment
This survey’s directional view is clear: agent deployment is advancing faster than agent containment. More than half of enterprises run agentic AI in production, and a majority have already experienced an incident or near‑miss. Organizations have invested in observation and runtime enforcement and are increasing budgets, but fewer than one in five isolate high‑risk agents, only 8% pair enforcement with isolation, and credential sharing persists across 63% of fleets. The primary security layer is provider‑native in 92% of cases, while specialists built to close identity and containment gaps remain in single digits.
The result is an architecture optimized for prevention and observation with little in place to limit damage when prevention fails — precisely the situation the near‑misses in the data describe. Whether enterprises will deliberately build isolation and governed non‑human identity, or wait for a more severe incident to force change, remains the key open question for future waves of the Pulse series.
Methodology note: The survey captured responses from 116 qualified enterprise respondents (organizations with 100+ employees) in a single July 2026 wave. The sample is self‑selected and intended to provide directional insight rather than precise measurement.



