VentureBeat’s June 2026 Pulse Research wave polled 107 qualifying enterprises (each with more than 100 employees) and found that 74 organizations — 69% of the sample after deduplication — reported at least one deployment where agents share credentials. The survey allowed multiple answers, but when responses are deduplicated by organization, 69% signaled credential sharing somewhere in their environment.
A practical risk is straightforward: a shared API key or a borrowed human or service‑account credential turns a single compromised agent into a vector for every workflow that key touches. Forensic attribution often ends at the credential level because multiple agents on one account leave no clear record of which agent performed which action.
Incidents and near‑misses
More than half of respondents (54%) said they have already experienced an agent security incident or a near‑incident: 18% confirmed an incident, and 36% detected a near‑miss that was stopped before it became a breach. Most of these events are being halted at the chain’s last control point, but other survey data shows that this margin is narrow.
Identities and containment are underinvested
Only 32% of enterprises give every AI agent its own scoped, managed identity. Another 48% said some agents have scoped identities, while 32% reported that agents mostly run on shared API keys or borrowed human/service‑account credentials. Because respondents could choose multiple options, the raw category totals exceed 100%, but deduplicated results show 69% of organizations flagged credential sharing in at least one answer.
Shared credentials are especially dangerous because a single compromised key propagates access across multiple agents. Independent research cited in the coverage (CyberArk) estimates machine identities vastly outnumber humans — 82 machines for every human — and agents are the fastest‑growing part of that ratio.
Size drives exposure; containment does not scale
Incident rates rise with company size: organizations with 101–1,000 employees report a 49% incident rate, while those with more than 1,000 employees report 63%. At the same time, sandboxing the highest‑risk agents — the one control that limits blast radius when prevention and detection fail — is less common at larger organizations: it drops from 35% in smaller firms to 20% in the larger ones.
Larger enterprises run more agents across more systems, which increases incidents. Yet the engineering work and funding for sandbox isolation lag, leaving the organizations with the most agents the least containment. The survey cautions that the highest size band pools the two largest groups and holds only 15 respondents, so those particular numbers are directional.
Market response: big acquisitions and new products
That gap has driven a buying spree among major security vendors. Palo Alto Networks closed its acquisition of CyberArk on February 11, 2026, for total consideration of $21.1 billion — a deal first announced in July 2025 at roughly $25 billion and the largest in Palo Alto Networks’ history.
CrowdStrike completed its $740 million acquisition of runtime authorization platform SGNL and, by June 15, shipped the first product from that deal, Continuous Identity for AI Agents. CrowdStrike integrated SGNL in less than a year to deliver a product that validates every agent action in real time based on owner, caller, and device risk posture.
Cisco announced its intent to acquire Astrix Security on May 4, 2026, a specialist in non‑human identity, in a deal reported at about $400 million.
These transactions target the layer the survey shows many enterprises have not finished building: identity and isolation controls for agents.
Model providers as the default security layer
Survey respondents most often rely on provider‑native controls as their primary agent security layer: OpenAI’s built‑in guardrails lead at 51%, Google Cloud at 36%, Microsoft Azure (Purview and Copilot Studio DLP) at 35%, and Anthropic’s managed‑agent controls at 29%. Overall, 82% of respondents named a provider‑native or hyperscaler control as their single primary layer.
Purpose‑built specialists have single‑digit penetration: Palo Alto Networks’ Prisma AIRS at 7%, CrowdStrike at 6%, Okta for AI Agents at 4%, with Zenity and non‑human identity platforms each at 3%. Microsoft Entra Agent ID, the highest‑penetration identity‑specific control in the dataset, appears at 13%.
Bundled, preinstalled controls dominate because they ship free and enabled by default, but most only filter prompts and outputs and do not give agents their own identities or sandbox them. The two controls that most reward incident data — scoped identity and isolation — are not part of the default stack in most deployments.
Prompt and output filters attempt to judge intent, which is fundamentally different from observing actual actions. CrowdStrike CTO Elia Zaitsev said at RSAC 2026 that observing kinetic actions is a structured, solvable problem, whereas intent is not. Endpoint sensors that track what agents actually did require scoped identities and isolation boundaries to produce useful, attributable telemetry; shared credentials on bundled guardrails do not provide that.
Perception, budgets and buying intent
Enterprises rate their agent security tooling highly on satisfaction (4.2 out of 5), value for money (4.1) and ease of implementation (3.9). Despite those scores, only 35% believe their AI‑enabled defenses are ahead of AI‑enabled attackers; 32% think they are roughly even, 21% say attackers lead, and 21% say it is too early to tell.
Budget allocation shows a mismatch: 46% of organizations dedicate 6–10% of their security budget to agent security, and one third spend 5% or less. Half the sample has already seen an incident or near‑miss, but funding does not align with exposure. Only 9% currently allocate more than 25% of their security budget to agent security.
Looking forward, 59% plan to adopt, add, or replace agent security tooling within 12 months, and 29% plan to act this quarter. Interest in hyperscaler or model providers for future tooling is led by OpenAI (34%), Google (30%), Anthropic (29%), and Azure (25%). Dedicated vendors show higher forward interest than their current footprints suggest, indicating many organizations view their present stacks as provisional.
Three recommended actions for security leaders
VentureBeat highlights three concrete moves:
-
Inventory every agent’s credentials this quarter. Map agents that share credentials and those that run on borrowed human or service‑account identities. The objective is zero shared credentials between agents and no borrowed human identities; scoped identities should be assigned where agents touch multiple systems.
-
Sandbox the riskiest agents first. Isolation is the least‑adopted control (30%) yet the only one that contains blast radius when prevention and detection fail. Rank agents by the sensitivity of the resources they touch and isolate the highest‑risk set.
-
Match budget to incident rate. A third of enterprises fund agent security at 5% or less of the security budget despite more than half having experienced an incident or near‑miss. The full report breaks out exposure and containment by company size.
Final question
The board‑level question is simple: if one of our AI agents were compromised this afternoon, what systems would it touch, and whose credentials would it hold? For the 69% of enterprises that run agents on shared credentials, the likely answer is a shrug — because the forensic trail often runs cold at the key.
VentureBeat will publish the full Q2 Agentic Security report, including the complete vendor matrix, industry breakdowns, and the full dataset, at VB Transform on July 14–15, 2026, at Hotel Nia in Menlo Park.



