Safety

Enterprises' AI Agents Outpace Identity and Isolation Controls, Survey Finds

A VentureBeat Pulse survey of 107 enterprises shows a widening "agent security gap": companies are granting autonomous AI agents real access to systems and data while identity, isolation and enforcement controls lag.

Enterprises' AI Agents Outpace Identity and Isolation Controls, Survey Finds

VentureBeat Pulse’s June 2026 survey of 107 organizations with more than 100 employees examined how enterprises secure autonomous AI agents — the tools they run, how they manage agent identity and isolation, what incidents have already occurred, budget allocations, and whether defenders think they are keeping pace with AI-enabled attackers.

The central finding is an “agent security gap”: enterprises are granting agents real reach into systems and data faster than they are building the identity, isolation, and enforcement controls needed to contain them.

Incidents and near-misses: the problem is already present

More than half of respondents (54%) reported an agent-related security event in the past 12 months: 18% a confirmed incident and 36% a near-miss that was caught before harm. Forty-two percent reported no such events, with a small remainder either not running agents in production or not tracking these events.

Exposure rises with company size: the incident-or-near-miss rate is 49% in mid-market firms (101–1,000 employees) and 63% at larger enterprises (1,001+ employees). At the same time, sandbox isolation of high-risk agents falls from 35% to 20% as size increases. Organizations running the most agents across the most systems therefore see more events and less of the containment control that limits blast radius.

The identity gap

Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the prerequisite for least-privilege access and clean attribution. Across the sample, 69% (74 of 107) report some form of credential sharing in their agent fleet: 48% say some agents have scoped identities but many still share credentials, and 32% say agents mostly run on shared API keys or borrowed human or service-account credentials. (Answers overlap because respondents could describe multiple patterns.)

When agents share credentials, a single over-permissioned or compromised agent can act with far greater reach, and forensic analysis cannot cleanly attribute actions. Organizations with credential sharing anywhere in the fleet experienced an incident or near-miss at 63.5% (47 of 74); organizations where every agent has its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so this is an association rather than proven causation, but the 23-point difference is suggestive.

Observe and enforce are common; isolate is not

Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes. From a defense-in-depth perspective this ordering is backward: observation shows what happened, enforcement tries to prevent it, but isolation limits the damage when prevention fails. The common configuration is agents that are watched and permissioned but rarely boxed in — a setup in which a single failure can propagate widely.

Security is mostly provider-native

Enterprises are leaning on the controls bundled with models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud controls and Anthropic’s managed-agent controls. When asked to name their single primary security layer, 82% named one of these provider-native offerings. Purpose-built agent-security vendors (for example, Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, and non-human identity platforms) register mainly in the low single digits.

This provider-default pattern held across two Q2 survey waves: enterprises typically reach first for the guardrails their platform ships, and independent agent-security specialists have not yet gained scale.

High satisfaction despite exposures, and modest budgets

Satisfaction with current agent-security tooling is high (4.2 out of 5 overall, 4.1 for value for money). That high satisfaction sits uneasily beside the incident rate and identity gaps: convenience and low friction of provider-native controls likely drive contentment, but the score may mask brittle coverage. Indeed, a clear majority plan to change tooling within the year.

Spending on agent security remains a small slice of the security budget. The most common allocation is 6–10% (46%), 34% spend 5% or less, and only 24% devote more than 10%. Given the incident and control gaps, budget appears to lag the emerging risk.

Defense vs. offense: no clear advantage

Only about a third of respondents (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; 32% say the balance is roughly even, 21% say attackers are ahead, and 21% say it is too early to tell. In total, 53% rate the balance as even or tilted toward attackers, a concerning position where the offense is also benefiting from AI.

Tooling changes are coming

A majority (59%) plan to adopt, add, or replace an agent-security solution within 12 months; 29% expect to do so within the next quarter. Among organizations that experienced an incident, 42.1% plan to change tooling within 90 days, versus 14.0% of those without an incident; after a confirmed incident, 52.6% intend to act. Incident experience strongly predicts both urgency and pessimism: 33.3% of hit organizations say attackers are ahead, compared with 8.0% of the unhit.

Although the consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), dedicated security vendors such as Cloudflare, Cisco, Palo Alto, Okta, and Check Point’s Lakera draw mid-to-high single-digit interest. Notably, only 12% include an agent-identity product (Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform) in their consideration set; among credential-sharing organizations that have already had an incident, identity consideration remains roughly one in ten.

Bottom line

In this directional, mid-market-weighted sample of 107 enterprise respondents, agent adoption is running ahead of agent security. More than half have had an incident or near-miss; only a third give every agent a scoped identity; most still share credentials; only 30% sandbox their highest-risk agents; and the security stack is overwhelmingly provider-native rather than purpose-built for agents.

The open question for future waves is whether enterprises will close the identity and isolation gaps deliberately — or whether a confirmed incident will force the change for them.

Methodology and limitations

The survey is a single June 2026 wave with 107 qualified respondents (100+ employees); the smallest company-size band (1–100 employees) was excluded. The sample is self-selected and skews toward the mid-market, so findings should be read as directional rather than precisely representative of all enterprises. Respondents are senior and buyer-credible (45% final decision-makers for AI purchases, 30% recommenders/influencers), and the largest industry cohorts are Technology/Software (23%), Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%). Satisfaction scores reflect the subset of respondents who answered those questions (82 of 107). Several survey questions allowed multiple selections, so some shares can sum to more than 100%.