Safety

Survey finds enterprises expose AI agents while identity and isolation controls lag

A June 2026 VentureBeat Pulse survey of 107 enterprises shows a widening "agent security gap": organizations are granting autonomous AI agents real system access faster than they deploy scoped identities, sandboxing, and dedicated enforcement.

Survey finds enterprises expose AI agents while identity and isolation controls lag

A VentureBeat Pulse survey conducted in June 2026 of 107 enterprises (each with 100+ employees) finds that organizations are handing autonomous AI agents meaningful access to systems and data, but the controls to contain them — especially identity and isolation — are underdeveloped. The study examined tooling, identity management, isolation practices, incidents, spending, and whether enterprises think their defenses keep pace with AI-enabled attackers.

Core finding: an "agent security gap"

The central conclusion is an agent security gap: autonomy granted to agents is outpacing the identity, isolation, and enforcement controls meant to limit their risk. Across the sample, 54% of organizations reported an agent security event in the past 12 months: 18% a confirmed incident and 36% a near-miss caught before harm. Forty-two percent said they had no event; the remainder either do not run agents in production or do not track such events.

Identity is the biggest structural weakness

Identity management is the clearest shortfall. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Responses indicate overlapping patterns, but taken together 69% of organizations (74 of 107) report credential-sharing somewhere in their agent fleet. Nearly half (48%) said some agents have scoped identities while many others share credentials; 32% said agents mostly run on shared API keys or borrowed human/service-account credentials.

When credentials are shared, a compromised or over-permissioned agent carries a wide blast radius and post-incident forensics cannot cleanly attribute actions to a single agent. Correlationally, organizations with some credential sharing experienced an incident or near-miss at a rate of 63.5% (47 of 74), while those with full per-agent scoped identities were hit at 40.9% (9 of 22). The fully scoped group is small, so this is an association rather than proven causation, but the difference is notable.

Observation and enforcement are common; sandbox isolation is not

About half of enterprises observe agent activity (47%) and enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes. From a defense-in-depth perspective this is backward: observation tells you what happened, enforcement tries to prevent it, and isolation limits damage when prevention fails. Combined with the identity gap, the common posture is one where agents are monitored and permissioned but rarely boxed in, increasing the risk that a single failure will propagate broadly.

Security stacks are largely provider-native

Most respondents secure agents using controls bundled with their model or cloud provider. OpenAI guardrails lead at 51%, followed by Google and Microsoft cloud controls and Anthropic’s managed-agent controls. When asked to name their single primary security layer, 82% named a provider-native offering. Purpose-built agent-security vendors — examples include Palo Alto Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, and non-human identity platforms — appear only in low single digits.

This provider-default pattern was consistent with prior Pulse waves: in April–May the same providers led usage and dedicated specialists registered under ~3% each. The data reflect presence in stacks rather than spending or exclusivity, but the structural pattern is clear: enterprises first adopt the guardrails their platform supplies, and the independent layer that would address identity and isolation has not yet scaled.

Satisfaction high despite exposure; budgets stay thin

Respondents reported high satisfaction with their agent security tooling — 4.2 out of 5 overall and 4.1 for value for money — even as incidents and identity gaps persist. Satisfaction likely reflects the convenience and low friction of provider-native controls rather than proven containment.

Spending on agent security remains a modest share of security budgets: the most common allocation is 6–10% (46% of respondents), 34% spend 5% or less, and only 24% allocate more than 10%. Given the incident rates and control gaps, the budget appears to lag the risk.

Defensive balance: no clear lead

Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; 32% rate the contest roughly even, 21% say attackers are ahead, and 21% say it’s too early to tell. Taken together, a majority (53%) rate the balance as even or tilted toward attackers — an uncomfortable position given the high satisfaction scores.

Tooling changes are likely within months

Despite the satisfaction scores, 59% of enterprises plan to adopt, add, or replace agent security tooling within 12 months; 29% plan to do so within the next quarter. Among organizations that have experienced an incident, 42.1% plan a change within 90 days versus 14.0% of organizations with no incident; after a confirmed incident, 52.6% plan changes. Experience in this data set predicts both urgency and pessimism.

The consideration set for future purchases still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but dedicated security vendors such as Cloudflare, Cisco, Palo Alto, Okta, and Check Point’s Lakera are drawing early interest in the mid-to-high single digits. Identity-specific products are less commonly included: only 12% list an agent-identity product (Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform) in their consideration set, and among credential-sharing organizations that have had an incident identity consideration remains around one in ten.

Bottom line: autonomy is testing incomplete controls

Enterprises with 100+ employees are giving AI agents meaningful reach while relying largely on provider-native guardrails rather than purpose-built agent-security controls. More than half have already seen an incident or near-miss; only a third give every agent a scoped identity; only 30% sandbox their highest-risk agents; and the security stack is dominated by model-provider and hyperscaler controls. Satisfaction is high, but budgets are small, only a third believe they’re ahead of AI-enabled attackers, and most plan to change tooling within a year.

At 107 respondents from a single June 2026 wave, these results are directional and skew toward mid-market organizations that are actively standing up agent security. The trend is nevertheless clear: agent adoption is running ahead of agent security, and the controls most important for containing failures — per-agent identity and isolation — are the ones enterprises have built least. Whether businesses close this gap deliberately or a confirmed incident forces change remains the open question for future waves of this research.