More than half of enterprises have already reported an AI agent security incident, with most lacking basic identity controls, according to new research from VentureBeat's June 2026 Pulse Research. The study of 107 enterprises found 54% experienced either a confirmed breach or a near-miss caught before harm occurred. Only 32% give every agent its own scoped identity, and most agents still share credentials, expanding the blast radius of any single compromise.
The Identity Gap
Only a third of enterprises give every agent its own scoped managed identity. The rest allow agents to share credentials or run on shared API keys and human or service-account credentials. What this means in practice is that a compromised agent can move laterally across systems. The research found that only 30% isolate their highest-risk agents in sandboxes to limit that movement. Larger enterprises with more agents actually report lower rates of sandbox isolation, falling from 35% in mid-market companies to 20% in organizations above 1,000 employees.
Borrowed Security Stacks
Enterprises overwhelmingly use provider-native security tools. OpenAI's guardrails lead at 51%, with Google and Microsoft cloud controls and Anthropic's managed-agent controls also widely deployed. Dedicated agent-security specialists barely register in the survey. Satisfaction with this borrowed stack averages 4.2 out of 5, yet a clear majority of enterprises plan to change tooling within the year. This signals that organizations are satisfied with controls they are preparing to replace. Spending remains a thin slice of the security budget, and only a third believe their AI defenses are ahead of AI-enabled attackers.
Why This Matters
The agent security gap has direct consequences for enterprise trust in AI systems. As more agents gain real access to sensitive data and systems, the lack of scoped identities and isolation means a single incident can cascade across the organization. The research shows larger enterprises, which run more agents, face a higher incident rate of 63% while deploying fewer sandbox controls. This creates a growing target for attackers. The Technology sector, which leads the survey at 23% of respondents, will likely face increasing pressure to adopt dedicated agent security solutions. For now, enterprises remain in a borrowed security model that may not scale as agent autonomy grows.



