Enterprise AI Agent Security Gap: Only 18% Isolate High-Risk Agents
VentureBeat finds only 18% of enterprises isolate risky AI agents, while 53% report incidents or near-misses and 74% plan tooling changes within a year.
Summary
VentureBeat’s August 12, 2026 Pulse report surveyed 116 self-selected organizations with more than 100 employees in July 2026. 53% run agents in production, 27% are piloting, and 3% have no 12-month plans. 53% reported an event, including overlapping answers from 19% with confirmed incidents and 38% with near-misses. Among 93 live or piloting respondents, 65% enforce scoped runtime permissions, 56% log activity, 18% isolate high-risk agents, and 8% combine enforcement with isolation. Isolation reaches 21% in production, 13% in pilots, and 15% where credentials are shared.
49% give every agent a scoped managed identity, yet 63% share credentials somewhere: 37% use shared API keys or borrowed accounts, 34% have mixed fleets, and only 29% eliminate sharing; per-agent identity reaches 60% in production. Usage is OpenAI guardrails at 44%, Microsoft Azure at 42%, Anthropic managed-agent controls at 37%, and Google Cloud at 31%; 92% of 92 respondents naming a primary layer chose provider-native tooling, led by Azure at 27% and Anthropic at 26%. Cloudflare, 11%, and Cisco, 9%, lead specialists; CrowdStrike, Palo Alto, Zenity, Check Point’s Lakera, HiddenLayer, F5, and SentinelOne range from 1% to 7%.
Satisfaction reached 4.29 of 5 overall and for implementation, and 4.11 for value, yet 74% plan tooling additions or replacements within 12 months, 30% next quarter, and 26% no change. Spending is 6% to 10% for 44%, above 10% for 35%, and 5% or less for 28%. Attackers lead for 30%, defenses for 30%, 33% call it even, and 24% are unsure; hit organizations say attackers lead at 39% versus 20% otherwise. Consideration favors OpenAI at 38%, Azure at 37%, Anthropic at 35%, and Google Cloud at 28%; agent identity draws 10% and sandboxing 6%. The directional, mid-market-weighted nonprobability sample cannot establish trends.
Positives
- 65% of live or piloting enterprises enforce scoped agent permissions at runtime, while 56% monitor and log activity.
- 49% give every agent a scoped, managed identity, rising to 60% among enterprises with agents in production.
- 38% reported near-misses caught before harm, twice the 19% reporting confirmed incidents.
- 35% allocate more than 10% of their security budget to agent security, while 44% allocate 6% to 10%.
- 74% plan to adopt, add, or replace agent security tooling within 12 months, including 30% within the next quarter.
- 4.29 out of 5 satisfaction scores for overall tooling and implementation mark a series high, with value rated 4.11.
Risks & concerns
- Only 18% isolate high-risk agents, and just 8% combine isolation with runtime permission enforcement.
- 53% have experienced an agent security event, comprising overlapping reports from 19% with confirmed incidents and 38% with near-misses.
- 63% share credentials somewhere in their agent fleets, while only 29% report scoped identities without any sharing.
- 92% naming a primary security layer rely on provider-native tooling, while dedicated specialists generally remain in single-digit usage.
- Microsoft Entra Agent ID reaches 7%, while Okta for AI Agents, non-human identity platforms and runtime sandboxing each reach 3%.
- 30% say AI-armed attackers lead their defenses, rising to 39% among organizations with an incident or near-miss.
