VentureBeat
Follow
Agentic security: Enterprises enforce agent permissions two-thirds of the time — and isolate high-risk agents less than one in five
Many enterprises have deployed AI agents in production, but a significant majority have already experienced security incidents or near-misses. Two-thirds of these organizations implement scoped permissions at runtime, while only a fifth isolate their most critical agents. This indicates that containment, a crucial security layer, is underdeveloped as agent autonomy increases. Credential sharing is prevalent, affecting nearly two-thirds of agent fleets, which contributes to a declining confidence in agent security. Current security measures are largely borrowed from model and cloud providers, and confidence in these defenses has waned. The perception is now split, with an equal number of enterprises believing AI-powered attackers are ahead of their defenses as those who believe the reverse. This research highlights a notable gap between observing and enforcing agent activity versus effectively containing potential damage when these controls fail. While identity management for agents is improving, credential sharing remains a significant issue, potentially magnifying the impact of compromised agents. The reliance on provider-native security tools is dominant, with dedicated security vendors playing a smaller role in this emerging threat landscape.