VentureBeat
Follow
The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials
Enterprises are granting AI agents significant system access, but their security controls are lagging far behind. Over half of surveyed companies have experienced an AI agent security incident or a near-miss. A mere third of organizations assign each AI agent a unique, scoped identity, while many still rely on shared credentials. Furthermore, only three out of ten businesses isolate their highest-risk AI agents.The current security frameworks are largely borrowed from AI model providers and hyperscalers, rather than being purpose-built for agent security. Investments in this critical area represent a small portion of overall security budgets. There is an even split among enterprises regarding whether their current defenses can keep pace with AI-powered attackers. This disparity has created an agent security gap, where autonomous agents are proliferating faster than the necessary identity, isolation, and enforcement mechanisms.The research highlights that 54% of organizations have faced an agent security event, with 18% experiencing confirmed incidents and 36% catching near-misses. A structural weakness lies in agent identity management, as only 32% provide distinct identities, leaving many to share credentials. This lack of unique Ids increases the potential damage from a compromised agent.Observing and enforcing agent activity are moderately common, but isolating high-risk agents is not. Despite high satisfaction levels with current, provider-native security tools, a majority of these same companies plan to update their tooling within the year, indicating a potential underlying dissatisfaction or a recognition of existing gaps. This suggests a reliance on convenience over robust, dedicated security solutions.