Home / Blog / The agent security gap: 54% of enterprises have already had…
Tech News

The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents…

By Dillip Chowdary • Jul 21, 2026 • Source: VentureBeat

Writing five analytical paragraphs from the provided facts only, plain text, no invented figures.Across 107 enterprises, AI agents are already being given real access to systems and data, and the controls meant to contain them are not keeping pace. More than half of those organizations — 54% — report a confirmed AI agent security incident or a near-miss. That figure is not a theoretical risk score; it is a count of environments where an agent with live access already crossed, or nearly crossed, a security boundary.

On the control side, the architecture is thin. Only about a third of enterprises give every agent its own scoped identity. Most agents still share credentials rather than running under least-privilege, per-agent principals. Only three in ten isolate their highest-risk agents. The security stack in use is overwhelmingly borrowed from model providers and hyperscalers, not purpose-built for agent-to-system access, tool calling, or multi-step action paths.

Advertisement

Tech Pulse Daily

Get tomorrow's pulse first

Join engineers who read Tech Pulse before stand-up. Free, weekday mornings.

For engineers and builders, the gap is concrete: agents that can read tickets, query databases, call internal APIs, or modify infrastructure are being deployed with shared secrets and incomplete isolation. Shared credentials erase attribution when something goes wrong, so incident response cannot reliably map an action back to a single agent. Scoped identity is not a compliance checkbox here; without it, rate limits, audit logs, and revocation all degrade into coarse, account-level controls.

Competitively, this favors vendors and internal platform teams that treat agents as first-class principals rather than chatbots bolted onto existing IAM. Model-provider and hyperscaler security tools are what most enterprises are using today, so default posture is likely shaped by LLM and cloud product boundaries, not by agent runtime design. Organizations that only wrap provider guardrails around agents with broad shared credentials are operating with a control plane that was never designed for non-human actors that chain tools and hold long-lived access.

What to watch next is whether enterprises close the three measurable gaps already visible in this sample: per-agent scoped identity instead of shared credentials, isolation for highest-risk agents, and purpose-built agent security rather than provider-borrowed stacks. Until those rates move, builders should assume production agents may share secrets, may not be isolated at the high-risk tier, and may already sit inside an organization that has had an incident or near-miss.

Advertisement

🔎 More interesting news

5-min tech signal

Weekday briefing for engineers who skip the noise.

No spam · Unsubscribe anytime

Advertisement

✈️ CareerPilot

Your AI job-search copilot

Match your resume against live Ashby, Greenhouse & Lever openings — fit scores, job-specific resume optimization and email alerts.

Find matching jobs →

Free Tools

Browse all tools →