The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials

| Source: VentureBeat AI

Tags: AI agents, enterprise security, identity management, agentic AI, credential sharing, VentureBeat

54% of 107 enterprises surveyed have already suffered an AI agent security incident or near-miss, with most still running agents on shared credentials and fewer than a third sandboxing their highest-risk agents.

Details

VentureBeat's Pulse Research survey of 107 enterprises reveals a structural security gap: AI agents are being granted broad system access while identity controls and isolation measures lag significantly behind. More than half (54%) report a confirmed incident (18%) or near-miss (36%), with weak identity management identified as the root structural cause. Only 32% of organizations assign each agent its own scoped, managed identity. The majority still run agents on shared API keys or human/service-account credentials — meaning a single compromised or over-permissioned agent can carry a wide blast radius across connected systems and data. Isolation is similarly thin: only 30% sandbox their highest-risk agents. The security tooling enterprises deploy is largely borrowed from model providers and hyperscalers rather than purpose-built for agentic architectures. Security spending on agents remains a small fraction of overall security budget. Notable is the disposition, not just the numbers. Enterprises appear largely comfortable inside the gap even as AI agents gain real access to production systems. With agentic deployments accelerating, the mismatch between autonomy granted and controls in place represents a live, not theoretical, risk.