More than half of enterprises running AI agents in production have already had a security event. That is not a projection. It is a count. In a June 2026 VentureBeat Pulse Research survey of 107 organizations with more than 100 employees, 54% report either a confirmed agent security incident, 18%, or a near-miss caught before harm, 36%. Only 42% report nothing at all.
The number that matters more, though, is the one beneath it. Only about a third of enterprises, 32%, give every agent its own scoped, managed identity. Nearly half say some agents have scoped identities but many still share credentials. Another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. Rolled together, 69% of enterprises have credential sharing somewhere in their agent fleet.
When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius. And only three in ten enterprises, 30%, isolate their highest-risk agents in sandboxes to bound that radius when other controls fail. The result is an agent security gap: autonomous agents are proliferating faster than the identity, isolation, and enforcement controls needed to hold them.
The comfort paradox
What makes the gap notable is how comfortable enterprises are inside it. Satisfaction with current agent security tooling averages 4.2 out of 5, among the most positive readings in this survey series. The security stack is overwhelmingly provider-native: OpenAI's guardrails lead at 51%, followed by Google's and Microsoft's cloud-native controls and Anthropic's managed-agent controls. When asked to name their single primary security layer, 82% choose one of these provider-native offerings.
The purpose-built agent-security category, Palo Alto's Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point's Lakera, Okta for AI Agents, and non-human identity platforms, barely registers. Each sits in the low single digits. Only 5% run no dedicated tooling at all.
That pattern held across two consecutive survey waves. In April to May, the same names led, and every dedicated specialist sat at 3% or below. Enterprises reach first for the guardrails their platform ships. The independent security layer that would address the identity and isolation gaps has not yet been adopted at scale.
The comfort appears to rest on convenience and low friction rather than on demonstrated containment. The same enterprises expressing high satisfaction are, as the survey shows, a clear majority planning to change tooling within the year. The confidence is thinner than the score implies.
The budget does not match the risk
Spending on agent security is still a thin slice. The most common allocation is 6 to 10% of the security budget, at 46%. A third of enterprises spend 5% or less. Only a quarter devote more than a tenth. Given the incident rate and the identity and isolation gaps, the budget looks like a lagging indicator. The risk has arrived faster than the funding to address it.
Enterprises are split on whether they are winning the security arms race. Only about a third, 35%, believe their AI-enabled defenses are ahead of AI-enabled attackers. Thirty-two percent call it roughly even. Twenty-one percent think attackers are ahead. Another 21% say it is too early to tell. Taken together, a clear majority, 53%, rate the balance as even or tilted toward the attacker.
That uncertainty sits uneasily beside the high satisfaction scores. Enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be.
Incidents start the buying cycle
The security stack is not settled. While 41% have no plans to change, 59% intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter. Among organizations that have been hit, 42.1% plan to adopt, add, or replace tooling within ninety days, against 14.0% of organizations with no incident. After a confirmed incident, it becomes majority behavior at 52.6%.
Getting hit also changes the threat assessment. Thirty-three percent of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience is the strongest predictor of both urgency and pessimism.
The consideration set still leans provider-native, but dedicated security vendors draw early interest in the mid-to-high single digits, more than their current footprint. What the shopping does not yet include is the identity layer specifically. Only 12% of respondents include an agent-identity product anywhere in their consideration set. Among credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged at roughly one in ten.
The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security is the question this series will keep tracking.
Exposure scales, containment does not
The incident-or-near-miss rate rises from 49% in the mid-market, companies with 101 to 1,000 employees, to 63% at larger enterprises above 1,000 employees. Meanwhile, sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius.
At 107 respondents in a single wave, this is a directional read, skewed toward the mid-market. But the direction is clear. Agent adoption is running ahead of agent security, and the controls that matter most when something fails, scoped identity and isolation, are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own. It is a problem of identity, isolation, and enforcement built for autonomous software. The open question is whether enterprises close it deliberately, or whether a confirmed incident closes it for them.