More than half of enterprises deploying AI agents in production have already experienced a security incident or a near-miss, according to a June 2026 survey by VentureBeat Pulse Research. The study of 107 mid-market and large organizations found that 54% had faced some form of agent security event, with 18% confirming a breach and 36% reporting a close call caught before damage occurred. Despite this exposure, the controls meant to contain autonomous agents remain thin, borrowed, and largely untested at scale.
The survey paints a picture of enterprises racing to give software agents real access to systems and data without building the identity, isolation, and enforcement frameworks those agents require. The result is what the report calls an "agent security gap": adoption is outpacing protection, and the tools currently in place were built for humans or static APIs, not for software that makes its own decisions.
The Identity Problem Hiding Beneath the Incidents
The structural weakness under every incident statistic is credential sharing. Only 32% of organizations give every agent its own scoped, managed identity. The rest, a full 69%, have credential sharing somewhere in their agent fleet. Nearly half say some agents have scoped identities but many still share credentials, while another third report agents running mostly on shared API keys or borrowed human and service-account logins.
This matters because shared credentials destroy both prevention and forensics. An over-permissioned or compromised agent operating on a shared key can move laterally with no clear audit trail. After an incident, security teams cannot cleanly determine which agent did what. The report flags this as the single largest unfinished piece of enterprise agent security, and the data supports that reading. Organizations with credential sharing anywhere in their fleet reported incidents or near-misses at a rate of 63.5%, compared to 40.9% for those with fully scoped per-agent identities. The sample of fully scoped organizations is small, so the gap is an association rather than proven causation, but a twenty-three point difference is hard to ignore.
Containment Is the Missing Layer
Enterprises are watching and permissioning their agents, but they are not boxing them in. Roughly half observe agent activity (47%) or enforce scoped permissions at runtime (49%), yet only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when other controls fail. That ordering is backwards from a defense-in-depth perspective. Observation tells you what happened. Enforcement tries to stop it. Isolation is what limits the damage when prevention fails, and it is the control enterprises have adopted least.
The gap widens with company size. In the mid-market (101 to 1,000 employees), 35% sandbox their riskiest agents. At larger enterprises (above 1,000 employees), that figure drops to 20%, even as the incident rate climbs from 49% to 63%. The organizations running the most agents across the most systems carry the most risk and the least containment.
Provider-Native Tools Dominate, But Satisfaction May Be Misplaced
When it comes to tooling, enterprises are defaulting to what came in the box. OpenAI's built-in guardrails lead at 51%, followed by Google Cloud controls (36%), Microsoft Azure Purview and Copilot Studio DLP (35%), and Anthropic's managed-agent controls (29%). When asked to name their single primary security layer, 82% picked one of these provider-native offerings. Purpose-built agent security vendors, including Palo Alto's Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point's Lakera, and Okta for AI Agents, sit in the low single digits.
Satisfaction with this borrowed stack is surprisingly high, averaging 4.2 out of 5. But the report suggests this comfort is built on convenience and low friction rather than demonstrated containment. Enterprises are highly satisfied with tools that have already allowed more than half of them to suffer an incident or near-miss. That satisfaction sits uneasily beside another finding: a clear majority plan to replace or supplement their current tooling within the year.
Budgets and Confidence Both Run Thin
Spending on agent security remains a modest slice of the overall security budget. The most common allocation is 6% to 10% (46%), while a third spend 5% or less. Only 24% devote more than a tenth of their security budget to protecting AI agents. Given the incident rates and the identity and isolation gaps, the funding looks like a lagging indicator. The risk has arrived faster than the money to address it.
Confidence is equally shaky. Only 35% of enterprises believe their AI-enabled defenses are ahead of AI-enabled attackers. Another 32% call the race roughly even, 21% think attackers are ahead, and 21% say it is too early to tell. Taken together, a majority (53%) rate the balance as even or tilted toward the attacker. In a domain where offensive capabilities are compounding with AI, an even race is not a stable position.
Incidents Are the Catalyst for Change
The security stack is not settled. While 41% have no plans to change, 59% intend to adopt, add, or replace agent security solutions within twelve months, and 29% plan to do so within the next quarter. Experience is the strongest predictor of urgency. Among organizations that have been hit, 42.1% plan to change tooling within ninety days, compared to 14.0% of those with no incident. After a confirmed breach, that figure jumps to 52.6%.
Getting hit also darkens the threat assessment. 33.3% of affected organizations say AI-armed attackers are ahead of their defenses, versus just 8.0% of the unhit. The shopping list still leans provider-native, but dedicated security vendors are drawing early interest in the mid-to-high single digits, more than their current footprint suggests.
What is largely missing from those purchase plans, however, is the identity layer itself. Only 12% of respondents include an agent-identity product, such as Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform, in their consideration set. Even among credential-sharing organizations that have already suffered an incident, identity tooling consideration sits at roughly one in ten. The control most directly implicated by the incident data is the one least likely to be purchased.
What This Means for the Industry
This pattern is familiar to anyone who watched cloud adoption a decade ago. Organizations rushed workloads into public cloud environments and secured them with perimeter tools built for on-premise data centers. The mismatch created years of breach reports and compliance headaches before cloud-native security architectures caught up. Agent security appears to be on the same trajectory. The difference is speed: agents are being deployed faster than cloud workloads were, and their autonomy means a single misconfiguration can propagate damage in seconds rather than hours.
For CISOs and security architects, the survey is a clear signal that provider guardrails are a starting point, not a strategy. The enterprises spending more than a tenth of their security budget on agents are likely the same ones building scoped-identity and isolation controls the rest have not. Their early investment may define the security posture of the next wave of AI adoption.
The open question for the next Pulse Research wave is whether enterprises close the agent security gap deliberately, through architecture and budget, or whether the next confirmed incident closes it for them.
Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. The sample is self-selected, skews mid-market, and is directional rather than a precise measurement.