Friday, September 25, 2026
Source trace. Via News points to the documents behind its reporting and shows what we drew from each — so you can check any claim. How we source
Source document

The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials

View original at venturebeat.com
VentureBeat AI - Enterprise Ai Title: The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials Date: 2026-07-16 19:02 Source: https://venturebeat.com/ai/the-agent-security-gap-54-of-enterprises-have-already-had-an-ai-agent-incident-and-most-still-let-…
Opening lines of the source · short snapshot — read the full document at the original

What we drew from this source

The claims Via News extracted from this document. We point to the source; we don't replace it.

  • Only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes.

    60% confidence
  • The most common agent security budget allocation is 6-10% (46%), a third of enterprises (34%) spend 5% or less, and only 24% spend more than a tenth.

    60% confidence
  • A clear majority (59%) of enterprises intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter.

    60% confidence
  • OpenAI's guardrails lead agent security tooling usage at 51%, and 82% of enterprises name a provider-native offering as their single primary security layer.

    60% confidence
  • Incident/near-miss rate rises from 49% in mid-market companies (101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation falls from 35% to 20% and satisfaction drops from 4.36 to 3.97.

    60% confidence
  • Only 35% of enterprises believe their AI-enabled defenses are ahead of AI-enabled attackers; 53% rate the balance as even or tilted toward the attacker.

    60% confidence
  • More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%).

    60% confidence
  • Only about a third (32%) of enterprises give every agent its own scoped, managed identity; the rest report shared credentials somewhere in the agent fleet.

    60% confidence
  • Among organizations that have been hit by an incident, 42.1% plan to adopt, add, or replace agent security tooling within 90 days, versus 14.0% of organizations with no incident; after a confirmed incident this rises to 52.6%.

    60% confidence
  • Satisfaction with agent security tooling averages 4.2 out of 5 overall, and 4.1 for value for money.

    60% confidence
  • Organizations with credential sharing anywhere in the fleet were hit with an incident or near-miss at 63.5% (47 of 74), versus 40.9% (9 of 22) for organizations where every agent has its own scoped identity.

    60% confidence
  • Twelve percent of respondents include an agent-identity product anywhere in their consideration set, and this figure is essentially unchanged among credential-sharing organizations that have already had an incident.

    60% confidence

Data points we hold from this source

OpenAI · agent security tooling usage rate51 percent
OpenAI · purchase consideration rate34 percent
Anthropic · purchase consideration rate29 percent
What we know · the intelligence behind this page
Live from the substrate
What we're seeing
Enterprise AI Agents Go Mainstream, But Trustworthy Data Access Lags Adoption
A wave of enterprise AI agent activity — fresh funding (Latitude's $35M Series A), a run of CB Insights CEO interviews spotlighting fintech- and healthcare-focused agent startups (Covecta, Penguin AI, Maisa AI), and major platform partnerships (Microsoft-Mistral, Manulife-Microsoft AI governance, Siemens-NVIDIA agentic EDA, Box's agent security controls) — signals agentic AI moving from pilot to production across financial and enterprise workflows. Yet Google Cloud's own research shows adoption is outrunning data readiness (companies average AI access to only 45% of their data, with 'data laggards' capped near 30%), while insider selling at incumbent C3.ai hints at mixed investor conviction even as the broader ecosystem accelerates.
Our read on the data ›
Signals we're tracking
Satellite-Terrestrial Network Integration Acceleration
Increased investment and launches in hybrid satellite-cellular networks across telecom industry; competitive responses from other carriers; regulatory activity around satellite spectrum; expansion of emergency/rural connectivity use cases
Patterns we're watching ›
Where sources disagree
ING Group
Both facts record the same metric (shares_outstanding) for ING Group at the identical observation date (2025-12-31). FACT A states 2,902,437,688 shares; FACT B states 2,902 million shares (2,902,000,000). The difference is 437,688 shares (~0.015%). This is a genuine value conflict, though the discrepancy appears to result from FACT B rounding to the nearest million while FACT A provides the precise count.
We flag conflicts openly ›
Recently verified
✓ Checked against the original source
4,983
facts traced to their source — and we flag the ones that don't hold up.
101 entities tracked4,983 facts checked against source5,305 source documents archived
Query this data → isubstrate.com
The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials — Source | Via News | Via News