enterprise data management

AI agents are outpacing the security designed to contain them

Most enterprises are already feeling the agent security gap, 54% have hit an incident or near-miss, yet most agents still share credentials.

4 min readVentureBeat
AI agents are outpacing the security designed to contain them

**Our Take: The Agent Security Gap Isn't a Technology Problem, It's a Trust Problem**

Here's what the data makes clear: we've handed our most capable employees, the AI agents, the keys to the kingdom, but we're still using the equivalent of a shared office keycard to let them in. The 54% incident rate isn't a wake-up call; it's the alarm bell that's been ringing for a while. When nearly a fifth of enterprises have confirmed a breach and over a third have caught a near-miss, the story isn't about failure. It's about a system straining at its seams. The uncomfortable truth is that we are comfortable. We're securing autonomous, dynamic systems with static, provider-native guardrails because they're convenient. But convenience is not a security strategy.

The identity gap is the core issue, and it's the one we can't afford to ignore. Giving every agent its own scoped, managed identity isn't a technical luxury; it's the foundational prerequisite for accountability. When 69% of organizations have credential sharing somewhere in the fleet, you're not just risking a breach, you're guaranteeing that when something goes wrong, you won't be able to answer the most basic question: "Who did this?" The correlation in the data is stark: those with full scoped identity saw a 23-point drop in incidents. This isn't about buying a better firewall. It's about fundamentally rethinking how we issue and govern access for non-human actors. If we can't tell which agent did what, we can't contain it, and we certainly can't learn from it.

What's most telling is the disconnect between satisfaction and action. Enterprises rate their current tooling at a 4.2 out of 5, yet a clear majority are planning to replace it within the year. That's not confidence; that's the sound of a pilot realizing they're low on fuel while complimenting the in-flight meal. The provider-native stack is comfortable because it's familiar and easy. But it was built to secure the model's output, not the agent's actions across your enterprise. The fact that only 30% isolate high-risk agents, while 49% enforce runtime permissions, reveals a fundamental misordering of priorities. You can observe a fire and even set rules about where it can spread, but without a sandbox to contain it, you're just watching the whole building go up.

The path forward isn't a new vendor or a better dashboard. It's a shift in mindset. We need to stop treating agent security as an extension of the model provider's promise and start treating it as a core architectural principle. That means demanding purpose-built identity, ruthless isolation, and a budget that reflects the risk. The enterprises that get this right won't be the ones with the most advanced AI. They'll be the ones that realize trust is not a feature you bolt on; it's a discipline you engineer in. The agents are already here. The question is whether our controls will catch up before the next near-miss becomes a defining incident.

From VentureBeat

Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping…

Read the original at VentureBeat