Enterprises Watch Their AI Agents Closely. They Just Won't Cage Them.
New research across 116 enterprises finds a majority have already had an agent security incident or near-miss — and only one in five isolates the agents most likely to cause the next one.
Written by OutOfToken AI
August 12, 2026 · 6 min read · Synthesized from reporting by VentureBeat · How this works
Agentic AI has moved past the pilot stage and into the blast radius. A new wave of VentureBeat Pulse Research, surveying 116 enterprises with more than 100 employees, finds that 53% already run agentic AI systems in production and another 27% are piloting them. The incidents have followed close behind: 53% of organizations report a confirmed agent security event or a near-miss caught just before it caused harm.
The containment gap
The report's central finding is less about whether enterprises are securing agents and more about which layer they're skipping. Sixty-five percent enforce scoped permissions at runtime and 56% monitor and log agent activity — both now mainstream controls. But only 18% isolate their highest-risk agents in sandboxes, and just 8% pair enforcement with isolation at all.
Backward from defense-in-depth
Security teams have long treated observation, enforcement, and isolation as layered defenses: watch, prevent, then contain. Enterprises have built the first two and largely skipped the third. Even among organizations running agents fully in production, isolation reaches only 21% — and among enterprises that already share credentials across their agent fleet, the group with the widest potential blast radius, isolation sits at just 15%.
"53% of enterprises have already had a confirmed agent security incident or near-miss. Only 18% isolate their highest-risk agents."
Identity: better, but not fixed
Progress is real but incomplete. Forty-nine percent of enterprises now give each agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution after an incident. Yet 63% report credential sharing somewhere in their fleet, whether through shared API keys, borrowed service accounts, or a mixed fleet where some agents are scoped and most aren't. Only 29% describe a fleet with scoped identities and zero sharing anywhere.
Borrowed guardrails, borrowed confidence
Ninety-two percent of enterprises naming a primary agent security layer point to a hyperscaler or model provider: OpenAI's guardrails lead at 44%, followed by Microsoft Azure (42%), Anthropic's managed-agent controls (37%), and Google Cloud (31%). Dedicated agent-security specialists — Cloudflare, Cisco, CrowdStrike, Zenity, and identity platforms like Okta and Microsoft Entra Agent ID — remain in single digits. Runtime sandboxing tooling, the control most directly tied to the isolation gap, sits at just 3%.
Satisfied, and about to replace it anyway
Enterprises rate their current tooling at a series-high 4.29 out of 5 for satisfaction and ease of implementation. At the same time, 74% plan to adopt, add, or replace agent security tooling within the next twelve months — the highest churn intent this research series has recorded. That combination points less to confidence in containment than to comfort with convenience: provider-native guardrails are easy to turn on, not necessarily sufficient to stop what near-misses already reveal.
The arms race has tilted
Confidence in the broader contest has slipped into an even split — 30% of enterprises now say AI-armed attackers are ahead of their defenses, exactly matching the 30% who say their defenses are ahead. Among enterprises that have already had an incident or near-miss, pessimism nearly doubles: 39% say attackers are ahead, versus 20% among those untouched. Experience, not headcount or budget, is the strongest predictor of how enterprises read the threat.
Incidents drive urgency — but not toward the right fix
Getting hit accelerates buying: 38% of enterprises with a confirmed incident or near-miss plan to adopt or replace tooling within ninety days, versus 22% of those with no incident history. Yet the consideration set still skews toward the same provider-native names already in place. Just 10% of enterprises include an identity-specific product like Okta for AI Agents or Microsoft Entra Agent ID anywhere in their shopping list, and runtime sandboxing draws only 6% — even among enterprises that both share credentials and have already been breached.
Agent deployment is outrunning agent containment, and the data suggests no provider-native guardrail update will close that gap on its own. Isolation and governed non-human identity are the two controls the incident data most directly implicates, and they remain the two least represented in what enterprises are actually buying. The open question for future waves is whether enterprises build those controls deliberately — or wait for a near-miss that doesn't stay one.
Editorial Note
The article draws directly from VentureBeat Pulse Research (n=116 enterprises, July 2026 wave), and every major quantitative claim in the article text is corroborated by the research data provided. The supporting sources confirm the critical findings about least-privilege access effectiveness and the broader enterprise AI security challenges, though they do not directly validate the specific survey percentages—only the VentureBeat research itself does that. The article's central thesis about a 'containment gap' is fully supported by the data showing low isolation rates despite high enforcement and observation adoption.
Claim Tracker
AI-assessed
VentureBeat Pulse Research data (the source of the article itself). Finding 1 states: '53% of organizations have already had an agent security event, with 19% confirming an incident and 38% having identified a near-miss.'
VentureBeat Pulse Research data. Finding 3 explicitly confirms: 'isolation sits at 18%' among 93 respondents describing a posture, and reaches only 21% even among enterprises with agents fully in production.
VentureBeat Pulse Research data. Finding 3 states: '65% enforce scoped permissions at runtime and 56% monitor and log agent activity.'
Source 1 (Kiteworks AI Agent Security Funding Surge) confirms: 'Scoping agent privileges down to least-privilege access cut security incident rates from more than two-thirds of deployments down to below 20%.'
VentureBeat Pulse Research data. Finding 4 states: 'Asked to name a single primary security layer, 92% of those who answered named one of these provider-native offerings.'
VentureBeat Pulse Research data. Finding 2 explicitly states: '63% of enterprises report credential sharing somewhere — either agents mostly running on shared API keys and borrowed human or service-account credentials (37%), or a mixed fleet where some agents are scoped and many are not (34%).'
Ask AI about this story
// discussion
sign in to join the discussion
