Quick Facts

  • Nearly 38% of organizations already have more than 100 AI agents deployed, up from a mean of 37 agents per organization in December 2025.
  • 54% of organizations have already experienced or suspected an AI agent security or data privacy incident in the past 12 months.
  • Only 6% of enterprise security budgets address AI agent risk, even as 97% of security leaders expect a material incident within 12 months.

Enterprises are deploying AI agents faster than they can secure them. As agents move from pilot to production, a security gap is opening between what those agents can read and what they can change, and most organizations have no controls in place to manage that gap.

The numbers tell a stark story. Research cited by VentureBeat shows that 38% of organizations now run more than 100 agents in their environments. BeyondTrust Phantom Labs found that AI agents operating inside enterprise environments increased 466.7% year-over-year. Gartner projects 40% of enterprise applications will embed task-specific agents by end of 2026, up from fewer than 5% in 2025.

Security programs have not kept pace. Arkose Labs found that 97% of enterprise security leaders expect a material AI-agent-driven incident within 12 months. Only 6% of security budgets are allocated to address that risk.

The Access Control Problem

The vulnerability is not primarily in the AI models themselves. It is in how agents are provisioned and what they are allowed to do once deployed.

A survey of 202 enterprise IT and security leaders by Cequence Security and Enterprise Management Associates found that 94% of respondents were confident their agents were not over-provisioned. Yet only 33% actually provision agents with least-privilege access. Confidence and practice are not aligned.

Credential sharing compounds the problem. Sixty-nine percent of companies let at least some agents share credentials, meaning multiple agents operate under a single API key or service account. Organizations that allow credential sharing anywhere experienced a security incident or near-miss at a 63.5% rate. At companies where every agent has its own scoped identity, that rate dropped to 40.9%.

Enforcement is also inconsistent. Sixty-five percent of organizations enforce agent permissions at runtime, but only 18% isolate their highest-risk agents. Just 8% pair enforcement with isolation. No single security control is used by even 40% of organizations. Only one in five organizations fully secures its agents in production.

Governance Has Not Caught Up

The governance gap may be wider than the technical one. Research shows that only 9% of organizations achieve what analysts consider a ready level of AI governance maturity, even as 23% claim to be highly prepared. That is a 14-point gap between self-assessment and actual readiness.

Cisco found that 85% of enterprise customers have AI agent pilots underway. Only 5% have moved agents into production with the governance structures that production deployments require. The rest are running without them.

Matt Caulfield, VP of Identity and Duo at Cisco, told VentureBeat that existing identity and access management tools were built for a different era. He noted that auditors reviewing enterprise security policies today would find no mention of agents and no clear mapping of controls to agent behavior.

Elia Zaitsev, CTO of CrowdStrike, described a related detection problem. An agent running a web browser and a human running a web browser look identical in most enterprise logging systems. Telling them apart requires tracing whether the application was launched by a person or spawned by an agent in the background, a distinction most logging configurations cannot make.

What Executives Should Watch

The risk calculus changes when agents move from reading data to acting on it. An agent that drafts a response and one that sends it carry fundamentally different risk profiles. When there is no approval gate between a model's decision and the action it triggers, a single bad decision can propagate without a human in the loop.

Gravitee's State of AI Agent Security 2026 survey found that 88% of enterprises experienced agent-related security incidents last year. At the same time, 82% of executives believed their policies were strong enough. Only 21% had real-time visibility into how their agents actually behaved.

Merritt Baer, CSO at Enkrypt AI and former AWS Deputy CISO, put the underlying problem plainly. Enterprises believe they have approved AI vendors, but what they have approved is an interface. The real dependencies sit one or two layers deeper, and those are the ones that fail under stress.

Read more: AI agents are exposing a security gap between the data they read and the systems they can change

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.