Quick Facts

  • 54% of organizations have experienced a confirmed agent security incident or near-miss, with credential-sharing linked to a 63.5% incident rate.
  • 71% of enterprises say a quarter or fewer of their deployed “agents” can complete multi-step tasks without human intervention.
  • 57% of enterprises traced a confident but wrong AI answer to missing or inconsistent business context in the past six months.

Enterprises deployed AI agents before they built the controls to manage them. That is the central finding of VentureBeat Research’s five-part survey series published July 24, covering 573 qualified respondents across organizations with 100 or more employees.

The surveys, fielded in June 2026 under VentureBeat’s VB Pulse program, covered five control layers: identity, evaluation, cost telemetry, context, and orchestration. Every survey pointed in the same direction: deployment is running ahead of governance, visibility, and cost control.

Most “Agents” Are Not Agents

The research drew a hard line between marketing and reality. Seventy-one percent of enterprises said a quarter or fewer of their deployed “agents” can complete multi-step work on their own. Only 10% said true agents make up the majority of what they run.

Gartner has flagged the same problem, warning that calling AI assistants agents is a widespread misconception it calls “agentwashing.” A single-prompt chatbot with a human reviewing every answer requires none of the identity, evaluation, or orchestration controls a real multi-step agent demands. Most enterprises surveyed cannot clearly say which type they have deployed.

Security Is the Most Alarming Gap

More than half of organizations, 54%, have experienced a confirmed agent security incident or a near-miss caught before harm. Eighteen percent confirmed actual incidents; 36% reported near-misses.

Credential sharing is the clearest risk factor. Sixty-nine percent of companies let at least some agents share credentials, such as multiple agents operating under a single API key. Organizations that allow credential sharing anywhere experienced a security incident or near-miss at a 63.5% rate. Companies where every agent has its own scoped identity saw that rate fall to 40.9%.

Only about a third of surveyed organizations give each agent its own scoped identity. Sandbox isolation, the measure that limits damage when an incident occurs, is moving in the wrong direction: from 35% adoption to 20%. The problem scales with company size. For organizations with more than 1,000 employees, the incident rate stands at 63%, compared to 49% for those with 101 to 1,000 employees.

Evaluations Are Not Working

Half of organizations deployed an agent or AI feature in the past year that passed internal evaluations and then caused a customer-facing failure. A quarter saw it happen more than once. Only 5% of respondents say they fully trust automated evaluation today.

The most common reason for distrust is poor alignment with real-world outcomes, cited by 29% of respondents. Bias or inconsistency follows at 21%, lack of explainability at 18%, and data leakage or privacy concerns at 17%.

Enterprises are not slowing down in response. Sixty-six percent already permit some production deployment without human review or are building systems to do so within 12 months. That means autonomy is expanding while the evaluations meant to justify it remain unreliable.

Context Problems Produce Confident Errors

Fifty-seven percent of enterprises traced a confident but wrong AI agent answer to missing or inconsistent business context in the past six months. Thirty-one percent said it happened more than once.

Only 25% of respondents run a governed context layer in production. Thirty-four percent are building one. The remaining 41% have not started. Document retrieval is the default approach for 38% of enterprises, nearly double the next closest method. Companies are selecting retrieval systems based on ease of ingestion and operational simplicity, with retrieval accuracy ranking lower. The accuracy problem only surfaces after the system is already live.

Vendors Are About to Change

Across all five control layers, 57% to 68% of enterprises plan to switch vendors or add new ones within 12 months. Roughly a third plan to move within the current quarter. The research describes this as enterprises retrofitting to catch up with their own stated standards.

The 573 respondents are not observers. Eighty-one percent recommend or decide AI purchases at their organizations, making the gaps they identified directly tied to upcoming spending decisions.

Read more: VentureBeat Research: Where enterprise AI agent governance hasn’t caught up

This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.