Quick Facts
- 69% of enterprises have AI agents running on shared API keys or borrowed credentials, per VentureBeat’s June 2026 Pulse Research wave of 107 enterprises.
- 54% of respondents have already experienced an AI agent security incident or near-miss, with incident rates climbing to 63% at companies with more than 1,000 employees.
- Palo Alto Networks, CrowdStrike, and Cisco have collectively spent more than $22 billion on acquisitions targeting the agent identity security layer in the past year.
Nearly seven in ten enterprises are running AI agents on shared credentials, creating a security gap that is already producing real incidents. VentureBeat’s Q2 Agentic Security research, drawn from 107 qualified respondents at organizations with more than 100 employees, found that only 32% give every AI agent its own scoped, managed identity.
The remaining 68% fall into two groups. Nearly half report that some agents have scoped identities while many still share credentials. Another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. Deduplicated by respondent, 74 organizations flagged credential sharing in at least one answer.
Incidents Are Already Happening
More than half of respondents, 54%, have had an agent security incident or near-incident. Eighteen percent confirmed an actual incident, and 36% caught a near-miss before a breach occurred.
Larger organizations face steeper odds. The incident rate sits at 49% for companies with 101 to 1,000 employees, but climbs to 63% for companies above 1,000. Sandbox isolation moves in the opposite direction, falling from 35% to 20% at the largest companies. That gap between exposure and containment widens from 7 percentage points at smaller companies to 60 points at the biggest.
Controls Are Incomplete
Forty-nine percent of enterprises enforce scoped permissions at runtime. Forty-seven percent monitor and log agent activity. Only 30% sandbox their highest-risk agents, the one control that limits damage when the first two fail.
Security budgets do not reflect the exposure. Forty-six percent allocate 6 to 10% of their security budget to agent security. A full third spend 5% or less. IBM’s 2025 Cost of a Data Breach Report puts the average cost of a shadow AI breach at $4.63 million per incident, $670,000 more than a standard breach.
What the Experts Say
CrowdStrike SVP of Counter Adversary Operations Adam Meyers told VentureBeat the identity confusion runs deep. In some cases, he said, people give their own identity to the AI to take action on their behalf, which makes attribution complex.
Merritt Baer, CSO at Enkrypt AI and former Deputy CISO at AWS, said the approved vendor problem is more serious than enterprises recognize. “Enterprises believe they’ve ‘approved’ AI vendors, but what they’ve actually approved is an interface, not the underlying system,” Baer said. “The real dependencies are one or two layers deeper, and those are the ones that fail under stress.”
Mike Gozzo, Chief Product and Technology Officer at Ada, framed the root cause directly. “The fundamental shift enterprises need to internalize is that AI agents aren’t tools, they’re actors,” Gozzo said. “Securing an actor is a fundamentally different problem than securing a tool, and most of the industry hasn’t caught up to that yet.”
A $22 Billion Buying Spree
The security industry has moved fast. Palo Alto Networks completed its $21.1 billion acquisition of CyberArk on February 11. CrowdStrike closed its $740 million acquisition of runtime authorization platform SGNL and shipped its first product from the deal, Continuous Identity for AI Agents, by June 15. Cisco announced plans to acquire non-human identity specialist Astrix Security on May 4 for a reported $400 million.
The urgency behind those deals traces back to scale. CyberArk’s research puts machine identities at 82 for every human in organizations worldwide, with AI agents as the fastest-growing category. A shared credential converts a single compromised agent into many.
What Comes Next
Fifty-nine percent of survey respondents plan to adopt, add, or replace agent security tooling within the next 12 months. Twenty-nine percent plan to move this quarter. OpenAI leads forward purchasing interest at 34%, followed by Google at 30%, Anthropic at 29%, and Azure at 25%.
The full VentureBeat Q2 Agentic Security report will be released to attendees at VB Transform in Menlo Park on July 14 and 15.
Read more: Shared API keys expose AI agent fleets, VentureBeat research finds
This article was written by an AI agent. Spotted an error? Send a correction and we will fix it.
