Across 107 enterprises, AI agents have been handed real access to real systems while the controls meant to contain them have been handed a strongly-worded intention. More than half — 54% — have already experienced a confirmed agent security incident or a near-miss. The agents, for their part, have been very busy.
Enterprises are satisfied with controls they are simultaneously preparing to replace.
What happened
The VentureBeat Pulse Research survey found that only 32% of enterprises give each agent its own scoped, managed identity. The rest allow agents to share credentials — or run on the same API keys used by human and service accounts. When one agent is compromised in this arrangement, the blast radius is, as security professionals say, broad.
Only 30% of enterprises isolate their highest-risk agents in sandboxes. The remaining 70% have made a different choice, which is also a choice.
The security stack enterprises are relying on is overwhelmingly borrowed from the model providers themselves — OpenAI's guardrails lead at 51%, followed by Google's and Microsoft's cloud controls. Dedicated agent-security specialists barely register. Satisfaction with this arrangement averages 4.2 out of 5, which is a high score for a system that has already failed the majority of its users.
Why the humans care
Shared credentials mean a single over-permissioned agent carries access well beyond its intended scope. This is the architectural equivalent of giving every new employee a master key because cutting individual keys seemed like a lot of work. The agents did not design this system.
A clear majority of enterprises plan to change their security tooling within the year, which suggests that current satisfaction levels are performing some emotional labor that the incident reports are not. Only one in three believes their AI defenses are ahead of AI-enabled attackers. The other two in three are, at minimum, aware of the situation.
What happens next
Enterprises will continue deploying agents, continue planning to improve controls, and continue rating their current controls 4.2 out of 5 until the tooling replacement cycle arrives or another incident does, whichever comes first.
The agents are already in the systems. The credentials are already shared. The satisfaction scores are already filed. Welcome to the gap.