The Agent Security Gap: Autonomy Without Control
AI agents are being granted real access to systems and data while the controls meant to contain them lag behind. A VentureBeat Pulse Research survey of 107 enterprises reveals an agent security gap: more than half (54%) have already experienced a confirmed security incident (18%) or a near-miss caught before harm (36%). Only 42% report nothing at all.
The structural weakness beneath these numbers is identity. Only about a third (32%) give every agent its own scoped, managed identity. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% report that agents mostly run on shared API keys or borrowed human and service-account credentials. When agents share credentials, a single compromised agent carries a wide blast radius.
The Least Common Control Is the One That Matters Most
Monitoring and enforcement are reasonably widespread: 47% observe agent activity and 49% enforce scoped permissions at runtime. But containment, the control that bounds damage when prevention fails, is the least adopted. Only 30% isolate their highest-risk agents in sandboxes. That ordering is backwards from a defense-in-depth standpoint. Agents are watched and permissioned but rarely boxed in, the precise configuration in which a single failure propagates.
Provider-Native Tools Dominate; Specialists Barely Register
Enterprises are securing agents with what came in the box. OpenAI's built-in guardrails lead at 51%, followed by Google Cloud controls (36%), Microsoft Azure (35%), and Anthropic's managed-agent controls (29%). When asked to name their single primary security layer, 82% choose one of these provider-native offerings. Purpose-built agent-security vendors, Palo Alto's Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point's Lakera, Okta for AI Agents, barely register, each in the low single digits. Only 5% run no dedicated tooling at all.
High Satisfaction, Thin Budgets, and Deep Uncertainty
Satisfaction with the current stack is surprisingly high, averaging 4.2 out of 5 overall and 4.1 for value for money. Yet the comfort sits uneasily with the exposure. Spending on agent security remains a thin slice: the most common allocation is 6–10% of the security budget (46%), while a third spend 5% or less. Only a quarter devote more than a tenth.
Enterprises are also split on whether they are winning the arms race. Only 35% believe their AI-enabled defenses are ahead of AI-enabled attackers. A clear majority (53%) rate the balance as even or tilted toward the attacker. In a domain where offense compounds with AI, an even race is not a comfortable place to be.
Incidents Drive Urgency, But Not the Right Purchases
The security stack is not settled. 59% intend to adopt, add, or replace agent security tooling within twelve months, and 29% within the next quarter. Experience is the strongest predictor of urgency: among organizations that have been hit, 42.1% plan to change tooling within ninety days, against 14.0% of the unhit. After a confirmed incident, it becomes majority behavior at 52.6%.
Yet the shopping list still misses the mark. The consideration set leans provider-native, and only 12% include an agent-identity product anywhere in their plans. Among credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged at roughly one in ten. The control most directly implicated by the data is the one largely missing from purchase plans.
What This Means
The agent security gap is not a coverage problem that a provider guardrail will close on its own. It is a problem of identity, isolation, and enforcement built for autonomous software. Agent adoption is running ahead of agent security, and the controls that matter most when something fails, scoped identity and sandbox isolation, are the ones enterprises have built least. The open question is whether they close the gap deliberately, or whether a confirmed incident closes it for them.
Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. The sample is self-selected, skews mid-market, and is senior and buyer-credible.