
Throughout 107 enterprises, AI brokers are being given actual entry to techniques and information whereas the controls meant to include them lag behind. Greater than half have already had a confirmed agent safety incident or a near-miss; solely a couple of third give each agent its personal scoped id, and most brokers nonetheless share credentials; and solely three in ten isolate their highest-risk brokers. The safety stack is overwhelmingly borrowed from the mannequin suppliers and hyperscalers reasonably than purpose-built for brokers, spending stays a skinny slice of the safety funds, and enterprises are evenly cut up on whether or not their defenses are conserving tempo with AI-enabled attackers. The result’s an agent safety hole — autonomous brokers proliferating sooner than the id, isolation, and enforcement controls wanted to carry them.
This wave of VentureBeat Pulse Analysis examines how enterprises safe their AI brokers: what tooling they run, how they handle agent id and isolation, what has already gone incorrect, how a lot they spend, and whether or not they imagine their defenses are conserving tempo with AI-enabled attackers.
The central discovering is an agent safety hole — the space between the autonomy enterprises are granting their brokers and the controls in place to include them. Greater than half of organizations (54%) have already skilled a confirmed agent safety incident (18%) or a near-miss caught earlier than hurt (36%). The structural weak spot beneath these numbers is id: solely a couple of third (32%) give each agent its personal scoped, managed id, whereas the remainder report that some brokers share credentials or that brokers largely run on shared API keys and human or service-account credentials. When brokers share credentials, a single compromised or over-permissioned agent carries a large blast radius — and solely three in ten enterprises (30%) isolate their highest-risk brokers in sandboxes to certain that radius.
What makes the hole notable is how comfy enterprises are inside it. The safety stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, whereas the devoted agent-security specialists barely register — and satisfaction with that borrowed stack is excessive, averaging 4.2 out of 5. But spending stays a skinny slice of the safety funds, solely a 3rd of enterprises imagine their AI defenses are forward of AI-enabled attackers, and a transparent majority plan to alter tooling inside the 12 months. Enterprises are glad with controls they’re concurrently making ready to switch.
Methodology
VentureBeat fielded this survey as a part of its ongoing Pulse Analysis sequence, this instrument centered on enterprise agent safety — the tooling, id, isolation, and enforcement controls organizations use to safe autonomous AI brokers. Responses are filtered to organizations with greater than 100 staff (n=107; the survey’s smallest measurement band, 1–100 staff, is excluded), drawn from a single June 2026 wave. As a result of that is one wave reasonably than a pooled multi-month pattern, the report reads cross-sectionally and doesn’t infer month-over-month developments. A number of questions have been multiple-select, so these shares can sum to greater than 100%.
By function the pattern is senior and buyer-credible: 45% are last decision-makers for AI purchases and one other 30% recommenders or influencers. Managers (43%), particular person contributors (24%), VPs and administrators (15%), and the C-suite (11%) make up the seniority combine. By group measurement the pattern is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) staff lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Know-how/Software program is the most important trade at 23%, adopted by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%).
At 107 respondents the pattern is giant sufficient to learn directionally however ought to be handled as a directional sign reasonably than a exact measurement; it’s self-selected and isn’t a chance pattern. It skews towards the mid-market, so it’s best learn because the view from organizations actively standing up agent safety reasonably than from the most important operators.
Satisfaction scores are computed on the respondents who answered every ranking query; the general satisfaction rating displays 82 of the 107 certified respondents.
Discovering 1: The incidents are already right here
Greater than half have had an agent safety incident or near-miss
We requested whether or not organizations had skilled an agent safety incident — a confirmed breach, or a near-miss caught earlier than hurt. Most that run brokers in manufacturing had.
Discovering 1 — The incidents are already right here
42%
no such incident recognized
36%
sure — a near-miss caught earlier than hurt
18%
sure — a confirmed incident
5%
not relevant — no brokers in manufacturing; 2% don’t monitor this
That is the report’s defining quantity. Greater than half of organizations (54%) have already had an agent safety occasion — 18% a confirmed incident and 36% a near-miss caught earlier than it brought about hurt. Solely 42% report nothing, and a small the rest both run no brokers in manufacturing or don’t monitor such occasions. That so many report near-misses reasonably than solely confirmed incidents is telling: enterprises are catching issues, however they’re catching them near the sting. The controls examined in the remainder of this report — id, isolation, enforcement — are what decide whether or not the subsequent near-miss stays a near-miss.
Publicity scales with firm measurement, however containment doesn’t. The incident-or-near-miss price rises from 49% within the mid-market (corporations with 101-1,000 staff) to 63% at bigger enterprises (above 1,000 staff), whereas sandbox isolation of high-risk brokers falls from 35% to twenty%, and satisfaction with safety tooling drops from 4.36 to three.97. The organizations working probably the most brokers throughout probably the most techniques carry probably the most incidents and the least of the one management that bounds an incident’s blast radius.
Discovering 2: The id hole
Solely a 3rd give each agent its personal scoped id
We requested how enterprises handle the id of their AI brokers — whether or not every agent has its personal credentials, or brokers share them. Full per-agent id is the exception.
Discovering 2 — The id hole
48%
some brokers have scoped identities, however many nonetheless share credentials
32%
every agent has its personal scoped, managed id
32%
brokers largely run on shared API keys or human / service-account credentials
7%
not relevant — no brokers in manufacturing; 5% don’t know
Rolled collectively, the overlapping solutions present 69% of enterprises (74 of 107) with credential sharing someplace within the agent fleet. Id is the structural weak spot beneath the incidents. Solely a couple of third of enterprises (32%) give each agent its personal scoped, managed id — the precondition for least-privilege entry and clear attribution. Almost half (48%) say some brokers have scoped identities however many nonetheless share credentials, and one other 32% say brokers largely run on shared API keys or borrowed human and service-account credentials. (Respondents might describe a couple of sample throughout their agent fleet, so these overlap.)
The consequence is direct: when brokers share credentials, an over-permissioned or compromised agent can act with much more attain than supposed, and forensics after an incident can not cleanly inform which agent did what. The non-human id drawback — giving each agent its personal ruled id — is the only largest unfinished piece of enterprise agent safety.
Furthermore, an organization’s agent credential posture is correlated with incidents. Organizations with credential sharing anyplace within the fleet have been hit — with an incident or a near-miss prior to now twelve months — at 63.5% (47 of 74). Organizations the place each agent carries its personal scoped id have been hit at 40.9% (9 of twenty-two). The fully-scoped group is small, so for now the connection is an affiliation reasonably than confirmed causation, and the hole is concentrated within the mid-market — however inside a single survey, a twenty-three level distinction in incident price suggests significance.
Discovering 3: Observe and implement, however hardly ever isolate
Solely three in 10 sandbox their highest-risk brokers
We requested what a company’s agent safety posture seems like in apply — whether or not they observe, implement, isolate, or some mixture. The management that bounds harm is the least frequent.
Discovering 3 — Observe and implement, however hardly ever isolate
49%
implement — brokers have scoped identities and permissions, enforced at runtime
47%
observe — they monitor and log agent exercise, however runtime enforcement is proscribed
30%
isolate — high-risk brokers run sandboxed, with bounded blast radius if controls fail
6%
don’t know; 5% haven’t any devoted agent safety program but
Monitoring and enforcement are moderately frequent; containment shouldn’t be. Roughly half of enterprises observe agent exercise (47%) or implement scoped permissions at runtime (49%), however solely 30% isolate their highest-risk brokers in sandboxes that certain the blast radius when the opposite controls fail. That ordering is backwards from a defense-in-depth standpoint: statement tells you what occurred, enforcement tries to forestall it, however isolation is what limits the harm when prevention fails — and it’s the management enterprises have adopted least. Mixed with the id hole in Discovering 2, the image is of brokers which can be watched and permissioned however hardly ever boxed in, which is exactly the configuration through which a single failure propagates.
Discovering 4: Safety runs on borrowed, provider-native controls
Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register
We requested which agent safety tooling enterprises use, and which is their major layer. The reply favors the mannequin suppliers and hyperscalers over the devoted safety distributors.
Discovering 4 — Safety runs on borrowed, provider-native controls
51%
use OpenAI’s built-in guardrails; 36% Google Cloud controls; 35% Microsoft Azure (Purview / Copilot Studio DLP); 29% Anthropic’s managed-agent controls
13%
Microsoft Entra Agent ID; 10% AWS Bedrock Guardrails
8%
every makes use of open-source guardrails, Cloudflare, and Cisco; the devoted specialists (Palo Alto, CrowdStrike, Zenity, HiddenLayer, Lakera, Okta) sit in low single digits
82%
title a provider-native or hyperscaler management as their major agent safety layer
Enterprises are securing brokers with instruments that got here bundled with their fashions and clouds. OpenAI’s guardrails lead at 51%, adopted by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when requested to call their single major safety layer, 82% title one in every of these provider-native choices. The aim-built agent-security class — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Protection, Zenity, HiddenLayer, Test Level’s Lakera, Okta for AI Brokers, non-human id platforms — barely registers, every within the low single digits, and solely 5% run no devoted tooling in any respect. As with retrieval and analysis elsewhere on this sequence, the supplier bundle is profitable the default: enterprises attain first for the guardrails their platform ships, and the unbiased safety layer that may tackle the id and isolation gaps has not but been adopted at scale.
The provider-default sample is constant throughout each Q2 survey waves. In April–Might (n=110), utilization was led by the identical names — OpenAI’s controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with each devoted agent-security specialist at 3% or beneath and one in ten utilizing no devoted tooling in any respect. The frequent discovering from the 2 surveys: Enterprises are defaulting to the options supplied by the platform they’re utilizing, and the specialist class distributors have but to turn out to be large gamers right here.
(A notice on studying these shares. As described within the methodology part, the respondent pattern is self-selected and skews mid-market, and the utilization query counted each vendor or strategy a respondent has in place — so the figures measure presence within the safety stack reasonably than spending or exclusivity. Particular person vendor percentages subsequently carry all the same old pattern caveats. The structural sample, nevertheless, held throughout each Q2 waves on two in a different way worded questions: provider-native and hyperscaler controls lead, and devoted agent-security specialists stay in low single digits. Learn the person shares loosely and the sample with confidence.)
Discovering 5: And enterprises are comfy with it
Satisfaction is excessive, at the same time as incidents mount and id lags
We requested how glad enterprises are with their present agent safety tooling. The consolation is notably out of step with the publicity documented above.
Discovering 5 — And enterprises are comfy with it
4.2
common general satisfaction with present agent safety tooling, on a five-point scale
4.1
common worth for cash; ease of implementation trails barely at 3.9
54%
have nonetheless already had a confirmed incident or near-miss (Discovering 1)
32%
give each agent its personal scoped id (Discovering 2)
Satisfaction with agent safety tooling is excessive — 4.2 out of 5 general, and 4.1 for worth for cash — among the many most constructive readings on this sequence. That’s the placing half: enterprises are extremely glad with a stack that’s largely borrowed supplier guardrails, though greater than half have already had an incident or near-miss and solely a 3rd give their brokers scoped identities. The consolation seems to relaxation on the comfort and low friction of provider-native controls reasonably than on demonstrated containment. It’s a false consolation within the making — the identical enterprises expressing satisfaction are, as Discovering 8 reveals, a transparent majority planning to alter tooling inside the 12 months, which suggests the boldness is thinner than the rating implies.
Discovering 6: Budgets haven’t caught up
Most spend beneath a tenth of the safety funds on brokers
We requested what share of the safety funds enterprises allocate to securing AI brokers. For a quick-emerging danger, the allocation is modest.
Discovering 6 — Budgets have not caught up
46%
allocate 6–10% of their safety funds to agent / AI safety — the most typical band
26%
allocate 1–5%; an extra 8% beneath 1%
9%
allocate greater than 25%
Spending on agent safety continues to be a skinny slice. The commonest allocation is 6–10% of the safety funds (46%), and a 3rd of enterprises (34%) spend 5% or much less; solely 1 / 4 (24%) commit greater than a tenth. Given the incident price in Discovering 1 and the id and isolation gaps in Findings 2 and three, the funds seems like a lagging indicator — the chance has arrived sooner than the funding to handle it. The enterprises spending greater than a tenth of their safety funds on brokers are a definite minority, and they’re seemingly those constructing the scoped-identity and isolation controls the remainder haven’t.
Solely a 3rd assume their AI defenses are forward of AI-enabled attackers
We requested how enterprises assess the stability between their AI-enabled defenses and AI-enabled attackers. Confidence is way from settled.
Discovering 7 — The arms race is even, at greatest
35%
our AI-enabled defenses are forward
21%
attackers utilizing AI are forward of our defenses
21%
too early to inform; 6% don’t know
Enterprises are cut up on whether or not they’re profitable. Solely a couple of third (35%) imagine their AI-enabled defenses are forward of AI-enabled attackers; the remainder are much less positive — 32% name it roughly even, 21% assume attackers are forward, and one other 21% say it’s too early to inform. Taken collectively, a transparent majority (53%) price the stability as even or tilted towards the attacker. That uncertainty sits uneasily beside the excessive satisfaction of Discovering 5: enterprises are content material with their tooling but unconvinced it’s profitable the competition it exists to win. In a website the place the offense can also be compounding with AI, a fair race shouldn’t be a snug place to be.
Discovering 8: A safety reshuffle is coming
Almost six in 10 plan to undertake or swap tooling inside a 12 months
We requested whether or not enterprises plan to undertake a brand new, extra, or alternative agent safety resolution, and which they’re contemplating. Few intend to face pat.
Discovering 8 — A safety reshuffle is coming
41%
haven’t any plans to alter
29%
plan to undertake or swap inside the subsequent 0–3 months
The safety stack shouldn’t be settled. Whereas 41% haven’t any plans to alter, a transparent majority (59%) intend to undertake a brand new, extra, or alternative agent safety resolution inside twelve months, and 29% inside the subsequent quarter — a powerful sign that, excessive satisfaction however, enterprises know the present stack is provisional. Incidents are what begin the shopping for cycle.
Amongst organizations which have been hit, 42.1% plan to undertake, add, or substitute agent safety tooling inside the subsequent ninety days, towards 14.0% of organizations with no incident — and after a confirmed incident it turns into majority conduct, at 52.6%. Getting hit additionally adjustments the risk evaluation: 33.3% of hit organizations say AI-armed attackers are forward of their defenses, towards 8.0% of the unhit. Expertise, on this information, is the strongest predictor of each urgency and pessimism.
The consideration set nonetheless leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), however the devoted safety distributors — Cloudflare, Cisco, Palo Alto, Okta, Test Level’s Lakera — draw early curiosity within the mid-to-high single digits, greater than their present footprint.
What the purchasing doesn’t but embody is the id layer particularly. Twelve % of the respondents embody an agent-identity product — Okta for AI Brokers, Microsoft Entra Agent ID, or a non-human id platform — anyplace of their consideration set, and among the many credential-sharing organizations which have already had an incident, id consideration is actually unchanged, at roughly one in ten. The management most immediately implicated by the incident information is the one largely lacking from the acquisition plans. Whether or not this wave hardens the provider-native default or lastly opens the door to purpose-built agent safety — the id and isolation controls the incidents name for — is the query this sequence will maintain monitoring.
The underside line: A safety hole that autonomy will take a look at first
Organizations with greater than 100 staff are giving AI brokers actual attain into techniques and information whereas securing them with controls constructed for one thing else. Greater than half have already had an incident or near-miss; solely a 3rd give each agent its personal scoped id, and most nonetheless share credentials; solely three in ten isolate their highest-risk brokers; and the stack doing this work is overwhelmingly borrowed from the mannequin suppliers and hyperscalers reasonably than purpose-built for brokers.
The uncomfortable pairing is confidence with publicity: satisfaction with the present tooling is among the many highest on this sequence, but spending is a skinny slice of the safety funds, solely a 3rd imagine their defenses are forward of AI-enabled attackers, and a transparent majority are already planning to switch what they’ve. At 107 respondents in a single wave it is a directional learn, skewed towards the mid-market — however the course is evident: agent adoption is working forward of agent safety, and the controls that matter most when one thing fails — scoped id and isolation — are those enterprises have constructed least. The agent safety hole shouldn’t be a protection drawback {that a} supplier guardrail will shut by itself; it’s a drawback of id, isolation, and enforcement constructed for autonomous software program. The open query for later waves is whether or not enterprises shut it intentionally — or whether or not a confirmed incident closes it for them.
Based mostly on survey responses from 107 certified enterprise respondents (100+ staff), drawn from a single June 2026 wave. It is a directional learn, not a exact measurement — the pattern is self-selected and skews mid-market, so it is best learn because the view from organizations actively standing up agent safety reasonably than from the most important operators. Respondents are senior and buyer-credible (45% last decision-makers, 30% recommenders/influencers), spanning managers by the C-suite, and drawn primarily from Know-how/Software program, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.

