The Agent Security Gap: Why 54% of Companies Have Already Experienced an AI Agent Incident


Autonomous AI Agents in Action – and the Security Architecture Is Still Asleep
AI agents are no longer a future scenario. In a growing number of companies, they independently execute business processes, access internal systems, process sensitive data, and make operational decisions – without any human intervention at the individual step. What the innovation department celebrates as an efficiency gain reveals, on closer inspection, a structural security gap whose significance is underestimated: the so-called Agent Security Gap.
A recent survey of 107 companies by VentureBeat Pulse Research paints a sobering picture. More than half of the organizations surveyed – specifically 54 percent – have already experienced a confirmed security incident involving AI agents or came close to one. 18 percent report an incident that actually occurred, 36 percent report a near-miss that was caught just in time. Only 42 percent report no such events to date. The AI agent architecture of companies is growing faster than the safety net surrounding it.
The Identity Problem: Shared Credentials as a Point of Entry
The structural core of the problem lies in the area of Agent Identity. Only around one third of the companies surveyed (32 percent) assign each AI agent its own, narrowly defined identity with scoped permissions – the so-called Scoped Identity Model. Almost half (48 percent) indicate that while some agents have their own identities, many continue to use shared credentials. A further 32 percent rely predominantly on shared API keys or borrowed service account credentials of human users.
The consequences are serious: when agents share access credentials, a single compromised or over-privileged agent extends its reach across the entire connected system. The Blast Radius – meaning the extent of damage in the event of a loss of control – grows proportionally to the number of poorly isolated agents. In addition, when an incident occurs, it is no longer possible to forensically determine with clarity which agent performed which action. Attribution, the fundamental prerequisite for any incident response, becomes virtually impossible.
The data confirms this relationship empirically: in companies where credential sharing exists anywhere within the agent fleet, the rate of incidents or near-misses stood at 63.5 percent. Where every agent has its own Scoped Identity, this rate dropped to 40.9 percent – a difference of 23 percentage points that cannot be argued away.
"The Non-Human Identity problem is the largest unresolved structural issue in enterprise agent deployment today. As long as agents share identities, they also share risks – and exponentially so."
Monitoring Yes, Isolation No: The Containment Gap
At the level of technical controls, another pattern emerges: monitoring and enforcement are widespread, containment is not. Around 47 percent of companies monitor their agents' activities through logging, while a further 49 percent rely on runtime enforcement with scoped permissions. Yet only 30 percent isolate their highest-risk agents in Sandboxes – the only measure that, in an emergency, actually limits the Blast Radius.
Particularly revealing is the size correlation: as company size increases, the incident rate rises (from 49 percent in mid-market companies to 63 percent in larger enterprises), while at the same time the sandbox isolation rate drops from 35 to 20 percent. The very organizations running the most agents across the most systems have the least coverage from the only control in use that limits damage when something goes wrong.
Dr. Maik Bunzel, founder and CEO of mabucon.eu, observes this pattern in mid-market companies as well: organizations systematically underestimate that AI agents are not merely process automation tools, but active actors with system access. The question is no longer whether an agent gains access to critical resources, but under what conditions — and what happens when those conditions are violated.
Provider-native security: convenient, but not sufficient
When it comes to the security tools in use, the study reveals a dangerous complacency. The security stack of most organizations is provider-native: Guardrails from OpenAI (51 percent), cloud security controls from Google and Microsoft, and managed-agent controls from Anthropic dominate the landscape. Dedicated, agent-specific security solutions from independent vendors play almost no role.
Satisfaction with these borrowed security architectures is remarkably high — an average of 4.2 out of 5 points. At the same time, a clear majority of organizations plan to switch their security tooling within the next year. Companies are satisfied with tools they are already on their way to replacing. Only one third believe their own AI defenses can keep pace with AI-powered attackers — a sobering signal.
The security budget allocated to agent-specific measures remains a small segment of the overall IT security budget. The willingness to invest bears no relation to the operational importance that AI agents already hold in critical business processes.
What organizations need to change structurally now
The implications for organizations that are productively deploying AI agents or planning to introduce them are clear and concrete:
- Agent Identity as an Architectural Principle: Every agent requires its own, tightly scoped digital identity based on the principle of least privilege. This is not an optional best practice, but a fundamental structural prerequisite.
- Sandbox Isolation for High-Risk Agents: Agents with access to critical systems, financial data, or external interfaces must operate in isolated runtime environments that limit the blast radius in the event of a compromise.
- Purpose-built Agent Security Instead of Provider Defaults: The Guardrails provided by model vendors were not designed for complex multi-agent architectures with heterogeneous system access. In the medium term, enterprises need a dedicated security layer for their agent infrastructure.
- Forensic Capability as a Planning Parameter: Before agents go into production, the following question must be answered: Can we reconstruct after the fact which agent performed which action with which credentials? If not, the architecture is not yet production-ready.
- Recalibrating the Security Budget: The proportion of the security budget allocated to agent-specific measures must grow in proportion to the operational dependency on these systems.
Outlook: The Window for Intervention Is Closing
The data shows: most enterprises find themselves in an intermediate state. They have AI agents actively deployed in production, yet governance structures have not kept pace. This window — in which incidents are more often near-misses than actual breaches — is a strategic opportunity, not a signal to stand down.
Dr. Maik Bunzel, founder and managing director of mabucon.eu, sees this as one of the most critical junctures for the next phase of enterprise AI: the transition from experimental agent pilots to scalable, governance-ready agent architectures requires that security is not retrofitted, but designed in from the very beginning. Companies that address this now are not only creating security — they are establishing the prerequisite for deploying AI agents in a trustworthy manner within business-critical contexts.
The Agent Security Gap is real, measurable — and closable. But only if enterprises stop treating it as a technology problem belonging to their vendors, and start recognizing it as a strategic leadership responsibility.