More than half of 107 surveyed enterprises have already experienced an AI agent security incident or near-miss, exposing a critical gap between deployment speed and security controls. The research reveals that autonomous agents are accessing real systems and data without adequate containment measures in place.

The security infrastructure lags behind agent proliferation. Only about one-third of enterprises assign each agent its own scoped identity. Most agents still share credentials, a practice that amplifies risk across systems. Only 30 percent isolate their highest-risk agents, leaving dangerous capabilities exposed alongside routine operations.

Enterprises rely heavily on security tools borrowed from model providers and hyperscalers rather than deploying purpose-built agent security solutions. This approach leaves gaps in identity management, access control, and behavioral enforcement. Agent security spending represents only a thin slice of overall security budgets, suggesting organizations underestimate the threat surface that autonomous systems create.

The divide on preparedness runs deep. Enterprises are evenly split on whether their defenses can keep pace with AI-enabled attackers. This uncertainty reflects a maturity gap. The identity, isolation, and enforcement controls needed to safely operate agents are not advancing at the speed agents themselves are being deployed.

The incident rate tells the real story. With 54 percent reporting actual breaches or close calls, enterprises are learning about agent risks through failure rather than prevention. The pattern mirrors early cloud security, where rapid adoption outpaced controls, leading to breaches. Agent security faces the same trajectory unless enterprises shift from borrowed defenses to purpose-built controls, enforce credential isolation, and allocate dedicated budget for agent-specific threats. The gap between capability and control continues widening as deployment accelerates.