Enterprises deploying AI agents in production environments are moving faster than their security practices can keep pace. A study of 116 enterprises reveals a stark gap between deployment speed and defensive maturity, with most organizations already experiencing agent-related security incidents or near-misses.

The data paints a troubling picture. More than half of surveyed enterprises have already suffered a confirmed agent security event or near-miss. Yet only two-thirds enforce scoped permissions at runtime, the baseline control that restricts what an agent can actually do. Worse, fewer than one in five enterprises isolate their highest-risk agents into separate environments. This containment gap represents the most dangerous vulnerability as autonomous systems scale across enterprise infrastructure.

Credential management practices remain dangerously loose. Nearly two-thirds of agent fleets share credentials across multiple agents and systems, a practice that amplifies blast radius if any single agent is compromised. Once attackers gain access through one compromised agent, they inherit permissions across the entire shared pool. This approach contradicts fundamental security principles applied to human users for decades.

The security stack itself reveals another vulnerability. Most enterprises borrow security tools directly from AI model providers like OpenAI or cloud hyperscalers like AWS and Microsoft, rather than deploying purpose-built agentic security platforms. These borrowed defenses were never designed for autonomous systems that make decisions at runtime without human review. Model provider security layers focus on API access control and usage monitoring, not on preventing agents from taking unintended actions within enterprise systems.

Confidence in agentic security has deteriorated rapidly. The survey shows that enterprises split evenly on whether AI-armed attackers have already outpaced their defenses. This parity represents a dramatic shift from traditional cybersecurity dynamics, where defenders typically maintain a confidence advantage. The erosion reflects rapid agent deployment without corresponding security architecture maturity.

The containment weakness deserves particular attention. Organizations isolate high-risk agents less than 20 percent of the time, meaning the most powerful or least-understood agents often run with full access to production systems. As autonomous systems grow in capability and autonomy, containment becomes exponentially more valuable. A compromised agent with full system access poses different risks than a compromised user account. The agent executes decisions at machine speed without pause for human verification.

Permission enforcement shows partial progress but incomplete adoption. Two-thirds of enterprises enforce scoped permissions, a positive signal. Yet one-third still run agents without runtime permission boundaries, giving them unconstrained access to whatever they can technically reach. This gap likely reflects the operational burden of defining proper scopes for novel agent capabilities that security teams barely understand.

The study suggests the security industry has not yet built specialized tooling for agentic risk. When enterprises default to model provider and hyperscaler solutions, they receive generic access controls rather than agentic-specific containment, isolation, and behavior monitoring. This gap creates an opportunity for specialized security vendors but reveals an immediate vulnerability for the 116 enterprises already running agents in production. The growing deployment velocity of agents now outpaces the maturation of defenses designed specifically to secure them.