53% of enterprises across 116 surveyed have already experienced an agent security event or near-miss. More than half run agentic AI in production today, another 27% are piloting. The incidents are scaling with the deployments, and the defenses are not keeping pace: 30% of enterprises now believe AI-armed attackers are ahead of their controls, exactly as many as believe the reverse.
The core finding is a containment gap, not a visibility gap. 65% of enterprises enforce scoped permissions at runtime. 56% monitor and log agent activity. Only 18% isolate their highest-risk agents in sandboxes, and just 8% pair enforcement with isolation. That ordering is wrong by any defense-in-depth standard. Observation tells you what happened. Enforcement tries to prevent it. Isolation limits the blast radius when prevention fails. The weakest layer is the one that matters most when the other two break. Identity is the second problem: 49% say each agent has its own scoped managed identity, but 63% report credential sharing somewhere in the fleet, and only 29% describe a fleet with no sharing anywhere.
The security stack doing this work is almost entirely borrowed. OpenAI guardrails lead at 44%, followed by Microsoft Azure at 42%, Anthropic managed-agent controls at 37%, and Google Cloud at 31%. 92% of enterprises naming a primary security layer name a hyperscaler or model provider. That dependence explains the churn signal: 74% plan to adopt, add, or replace agent security tooling within twelve months, even as satisfaction sits at a series high of 4.29 out of 5. Read the full report for the breakdown of how isolation rates differ between production and pilot deployments, and why near-misses outnumbering confirmed incidents two to one is not the reassuring statistic it appears to be.
[READ ORIGINAL →]