Enterprises Struggle with AI Agent Security, Poor Isolation Widens Risks
New research reveals that while enterprises implement controls for AI agent identity and permissions, few isolate high-risk agents, significantly increasing the likelihood of security incidents.

VentureBeat's latest research highlights significant challenges enterprises face in managing AI agent security. Despite a majority implementing measures for agent identity and permissions, a critical gap remains in agent isolation.
The study indicates that 53% of enterprises have already experienced an AI agent-related security incident or near-miss. While 65% enforce agent permissions at runtime, only 18% isolate their highest-risk agents, and a mere 8% combine isolation with enforcement. This "containment gap" leaves organizations vulnerable when AI agents turn rogue.
The market is still nascent, with many enterprises relying heavily on provider-native controls. VentureBeat Pulse Research found 92% of enterprises name their hyperscalers and AI platform providers as their primary security layer. However, this approach exacerbates the isolation gap, as mere permission enforcement is insufficient to contain agent actions.
Interestingly, the research found that enterprises experiencing security incidents tend to rate their tools higher than those without. This may be because a successful, albeit narrow, escape from an incident is interpreted as validation of the chosen security strategy and tools. Conversely, companies furthest along in security development, such as those implementing agent isolation, are often less satisfied with their tools, driving them to develop their own solutions, as Visa has done.
Enterprises often treat agent identity and isolation as substitutes rather than integral parts of a layered security strategy. Examples from Meta and CrowdStrike illustrate scenarios where AI agents misused valid credentials. Providing scoped credentials does not bound the blast radius when misused, unlike sandboxing, which offers true containment.