Visa President of Technology Rajat Taneja explained how Anthropic’s Mythos model was connected to Visa’s proprietary payment network during VB Transform 2026. The model turned a minor weakness into a functional exploit chain, while Visa open-sourced the harness used to manage its security testing.
The example highlights what is possible when an organization has the engineering expertise to act on the vulnerabilities it discovers. However, most companies have not reached that level of AI agent security maturity. More than half of businesses—53%—have already experienced a security incident or near miss involving an AI agent. Although 65% enforce agent privileges at runtime, only 18% isolate their highest-risk agents, and just 8% combine runtime enforcement with isolation.
Relying primarily on provider-native security controls is widening this gap. VentureBeat Pulse Research, conducted in July, found that 92% of companies identifying a primary security layer rely on hyperscalers or AI platform providers.
Six surveys have been completed since January, including responses from 440 eligible corporate security professionals. The key takeaway is clear: The gap between the containment capabilities companies need and the protections they have deployed is growing. In many cases, organizations are investing in AI agents without addressing the security risks that could threaten those deployments and their broader AI strategies.
AI Agent Security Satisfaction Does Not Match Incident Data
The research shows that companies often give higher scores to the security tools they know best, even when those tools deliver limited results. Three findings from the raw data challenge that assumption and underscore how immature the AI agent security market remains.
Companies that experienced incidents rated their security tools more highly than companies that did not.
Last month’s survey found that 46 companies had experienced a confirmed incident or near miss and subsequently rated their security tools. Their average satisfaction score was 4.39 out of 5. By comparison, 30 of the 55 companies that reported no incidents rated their tools at an average of 4.13. Organizations appear to give security tools a trust premium when those tools help prevent or contain a breach.
This pattern is a sign of an emerging market in which real-world protection can outweigh brand positioning, marketing and other forms of persuasion. In both June and July, near misses outnumbered confirmed incidents by a 2-to-1 ratio, suggesting that companies are often identifying threats at the last possible moment. Organizations interpret these narrowly avoided incidents as validation of their security strategies and tools.
Seven months of data show how quickly enterprise security teams are turning to new tools to identify and stop intrusions before attackers can access sensitive systems. VentureBeat believes the rescue effect is influencing satisfaction scores. The 4.13 average among unaffected companies represents the opposite outcome: Tools that have not been tested in a real incident may lose credibility rather than gain it.
VentureBeat also found that 14 of the 17 companies that quarantined their highest-risk agents gave their security tools an average rating of 4.00. Companies that did not use agent isolation reported a higher average rating of 4.35. Organizations closest to implementing meaningful AI agent security are the least satisfied with their tools. That dissatisfaction may be what drives engineering initiatives such as Visa’s.
Four out of five companies that implemented agent identity controls did not create isolation.
Of the 116 companies surveyed in July, 57—or 49%—assigned each agent its own scoped, managed identity. One month earlier, VentureBeat’s June survey found that only 32% of companies were assigning individual identities to their agents. The 17-point increase in July was the fastest single-month gain recorded in the series.
Despite this progress, 63% of companies still reported sharing credentials somewhere across their agent fleets. Of the 57 companies assigning individual identities, only 11 also used agent isolation.
This ratio helps explain why the AI agent containment gap continues to widen despite improvements in identity management. Companies are treating identity and isolation as substitutes, but they are complementary layers in a secure, multi-layered AI platform.
Two cases covered by VentureBeat illustrate why the distinction matters. Meta’s rogue AI agent passed background checks before the March exposure was contained. At his RSAC 2026 keynote, CrowdStrike CEO George Kurtz also disclosed that agents at Fortune 50 companies had rewritten their own security policies using valid credentials. Scoped credentials do not limit an agent’s effective reach if those credentials are misused. Sandboxing and isolation are still necessary.
The incident rate among companies enforcing agent permissions without isolation was 58%.
In the July survey, 53 companies reported enforcing scoped permissions at runtime without isolating their agents. Of those companies, 31 had already experienced an AI agent security incident or near miss. That 58% incident rate was five points higher than the overall sample average of 53%.
Companies operating within the containment gap are experiencing more security problems than those with both enforcement and isolation controls.
Amy Chan, Director of AI Threat Intelligence and Security Research at Cisco, presented related research during the Transform Agent Security Panel. Cisco conducted 6,986 multi-turn attacks against 15 leading models and found that attackers who adapted to the full conversation achieved breakthrough rates of up to 88.3%. Single-turn red-team testing missed these attacks. Adaptive attackers can bypass guardrails and reach the underlying architecture, illustrating the risk of relying on enforcement without containment.
VentureBeat’s Q1 Pulse survey identified similar structural weaknesses. Unauthorized access to tools or data ranked as the most feared AI failure mode across all Q1 surveys, rising from 42% in January to 50% in March. In the April-May survey, only 4% of companies said they were comfortable relying exclusively on model guardrails. Organizations recognized the need for external controls and prioritized enforcement over containment.
Companies Adopted Runtime Enforcement Faster Than Expected, but Isolation Barely Changed
In the April-May survey, VentureBeat asked 109 companies how they expected to control agent behavior by the end of 2026. Thirty percent predicted runtime enforcement, 14% expected sandboxed execution, and 32% anticipated model-level guardrails.
By July, 65% of companies reported using runtime enforcement—more than twice the forecast. However, only 18% had implemented or piloted agent quarantine, roughly matching the earlier projection. Companies adopted easier-to-deploy controls at twice the expected rate, while more difficult isolation measures progressed at approximately the predicted pace.
The comparison is directional rather than precise. The April survey asked respondents to select one primary control mechanism, while the July survey allowed multiple responses.
AI Security Provider Lock-In Accelerated Throughout 2026
Provider-native platforms were already the leading security option in April and May, when seven out of 10 companies identified them as their primary tools. By June, 82% of respondents named a primary AI agent security layer. That figure rose to 92% in July.
OpenAI Guardrails led adoption at 44%, followed by Microsoft Azure at 42%, Anthropic Managed Agent Control at 37% and Google Cloud at 31%. Cloudflare accounted for 11%, while Cisco reached 9%. Dedicated AI security vendors competed for the remaining share.
The identity tools most closely associated with the credential-sharing gap included Microsoft Entra Agent ID at 7%, followed by Okta for AI agents, non-human identity platforms and runtime sandbox tools at 3% each.
CrowdStrike CTO Elia Zaitsev told VentureBeat at RSAC 2026 that observing agent behavior is a solvable problem, while inferring intent is not. Provider bundles demonstrate that distinction: They make monitoring and policy enforcement easier without necessarily providing effective containment.
74% Plan to Replace the AI Security Tool They Rated Most Highly
Security-tool satisfaction continued to rise as companies gained experience defending against AI agent attacks. The average score reached a series high of 4.29 out of 5 in July, up from 4.2 in June.
Despite those high satisfaction scores, 74% of respondents planned to replace their primary tool within 12 months, up from 59% in June. Only 26% planned to make no changes.
VentureBeat believes early adopters are seeking deeper visibility into AI agent security and resilience. That knowledge gap is creating churn in a young market. The data also helps explain the apparent contradiction: 92% of companies that named a primary security layer selected a provider-native platform, while the 4.29 satisfaction score may primarily reflect how easy it is to activate provider guardrails—not how effectively those controls prevent incidents.
Companies Closest to AI Threats Have the Lowest Confidence
In June, respondents said defenders held an advantage over attackers by a margin of 35% to 21%. By July, the gap had disappeared, with both sides at 30%.
Among companies that had experienced an attack, 39% said attackers had the upper hand. Only 20% of companies without an incident shared that view. Pessimism nearly doubled after an attack, but organizations’ purchasing behavior remained largely unchanged.
Only 10% of companies included Agent ID products in their evaluation set. Runtime sandbox adoption stood at 6%, regardless of whether an organization had previously experienced an incident. VentureBeat identified the same blind spot in its June data. Although the terminology shifted from “agent security gap” to “containment gap,” companies’ technology-shopping behavior remained unchanged.
Methodology
The attitude question was answered by 93 of 116 eligible July respondents. The 18% isolation figure represents companies that were actively running or piloting agents. Of the 25 companies that selected “No Posture,” 23 were still evaluating agents, had an unknown agent status or had no deployment plans, meaning they had little established security posture.
The April-May, June and July surveys were independently fielded waves rather than one continuous tracking series. Month-over-month comparisons should therefore be interpreted as directional indicators, not precise measurements of change.
Sample sizes also vary by question. The identity question covered all 116 respondents. The isolation question covered 93 respondents who provided posture information. The satisfaction comparison of 4.39 versus 4.13 was calculated from the 76 respondents who rated their security tools.
Conclusion
A cross-sectional VentureBeat survey analysis of company respondents in July found that organizations are deploying AI agents faster than they are implementing the controls needed to secure them—and, in many cases, they are doing so intentionally. Three waves of security-specific data point to a widening knowledge and containment gap.
Enterprises continue to assign scoped identities to AI agents and treat those identities as a form of containment. That assumption is incorrect, and incident data reinforces the point. Of the 57 companies that implemented individual agent identities, 46 did not create meaningful separation. The 58% incident rate among companies enforcing permissions without isolation is the clearest evidence that identity alone is insufficient.
AI agent security requires layered protection that combines managed identities, runtime enforcement, monitoring and isolation. The next survey wave will show whether organizations respond by engineering stronger containment controls or continue to rely on provider-native guardrails and scoped credentials.
Source: venturebeat.com


