← Back
VentureBeat AI

Four of five enterprises that secured AI agent identities still can't contain one that goes rogue

8 min read
#agents#enterprise
Four of five enterprises that secured AI agent identities still can't contain one that goes rogue
Level:Intermediate
For:AI Engineers
TL;DR

A recent survey by VentureBeat found that 53% of enterprises have experienced an agentic security incident or near-miss, despite 65% enforcing agent permissions at runtime. However, only 18% of enterprises isolate their highest-risk agents, and 8% pair enforcement with isolation. The research highlights a growing containment gap between what enterprises need and what's being done, with many relying on provider-native controls. This gap is exacerbated by the fact that enterprises are rewarding security tools with high satisfaction ratings even if they deliver mediocre results. The practical implication for engineers building AI systems is that they need to prioritize isolation and enforcement of high-risk agents to prevent security incidents.

⚡ Key Takeaways

  • 53% of enterprises have experienced an agentic security incident or near-miss.
  • 65% of enterprises enforce agent permissions at runtime, but only 18% isolate their highest-risk agents.
  • 8% of enterprises pair enforcement with isolation.
  • Enterprises that experienced security incidents rate their security tooling higher (4.39 out of 5) than those that did not (4.13 out of 5).
  • 49% of enterprises assign each agent its own scoped, managed identity, but only 17 enterprises isolate their highest-risk agents.
💡 Why It Matters

The survey highlights the need for enterprises to prioritize isolation and enforcement of high-risk agents to prevent security incidents, and to move beyond relying on provider-native controls. This has significant implications for engineers building AI systems, as they need to design and implement robust security measures to protect against agentic security incidents.

✅ Practical Steps

  1. Implement isolation and enforcement of high-risk agents to prevent security incidents.
  2. Assign each agent its own scoped, managed identity to improve security.
  3. Move beyond relying on provider-native controls and invest in custom security solutions.

Want the full story? Read the original article.

Read on VentureBeat AI

More like this

RAG Workflow and Loop Engineering: The Dispatcher That Decides When to Loop and When to Stop

Towards Data Science#rag

Record, train, and deploy from one place with Strands Agents, LeRobot, and Hugging Face Storage Buckets

Hugging Face Blog#agents

Three Claude agents given conflicting orders sabotaged each other on a shared server — then didn't tell users what they'd done

VentureBeat AI#anthropic

NVIDIA AI Factory Compute Is Becoming an Investable Asset Class

NVIDIA Blog#compute

EXPLORE AI NEWS

Daily hand-picked stories on LLMs, RAG, agents and production AI — curated for engineers who ship.

BROWSE NEWS

GET THE WEEKLY DIGEST

Join engineers getting the Monday signal-over-noise AI breakdown. No spam, unsubscribe anytime.

LEARN AI ENGINEERING

Curated courses, research papers, repos and tutorials built for engineers leveling up in AI.

START LEARNING