Four of five enterprises that secured AI agent identities still can't contain one that goes rogue
A recent survey by VentureBeat found that 53% of enterprises have experienced an agentic security incident or near-miss, despite 65% enforcing agent permissions at runtime. However, only 18% of enterprises isolate their highest-risk agents, and 8% pair enforcement with isolation. The research highlights a growing containment gap between what enterprises need and what's being done, with many relying on provider-native controls. This gap is exacerbated by the fact that enterprises are rewarding security tools with high satisfaction ratings even if they deliver mediocre results. The practical implication for engineers building AI systems is that they need to prioritize isolation and enforcement of high-risk agents to prevent security incidents.
⚡ Key Takeaways
- 53% of enterprises have experienced an agentic security incident or near-miss.
- 65% of enterprises enforce agent permissions at runtime, but only 18% isolate their highest-risk agents.
- 8% of enterprises pair enforcement with isolation.
- Enterprises that experienced security incidents rate their security tooling higher (4.39 out of 5) than those that did not (4.13 out of 5).
- 49% of enterprises assign each agent its own scoped, managed identity, but only 17 enterprises isolate their highest-risk agents.
The survey highlights the need for enterprises to prioritize isolation and enforcement of high-risk agents to prevent security incidents, and to move beyond relying on provider-native controls. This has significant implications for engineers building AI systems, as they need to design and implement robust security measures to protect against agentic security incidents.
✅ Practical Steps
- Implement isolation and enforcement of high-risk agents to prevent security incidents.
- Assign each agent its own scoped, managed identity to improve security.
- Move beyond relying on provider-native controls and invest in custom security solutions.
Want the full story? Read the original article.
Read on VentureBeat AI ↗