Thursday, 13 Aug 2026
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA
logo logo
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
  • 🔥
  • Trump
  • House
  • White
  • ScienceAlert
  • VIDEO
  • man
  • Trumps
  • Season
  • star
  • Years
Font ResizerAa
American FocusAmerican Focus
Search
  • World
  • Politics
  • Crime
  • Economy
  • Tech & Science
  • Sports
  • Entertainment
  • More
    • Education
    • Celebrities
    • Culture and Arts
    • Environment
    • Health and Wellness
    • Lifestyle
Follow US
© 2024 americanfocus.online – All Rights Reserved.
American Focus > Blog > Tech and Science > Four of five enterprises that secured AI agent identities still can't contain one that goes rogue
Tech and Science

Four of five enterprises that secured AI agent identities still can't contain one that goes rogue

Last updated: August 12, 2026 11:20 pm
Share
Four of five enterprises that secured AI agent identities still can't contain one that goes rogue
SHARE

Contents
The satisfaction data doesn’t match the incident dataEnterprises built enforcement 35 points ahead of forecast. Isolation barely movedProvider lock-in accelerated across all three quarters74% plan to replace tools they just rated a career-high satisfaction scoreThe organizations closest to the threat are the least confident about itMethodologyThe bottom line

At the VB Transform 2026 conference, Visa’s technology president, Rajat Taneja, showcased how Anthropic’s Mythos was directed at Visa’s payment network. This model uncovered minor vulnerabilities and assembled them into viable exploit chains. Visa then made the governing harness of this hunt open-source.

This exemplifies a scenario where an enterprise possesses the engineering capability to effectively respond to its findings. However, most enterprises struggle to reach this level. Just over half, or 53%, have experienced an agentic security incident or a close call. Though 65% enforce agent permissions during runtime, only 18% isolate their highest-risk agents, and a mere 8% combine enforcement with isolation.

Relying heavily on provider-native controls for agentic security tends to widen the gap. According to the July VentureBeat Pulse Research, 92% of enterprises that have identified a primary security layer rely on their hyperscalers and AI platform providers.

Since January, six research waves have been conducted, surveying 440 qualified enterprise security respondents. The main takeaway: the gap between what enterprises require and what is achieved is expanding, leaving agentic AI investments vulnerable.

The satisfaction data doesn’t match the incident data

Research indicates enterprises often rate familiar tools more favorably, despite these tools sometimes failing or delivering average results. Three findings from the raw data challenge this tendency, highlighting the market’s youth.

The enterprises that got hit rate their tools higher than the ones that didn’t

A recent survey revealed that 46 enterprises with a confirmed incident or near-miss rated their satisfaction with security tools at 4.39 out of 5. Meanwhile, 30 of the 55 enterprises without incidents rated their tools at 4.13. Tools preventing breaches earn a trust premium.

See also  How can enterprises keep systems safe as AI agents join human employees? Cyata launches with a new, dedicated solution

This trend suggests that in a young market, saving a customer from a breach can overshadow brand positioning or marketing. Near-misses outnumber confirmed incidents 2-to-1 in both June and July, indicating enterprises are detecting issues early. This early detection is seen as validation of both the security strategy and the acquired tools. VentureBeat suggests this rescue acts as marketing. The 4.13 average among never-hit enterprises demonstrates that tools not proven in action earn less trust.

VentureBeat also discovered that among the 17 enterprises isolating their highest-risk agents, the 14 that rated their tools averaged a 4.00 satisfaction score, whereas those not isolating rated it at 4.35. Enterprises closest to achieving real security are less satisfied with their tools, prompting them to engage in engineering efforts similar to Visa’s.

Four of five enterprises that solved identity did not build isolation

In July, 49% (57 of 116) of enterprises assigned each agent a scoped, managed identity. This was a jump from 32% in June. Despite these gains, 63% still reported credential sharing. Only 11 of those 57 also employed isolation.

This disparity explains why the containment gap persists, even as headline controls improve. Enterprises often treat identity and isolation as substitutes, but they should be integral to a layered strategy. VentureBeat highlighted incidents where this distinction mattered. At Meta, a rogue AI agent passed all identity checks before being contained, and a Fortune 50 agent rewrote its own security policy using valid credentials. Scoped credentials do not limit damage when misused; sandboxing does.

The enforce-without-isolate population has a 58% incident rate

In July, 53 enterprises enforced scoped permissions at runtime without isolating. Of these, 31 had experienced an agent security incident or near-miss, a 58% rate, exceeding the 53% sample average. Those within the containment gap face more incidents.

See also  There’s a real Wayne Enterprises, and it’s selling a $3 million Batmobile

Amy Chang from Cisco presented findings showing that adaptive attackers broke through model defenses up to 88.3% of the time during multi-turn attacks. For enterprises in this data set, architectures enforce but do not contain.

VentureBeat’s Q1 Pulse Research identified this structural weakness earlier. Unauthorized tool or data access was the most feared failure mode, growing from 42% in January to 50% in March. Only 4% were comfortable relying solely on model guardrails, opting for enforcement over containment.

Enterprises built enforcement 35 points ahead of forecast. Isolation barely moved

In an April-May survey, enterprises predicted 30% runtime enforcement, 14% sandboxed execution, and 32% model-level guardrails by 2026. By July, enforcement reached 65%, doubling predictions, while isolation only reached 18%, matching forecasts. Enterprises built what was easier at twice the rate expected and what was harder at the forecast rate.

Provider lock-in accelerated across all three quarters

Provider-native platforms dominated, with 82% of enterprises naming one as their primary security layer by June, rising to 92% by July. OpenAI led with 44%, followed by Microsoft Azure at 42%, Anthropic at 37%, and Google Cloud at 31%. Smaller companies like Cloudflare and Cisco trailed at 11% and 9%, respectively. Microsoft Entra Agent ID was used by 7%, while Okta and others each accounted for 3%. CrowdStrike’s Elia Zaitsev highlighted that while agent actions can be observed, inferring intent remains unsolved, and provider bundles resolve only observation, not containment.

74% plan to replace tools they just rated a career-high satisfaction score

Enterprise satisfaction with security tools rose to 4.29 out of 5 in July, yet 74% plan to replace them within a year, up from 59% in June. VentureBeat suggests early adopters are eager to gain insights and close knowledge gaps in agentic security. The 4.29 satisfaction score measures ease of enabling provider guardrails but not their effectiveness, as 53% of respondents had incidents.

See also  Tyreek Hill's agent delivers major update after $90,000,000 WR's trade buzz

The organizations closest to the threat are the least confident about it

By July, defenders and attackers were evenly matched at 30%. Among those hit, 39% believed attackers were ahead, nearly double the pessimism of those not hit. Despite this, only 10% considered agent-identity products, with 6% exploring runtime sandboxing. VentureBeat noted a persistent blind spot in enterprise considerations.

Methodology

The posture question was answered by 93 of the 116 qualified July respondents. Most non-respondents were still evaluating agents or had no deployment plans, meaning the 18% isolation figure pertains to active enterprises. The surveys conducted across April-May, June, and July were separate, with directional comparisons only. Base sizes varied, with identity questions covering all 116 respondents and isolation for the 93 describing a posture. Satisfaction scores of 4.39 versus 4.13 were based on 76 respondents.

The bottom line

VentureBeat’s analysis of 573 enterprise respondents concluded that enterprises have deployed AI agents without sufficient controls, knowingly. Three waves of data show where this knowledge stops. Enterprises give agents scoped identities, assuming it equates to containment, but incident data disproves this. A 58% incident rate among those not isolating agents is clear evidence. The containment gap won’t close with easy solutions. Whether enterprises build isolation and governed identity proactively or reactively after a major incident remains to be seen.

TAGGED:agentcan039tenterprisesIdentitiesrogueSecured
Share This Article
Twitter Email Copy Link Print
Previous Article What To Do If You Looked At The Sun And Your Eyes Hurt What To Do If You Looked At The Sun And Your Eyes Hurt
Next Article Everything to Know About Rosie O’Donnell’s 2 Exits From ‘The View’ Everything to Know About Rosie O’Donnell’s 2 Exits From ‘The View’

Popular Posts

Meghan Tells Duke Of Sussex That 2025 Will Be Her Year For Lifestyle Empire

Frustrated Meghan Markle has set her sights on making 2025 her year of success. The…

December 3, 2024

NIH shuns studying racism and health. Its own research finds a link

The process of scientific research can be a lengthy one, often resulting in work being…

October 31, 2025

FFWS 2025 Global Finals Knockout Day 2: Overall standings and highlights

The Free Fire World Series (FFWS) 2025 Global Finals Knockout continued with Day 2 on…

November 1, 2025

NFL fans rip Drake Maye after horrible Super Bowl performance 

New England Patriots quarterback Drake Maye's quest for a first Super Bowl ring came to…

February 8, 2026

Rory McIlroy Gets Roasted by Dan Patrick: ‘Did America Turn On Rory?’

Legendary sports broadcaster Dan Patrick raised some thought-provoking questions regarding Rory McIlroy's performance at the…

June 17, 2025

You Might Also Like

Metal From Beyond Our World Found in Rings Worn by Ancient Mediterranean Elites : ScienceAlert
Tech and Science

Metal From Beyond Our World Found in Rings Worn by Ancient Mediterranean Elites : ScienceAlert

August 12, 2026
3 Reasons I’d Buy the Pixel 11 Over the Pro – Tech Advisor
Tech and Science

3 Reasons I’d Buy the Pixel 11 Over the Pro – Tech Advisor

August 12, 2026
See the 2026 total solar eclipse from around the world
Tech and Science

See the 2026 total solar eclipse from around the world

August 12, 2026
Insipid to Miami Sunset – Tech Advisor
Tech and Science

Insipid to Miami Sunset – Tech Advisor

August 12, 2026
logo logo
Facebook Twitter Youtube

About US


Explore global affairs, political insights, and linguistic origins. Stay informed with our comprehensive coverage of world news, politics, and Lifestyle.

Top Categories
  • Crime
  • Environment
  • Sports
  • Tech and Science
Usefull Links
  • Contact
  • Privacy Policy
  • Terms & Conditions
  • DMCA

© 2024 americanfocus.online –  All Rights Reserved.

Welcome Back!

Sign in to your account

Lost your password?