Corporate AI agents are becoming an increasingly vulnerable link in security infrastructure. According to fresh survey data conducted among 107 companies with more than 100 employees, over half of respondents have already encountered incidents related to the operation of these agents. 18% of organizations reported a confirmed security breach, while another 36% reported a prevented threat. Only 42% of participants recorded no such events, with 5% of companies not using AI agents in a production environment at all, and 2% not monitoring such incidents.
The survey, conducted in June 2026, revealed an alarming trend: organizations are massively ignoring basic principles of access management. Only 32% of respondents stated that each AI agent in their infrastructure has its own managed identity with limited permissions. The remaining 48% admitted that only some agents received separate identifiers, while others continue to use shared credentials. In 32% of companies, agents primarily operate through shared API keys, employee accounts, or service accounts. According to analysts' calculations, 69% of surveyed organizations use shared credentials in at least part of their infrastructure.
Correlation Between Practices and Incidents
Statistics confirm a direct link between the level of protection and the frequency of incidents. Among companies that practice credential separation, 63.5% reported incidents or prevented threats. In organizations where each agent has a separate identity, this figure drops to 40.9%. Although the study authors emphasize that the results do not prove a causal relationship, the numbers speak for themselves. To protect agents, 49% of companies restrict their permissions directly during operation, 47% use monitoring and logging, but only 30% isolate agents with broad permissions in sandboxes.
Reliance on Vendor Built-in Tools
82% of respondents cited built-in tools from AI model vendors or major cloud platforms as their primary security level. 51% of organizations use OpenAI's built-in restrictions, 36% use Google's tools, 35% use Microsoft's, and 29% use Anthropic's. The average satisfaction with current tools was 4.2 out of 5, yet 59% of organizations plan to implement a new tool or replace one of the products within a year. Among companies that have already encountered incidents, the share planning changes in the next three months is 42.1%, while in organizations without such events, it is only 14%.
In my opinion, the AI agent protection market is in its infancy. Companies rely too heavily on built-in solutions from model vendors, which often fail to account for the specifics of corporate infrastructure. The Zero Trust principle, which Anthropic proposed in June, is not just a recommendation but a necessity. Without implementing separate identifiers, minimal permissions, and verification of every action, corporate agents remain a "Trojan horse" for cybersecurity.