The corporate sector is increasingly adopting AI agents, but their level of protection leaves much to be desired. According to the results of a recent survey conducted among 107 companies with more than 100 employees, over half of respondents have already encountered security incidents related to these programs. 18% confirmed a hack or data leak, while another 36% reported that the threat was averted at the last moment.
The problem is compounded by the fact that many organizations still neglect basic isolation principles. Only in 32% of companies does each AI agent have its own managed identity with limited rights. This allows not only for access control but also for unambiguous identification of which program performed a particular action. In the remaining cases—69% of respondents—agents share common credentials: API keys, employee accounts, or service records.
The statistics are discouraging: among companies that practice shared identifiers, 63.5% have already experienced an incident or a prevented attack. For comparison, in organizations with individual identities, this figure stands at 40.9%. Although the study authors emphasize that this is a correlation rather than a direct causal link, the difference is evident.
Reliance on Vendor Security
The main focus of corporate security efforts is on built-in tools from AI model providers and cloud platforms—82% of participants responded this way. The leader here is OpenAI, whose restrictions are used by 51% of respondents. This is followed by Google (36%), Microsoft (35%), and Anthropic (29%). The average satisfaction with these tools is 4.2 out of 5.
However, despite the high rating, 59% of organizations plan to update or supplement their security arsenal within the year. Among those who have already suffered an incident, this figure reaches 42.1% in the next three months, whereas in incident-free companies, it is only 14%. This suggests that current measures do not inspire full confidence.
Budget and Future
Spending on AI agent protection remains modest: 46% of companies allocate 6–10% of their total cybersecurity budget to this, while 34% spend no more than 5%. Only 24% spend over 10%.
As an expert, I see a systemic problem here. The AI agent market is growing at an explosive pace, while security practices lag behind. Shared credentials are the "Achilles' heel" that makes corporate infrastructure vulnerable to attacks. The Zero Trust principle, recently proposed by Anthropic, should become the standard, not the exception. For now, companies rely on vendor protection, but judging by their update plans, they recognize its inadequacy. The actual frequency of incidents is likely higher than surveys show, as many simply do not track such events.