The market for enterprise AI agents is growing explosively, but along with it, the attack surface is rapidly expanding. A recent survey conducted in June 2026 among 107 companies with more than 100 employees revealed an alarming trend: more than half of respondents have already encountered security incidents related to AI agents. 18% reported a confirmed breach or leak, and another 36% reported cases that were prevented at the last moment. This is not just statistics—it is a signal of a systemic gap in protection that is dangerous to ignore.

Shared Credentials — The Main Threat Vector

The root of the problem is obvious: only 32% of organizations provided each AI agent with its own managed identity with limited privileges. The remaining 68% use shared credentials to some extent—API keys, employee accounts, or service accounts. This is a direct path to privilege escalation and lateral movement within the infrastructure. The numbers speak for themselves: among companies that use shared identifiers, 63.5% have already experienced an incident or prevented a threat. In the "individualist" camp, this figure is 40.9%. Although the study authors rightly note that the sample is too small for definitive conclusions, the correlation is clear.

Protection Tools: Reliance on Vendors and Budget Constraints

Interestingly, 82% of respondents rely on built-in security features from AI model providers (OpenAI, Google, Microsoft, Anthropic) or major cloud platforms. Satisfaction with these solutions is high—4.2 out of 5. However, 59% of companies plan to implement additional tools within a year, and 29% within the next three months. The dynamics among affected companies are particularly telling: 42.1% of them intend to update their security stack within a quarter, compared to 14% among those who have not seen incidents. This suggests that the "native" protection from vendors is often insufficient, especially when 46% of organizations spend only 6-10% of their total cybersecurity budget on AI agent security, and 34% spend no more than 5%.

Sandboxes and Monitoring: Palliative Instead of Strategy

Currently, only 49% of companies restrict agent privileges at runtime, 47% conduct monitoring and logging but cannot always automatically stop a dangerous action, and only 30% isolate the most "privileged" agents in sandboxes. This resembles the early days of web applications, when everyone relied on perimeter defense while ignoring the need for micro-segmentation. The Zero Trust principle, recently proposed by Anthropic, is becoming not just a recommendation but an urgent necessity: separate identity, minimal privileges, and verification of every action—this is the only path to the managed growth of the AI agent ecosystem.

Cryptalist Analytical Summary: The survey data confirms what we have been warning about since early 2025: AI agents are becoming the "weak link" in corporate security. Companies invest millions in developing and integrating agents but skimp on their protection, relying on "free" built-in vendor mechanisms. This is a dangerous illusion. The market for AI agent security solutions (AI Security Posture Management) is poised for explosive growth, and those who do not restructure their identity and access control architecture today risk becoming the next high-profile victim of a cyberattack.