• Space Exploration Technologies (Dinari Tokenized Stock)Space Exploration Technologies (Dinari Tokenized Stock)(SPCX)$139.732.60%
  • bitcoinBitcoin(BTC)$63,349.00-0.50%
  • ethereumEthereum(ETH)$1,876.71-0.40%
  • tetherTether(USDT)$1.000.00%
  • binancecoinBNB(BNB)$609.89-0.50%
  • usd-coinUSDC(USDC)$1.000.00%
  • rippleXRP(XRP)$1.00-2.00%
  • solanaSolana(SOL)$75.51-1.50%
  • tronTRON(TRX)$0.3357840.20%
  • Figure HelocFigure Heloc(FIGR_HELOC)$1.040.00%
  • HyperliquidHyperliquid(HYPE)$56.022.40%
  • dogecoinDogecoin(DOGE)$0.069562-4.80%
  • USDSUSDS(USDS)$1.000.00%
  • RainRain(RAIN)$0.012789-1.10%
  • leo-tokenLEO Token(LEO)$9.11-3.40%
  • zcashZcash(ZEC)$488.911.20%
  • moneroMonero(XMR)$391.572.50%
  • cardanoCardano(ADA)$0.182368-2.70%
  • chainlinkChainlink(LINK)$8.67-1.20%
  • whitebitWhiteBIT Coin(WBT)$54.89-0.40%
  • stellarStellar(XLM)$0.159468-2.40%
  • daiDai(DAI)$1.000.00%
  • bitcoin-cashBitcoin Cash(BCH)$212.29-0.80%
  • USD1USD1(USD1)$1.000.00%
  • Ethena USDeEthena USDe(USDE)$1.000.00%
  • CantonCanton(CC)$0.098773-1.90%
  • the-open-networkGram (prev. Toncoin)(GRAM)$1.351.50%
  • litecoinLitecoin(LTC)$44.88-1.50%
  • Global DollarGlobal Dollar(USDG)$1.000.00%
  • Circle USYCCircle USYC(USYC)$1.130.00%
  • hedera-hashgraphHedera(HBAR)$0.065907-1.30%
  • paypal-usdPayPal USD(PYUSD)$1.000.00%
  • suiSui(SUI)$0.68-2.10%
  • BlackRock USD Institutional Digital Liquidity FundBlackRock USD Institutional Digital Liquidity Fund(BUIDL)$1.000.00%
  • avalanche-2Avalanche(AVAX)$6.31-0.30%
  • tether-goldTether Gold(XAUT)$4,384.830.60%
  • shiba-inuShiba Inu(SHIB)$0.000004-2.70%
  • uniswapUniswap(UNI)$3.57-5.70%
  • crypto-com-chainCronos(CRO)$0.046748-0.50%
  • nearNEAR Protocol(NEAR)$1.641.70%
  • Ondo US Dollar YieldOndo US Dollar Yield(USDY)$1.140.10%
  • okbOKB(OKB)$98.693.10%
  • pax-goldPAX Gold(PAXG)$4,400.180.60%
  • BittensorBittensor(TAO)$199.90-0.30%
  • World Liberty FinancialWorld Liberty Financial(WLFI)$0.0550990.30%
  • HTX DAOHTX DAO(HTX)$0.000002-0.40%
  • AsterAster(ASTER)$0.60-0.70%
  • OndoOndo(ONDO)$0.330042-2.20%
  • Ripple USDRipple USD(RLUSD)$1.000.00%
  • usddUSDD(USDD)$1.000.00%
TradePoint.io
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop
No Result
View All Result
TradePoint.io
No Result
View All Result

Four of five enterprises that secured AI agent identities still can’t contain one that goes rogue

August 12, 2026
in AI & Technology
Reading Time: 9 mins read
A A
Four of five enterprises that secured AI agent identities still can’t contain one that goes rogue
ShareShareShareShareShare

Visa’s president of technology, Rajat Taneja, walked the VB Transform 2026 audience through aiming Anthropic’s Mythos at Visa’s own payment network. The model stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that governed the hunt.

That’s what it looks like when an enterprise has the engineering depth to act on what it finds. Most don’t get there. Just over half, or 53%, of enterprises have already had an agentic security incident or near-miss. Sixty-five percent enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents, and just 8% pair enforcement with isolation.

YOU MAY ALSO LIKE

Cisco Books $4B in Quarterly AI Orders as Networking Supercycle Lifts FY2027 Outlook – Unite.AI

FlightAware Dropped Its Lawsuit Against Kalshi After Just One Day

Leaning on provider-native controls to do the heavy lifting of agentic security just exacerbates that gap. The July wave of VentureBeat Pulse Research found that 92% of enterprises naming a primary security layer default to their hyperscalers and AI platform providers.

Six waves of research have been completed since January, surveying 440 qualified enterprise security respondents. The key takeaway: the containment gap between what enterprises need and what’s getting done is growing wider, often unaddressed by enterprises whose agentic AI investments and futures are at risk.

The satisfaction data doesn’t match the incident data

The research keeps showing enterprises rating the tools they know best at a higher score, even if those tools failed them or delivered mediocre results. Three findings from the raw data cut against that instinct, and each one says something about how young this market still is.

The enterprises that got hit rate their tools higher than the ones that didn’t

Last month’s survey found that 46 enterprises reported a confirmed incident or near-miss, then went on to rate their satisfaction with their security tooling. Their average satisfaction was 4.39 out of 5. 30 of the 55 enterprises who experienced no incidents rated their security tooling at 4.13. Enterprises are rewarding any tool that saves them from a breach with a trust premium.

It’s a sure sign of a nascent market when brand positioning, marketing, or other means of persuading enterprises get easily superseded by saving a customer from a breach. Near-misses outnumber confirmed incidents 2-to-1 in both June and July, which means enterprises are catching problems at the edge. That edge catch is being interpreted as validation of both the security strategy and the tools acquired. Evident through seven months of data is how quick enterprise security leaders are to trust a new tool that identifies an intrusion or breach and defeats it before it gains access. VentureBeat believes the rescue itself is doing the marketing. The 4.13 average among never-hit enterprises shows the other side of the same effect. Tools that have never been seen working earn less trust, not more.

VentureBeat also found that of the 17 enterprises isolating their highest-risk agents, the 14 that rated their tooling average 4.00. Enterprises that do not isolate rate it 4.35. The enterprises closest to real security are the least satisfied with their tools — that dissatisfaction is what drives them toward the kind of engineering effort Visa put in.

The satisfaction ladder. Enterprises that built isolation rate tools 4.00. Enterprises that experienced an incident rate them 4.39. VentureBeat Pulse Research, July 2026, respondent-level analysis, n=76 who rated.

Four of five enterprises that solved identity did not build isolation

49%, or 57 of the 116 enterprises surveyed in July, gave each agent its own scoped, managed identity. Just a month earlier, VentureBeat’s June wave recorded 32% of enterprises having assigned per-agent identities. July’s 17-point jump in one month is the fastest single-month move this series has recorded. Despite these gains, 63% still report credential sharing somewhere in the fleet. Only 11 of those 57 also isolate.

That ratio explains why the containment gap keeps widening even as every headline control improves. Enterprises are treating identity and isolation as substitutes. They need to see the longer-term vision of each being integral to a platform-based, layered strategy. Two incidents VentureBeat has covered show why that distinction matters. A rogue AI agent at Meta passed every identity check before its March exposure was contained. And CrowdStrike CEO George Kurtz disclosed, at his RSAC 2026 keynote, a Fortune 50 agent that rewrote its own security policy using valid credentials. Giving an agent scoped credentials does not bound the blast radius when those credentials are misused. Sandboxing does.

The enforce-without-isolate population has a 58% incident rate

Fifty-three enterprises in July’s survey enforce scoped permissions at runtime but do not isolate. 31 of those 53 have already had an agent security incident or near-miss. That is 58%, five points above the 53% sample average. The enterprises living inside the containment gap are getting hit more often than the enterprises outside it.

Amy Chang, Cisco’s head of AI threat intelligence and security research, presented findings on the Transform agentic security panel showing that when Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through up to 88.3% of the time. Single-turn red-teaming missed it. An adaptive attacker who defeats the guardrails lands inside whatever architecture sits behind them, and for 53 of the enterprises in this data, that architecture enforces but does not contain.

VentureBeat’s Q1 Pulse Research tracked the same structural weakness earlier this year. Unauthorized tool or data access ranked as the most feared failure mode in every Q1 survey, growing from 42% in January to 50% in March. The April-May survey found only 4% of enterprises comfortable relying on model guardrails alone. Enterprises predicted they needed external controls, choosing to build enforcement over containment.

Enterprises built enforcement 35 points ahead of forecast. Isolation barely moved

The April-May survey asked 109 enterprises how they expected agent behavior to be controlled by the end of 2026, and 30% predicted runtime enforcement, 14% sandboxed execution, and 32% model-level guardrails. By July, 65% had built enforcement, more than double the prediction, while isolation reached 18%, roughly the rate they said it would. Enterprises built what was easy at twice the forecast and built what was hard at roughly the forecast. The April question asked for the primary control mechanism, single-select, while July’s posture question allowed multiple selections, so the comparison is directional rather than exact.

65% of enterprises are enforcing AI agent permissions at runtime. Just 18% can contain an agent if enforcement fails

Three quarters, one gap. Q1 threat prediction, Q2 forecasts, and the June-to-July build-out in which every control improved except isolation. VentureBeat Pulse Research, seven waves, Jan-Jul 2026.

Provider lock-in accelerated across all three quarters

Provider-native platforms already led usage in April-May, named by seven in ten enterprises describing their tooling. By June, 82% called one their primary agent security layer, and by July that share reached 92%, with OpenAI’s guardrails leading at 44%, Microsoft Azure at 42%, Anthropic’s managed-agent controls at 37%, and Google Cloud at 31%. Cloudflare at 11% and Cisco at 9% lead the dedicated specialists fighting over what remains. The identity tools most relevant to the credential-sharing gap are the smallest of all, with Microsoft Entra Agent ID at 7%, while Okta for AI Agents, non-human identity platforms, and runtime sandboxing tooling each sit at 3%. CrowdStrike CTO Elia Zaitsev told VentureBeat at RSAC 2026 that observing agent actions is a solvable problem but inferring intent is not. The provider bundle proves his point, solving observation while leaving containment unbuilt.

74% plan to replace tools they just rated a career-high satisfaction score

Satisfaction scores continue rising as enterprises gain more experience using tools and techniques to stop agentic AI-based attacks. Rising to 4.29 out of 5 in July from 4.2 in June, satisfaction is the highest reading in the series.

Despite the high satisfaction levels, 74% plan to replace their tools within 12 months, up from 59% in June. Only 26% intend not to change. VentureBeat believes early adopters are impatient to gain greater insights, and know what they don’t know about agentic security and resilience. Closing that knowledge gap is forcing churn into a market this young, and the raw answers resolve the paradox: 92% of enterprises naming a primary layer name a provider-native one. The 4.29 measures how easy it is to turn on a provider’s guardrails. It does not measure how effective those guardrails are at preventing the incidents 53% of the same respondents already had.

The organizations closest to the threat are the least confident about it

In June, defenders led attackers 35% to 21%, but by July the split was 30-30, a dead heat. Among enterprises that have been hit, 39% now say attackers are ahead, against 20% of those that have not. Getting hit nearly doubles the pessimism but does not change the shopping. Just 10% of enterprises include any agent-identity product in their consideration set. Runtime sandboxing draws 6%, and those numbers hold regardless of incident history. VentureBeat covered the same blind spot in the June data. The label changed from agent security gap to containment gap, but the shopping did not.

Methodology

The posture question was answered by 93 of the 116 qualified July respondents, and the skippers are not hidden isolators. Twenty-three of the 25 who selected no posture option are organizations still evaluating agents, unsure of their status, or with no deployment plans, groups for which a security posture largely does not yet exist, so the 18% isolation figure reads on the enterprises actually running or piloting agents. April-May, June, and July are separate, independently fielded waves rather than a single tracked series, so month-over-month comparisons in this piece are directional rather than a measured trend. Base sizes for the cross-cuts differ by instrument. The identity question covers all 116 respondents, isolation covers the 93 who described a posture, and the satisfaction inversion of 4.39 versus 4.13 is computed on the 76 respondents who rated their tooling.

The bottom line

VentureBeat’s cross-survey analysis of 573 enterprise respondents concluded in July that enterprises deployed AI agents ahead of the controls needed to manage them, and they did it knowingly. Three waves of security-specific data now show where the knowing stops.

Enterprises continue giving agents scoped identities and treating that as containment, but that assumption is false, and the incident data keeps proving it. In fact, 46 of 57 enterprises that solved identity did not build isolation. The enforce-without-isolate population’s 58% incident rate is the clearest evidence that identity alone isn’t enough. The containment gap will not close through satisfaction with what is easy. Whether enterprises build isolation and governed identity deliberately, or whether a confirmed incident that propagates does it for them, is the question the next wave will answer.

Credit: Source link

ShareTweetSendSharePin

Related Posts

Cisco Books B in Quarterly AI Orders as Networking Supercycle Lifts FY2027 Outlook – Unite.AI
AI & Technology

Cisco Books $4B in Quarterly AI Orders as Networking Supercycle Lifts FY2027 Outlook – Unite.AI

August 12, 2026
FlightAware Dropped Its Lawsuit Against Kalshi After Just One Day
AI & Technology

FlightAware Dropped Its Lawsuit Against Kalshi After Just One Day

August 12, 2026
AllenAI Open Instruct Tulu 3 Post-Training with SFT, DPO, RLVR, GRPO, and Verifier-Based Evaluation
AI & Technology

AllenAI Open Instruct Tulu 3 Post-Training with SFT, DPO, RLVR, GRPO, and Verifier-Based Evaluation

August 12, 2026
SpaceXAI debuts Grok 4.6, overtaking Kimi K3’s performance and matching GPT-5.6 Sol for world’s third best on Artificial Analysis
AI & Technology

SpaceXAI debuts Grok 4.6, overtaking Kimi K3’s performance and matching GPT-5.6 Sol for world’s third best on Artificial Analysis

August 12, 2026
Next Post
FlightAware Dropped Its Lawsuit Against Kalshi After Just One Day

FlightAware Dropped Its Lawsuit Against Kalshi After Just One Day

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

Search

No Result
View All Result
Recapping the biggest-ever group stage at the World Cup

Recapping the biggest-ever group stage at the World Cup

August 10, 2026
Inside look at the Christian and Jewish groups trying to build a temple at Al-Aqsa Compound

Inside look at the Christian and Jewish groups trying to build a temple at Al-Aqsa Compound

August 11, 2026
Monaco and French authorities investigating explosion as possible assassination attempt

Monaco and French authorities investigating explosion as possible assassination attempt

August 9, 2026

About

Learn more

Our Services

Legal

Privacy Policy

Terms of Use

Bloggers

Learn more

Article Links

Contact

Advertise

Ask us anything

©2020- TradePoint.io - All rights reserved!

Tradepoint.io, being just a publishing and technology platform, is not a registered broker-dealer or investment adviser. So we do not provide investment advice. Rather, brokerage services are provided to clients of Tradepoint.io by independent SEC-registered broker-dealers and members of FINRA/SIPC. Every form of investing carries some risk and past performance is not a guarantee of future results. “Tradepoint.io“, “Instant Investing” and “My Trading Tools” are registered trademarks of Apperbuild, LLC.

This website is operated by Apperbuild, LLC. We have no link to any brokerage firm and we do not provide investment advice. Every information and resource we provide is solely for the education of our readers. © 2020 Apperbuild, LLC. All rights reserved.

No Result
View All Result
  • Main
  • AI & Technology
  • Stock Charts
  • Market & News
  • Business
  • Finance Tips
  • Trade Tube
  • Blog
  • Shop

© 2023 - TradePoint.io - All Rights Reserved!