844-ai.ro
Everything that matters in AI, in one place.
News← Citește în română

AI Agents Are Becoming a Major Security Liability: Over Half of Companies Have Already Experienced an Incident

17 July 2026

Enterprise adoption of AI agents is accelerating at a pace that far outstrips organizations' ability to secure them properly. A study of 107 companies found that the majority have granted AI agents real, functional access to internal systems and sensitive data — without implementing safeguards proportionate to the risks involved, according to VentureBeat.

Half of Companies Already Affected

The numbers are alarming: more than half of the organizations surveyed — 54% — confirmed either a security incident caused by an AI agent or a near-miss, meaning an event that was only narrowly avoided. This is no longer a theoretical threat or a lab scenario. It is an operational reality that companies are already facing, even if they are reluctant to acknowledge it publicly.

The core problem does not lie in the agent technology itself, but in how these agents are integrated into corporate infrastructure. In many cases, AI agents are treated like ordinary software applications, without applying the security principles appropriate for entities that hold privileged access to critical resources.

Shared Credentials and Unscoped Identities

One of the most serious vulnerabilities identified is the practice of sharing credentials among agents. According to VentureBeat, only about one-third of companies assign each agent its own identity with limited, well-defined permissions. The rest allow agents to operate using shared credentials — meaning a single compromised agent could give an attacker broad access across multiple systems.

This approach directly contradicts one of cybersecurity's foundational principles: least privilege — granting only the minimum level of access required to perform a given task. Applying this principle to AI agents is, paradoxically, even more critical than applying it to human users, precisely because agents act autonomously and at high speed.

Isolating High-Risk Agents Remains the Exception, Not the Rule

Another troubling finding concerns the isolation of agents deemed high-risk. The study shows that only three in ten companies implement isolation measures for the most dangerous agents in their infrastructure. The remaining 70% allow these agents to operate within the same environment as the rest of their systems, creating conditions in which an incident can spread rapidly.

In effect, companies are building powerful engines without investing in adequate brakes. The pace of AI agent deployment is driven by competitive pressure and the desire to streamline internal processes quickly. Security consequently becomes an afterthought — addressed retrospectively, after the architecture is already up and running.

A Structural Gap Between Innovation and Governance

What this study ultimately describes is a structural gap between the pace of technological innovation and organizations' capacity to govern it. Security teams are not brought into the AI agent deployment process early enough, and existing policies have not been updated to account for the specific characteristics of this category of autonomous software.

For companies operating in European markets, the stakes are even higher given the region's strict data protection regulations. A security incident caused by an AI agent can result not only in operational losses, but also in significant penalties under applicable regulatory frameworks. The moment when AI agent security becomes a strategic priority — rather than a footnote in digital transformation plans — can no longer be postponed.

Source

VentureBeat

844-ai.ro reports based on the source above. Editorially synthesized article, with attribution.

Subscribe to our newsletter

Get the most important AI news once a week, straight to your inbox.

AI Agents: A Growing Security Risk for Enterprises | 844-ai.ro