Brief IA

AI Agents: 54% of Companies Affected by Incidents

🛠️ AI Tools·Tom Levy·

AI Agents: 54% of Companies Affected by Incidents

AI Agents: 54% of Companies Affected by Incidents
Key Takeaways
1More than half of companies have experienced security incidents related to AI agents, revealing weaknesses in controls.
2Only 32% of companies assign a unique identity to each agent, while 69% still share identifiers.
3Security tools are primarily provided by tech giants, but few companies isolate their high-risk agents.
💡Why it mattersThe security of AI agents is crucial for protecting sensitive company data and avoiding costly incidents.
Le brief IA que lisent les pros

Le brief IA que les pros lisent chaque soir

Les 7 actus IA du jour, décryptées en 5 min. Gratuit.

Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.

Choisis ton rythme

Gratuit · Pas de spam · Désabonnement en 1 clic

📄
Full Analysis

The Security Gap of AI Agents

An increasing number of companies are facing security incidents involving artificial intelligence agents. More than half of organizations have already experienced such incidents, highlighting a lack of adequate controls to manage these agents. Despite this, many companies continue to allow the sharing of credentials among agents, thereby increasing security risks.

Key Findings

A survey conducted among 107 companies reveals that AI agents often have direct access to sensitive systems and data, while security measures to control them are insufficient. More than half of the companies reported having experienced a confirmed security incident or narrowly avoided a potential incident. Only one-third of companies assign a unique and restricted identity to each agent, and the majority continue to share credentials among agents. Furthermore, a minority of companies take steps to isolate agents deemed to be high-risk.

The security gap of agents is partly due to the excessive autonomy granted to agents by companies, which exceeds the security controls in place. Although most companies claim to be satisfied with the controls they use, security spending still represents a small portion of the overall budget.

Methodology

The study was conducted as part of VentureBeat's Pulse research series, focused on the security of AI agents. It gathered responses from organizations with more than 100 employees, with a majority of senior decision-makers, of which 45% are final decision-makers for AI purchases.

Key Results

1. Incidents Are Already Here

A significant percentage, 54% of organizations, have already experienced a security incident related to an AI agent. Among these, 18% reported a confirmed incident, while 36% successfully avoided an incident before it could cause damage.

2. The Identity Gap

Only 32% of companies assign a unique and managed identity to each agent, leaving a majority of 69% of companies admitting to sharing credentials among their agents.

3. Monitoring and Enforcement, but Rarely Isolation

About 30% of companies take the precaution of isolating their high-risk agents in secure environments. Additionally, 47% monitor agent activity, and 49% enforce limited permissions in real-time.

4. Security Based on Borrowed Controls

The security tools used by companies primarily come from model providers and hyperscalers. Among them, OpenAI's safeguards are employed by 51% of companies, along with controls from Google and Microsoft. Anthropic's agent management solutions are also used, but dedicated security specialists remain few.

Conclusion

The security gap of AI agents represents a major challenge, with increasing autonomy of agents and insufficient security controls. To reduce their exposure to incidents, companies must invest in managed identity systems and isolate high-risk agents.

Brief IA — L'actualité IA en français

L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.