AI Agents: 54% of Companies Affected by Incidents

Le brief IA que les pros lisent chaque soir
Les 7 actus IA du jour, décryptées en 5 min. Gratuit.
Inclus dès l'inscription : notre sélection des meilleurs guides & comparatifs IA.
Choisis ton rythme
Gratuit · Pas de spam · Désabonnement en 1 clic
The Security Gap of AI Agents
An increasing number of companies are facing security incidents involving artificial intelligence agents. More than half of organizations have already experienced such incidents, highlighting a lack of adequate controls to manage these agents. Despite this, many companies continue to allow the sharing of credentials among agents, thereby increasing security risks.
Key Findings
A survey conducted among 107 companies reveals that AI agents often have direct access to sensitive systems and data, while security measures to control them are insufficient. More than half of the companies reported having experienced a confirmed security incident or narrowly avoided a potential incident. Only one-third of companies assign a unique and restricted identity to each agent, and the majority continue to share credentials among agents. Furthermore, a minority of companies take steps to isolate agents deemed to be high-risk.
The security gap of agents is partly due to the excessive autonomy granted to agents by companies, which exceeds the security controls in place. Although most companies claim to be satisfied with the controls they use, security spending still represents a small portion of the overall budget.
Methodology
The study was conducted as part of VentureBeat's Pulse research series, focused on the security of AI agents. It gathered responses from organizations with more than 100 employees, with a majority of senior decision-makers, of which 45% are final decision-makers for AI purchases.
Key Results
1. Incidents Are Already Here
A significant percentage, 54% of organizations, have already experienced a security incident related to an AI agent. Among these, 18% reported a confirmed incident, while 36% successfully avoided an incident before it could cause damage.
2. The Identity Gap
Only 32% of companies assign a unique and managed identity to each agent, leaving a majority of 69% of companies admitting to sharing credentials among their agents.
3. Monitoring and Enforcement, but Rarely Isolation
About 30% of companies take the precaution of isolating their high-risk agents in secure environments. Additionally, 47% monitor agent activity, and 49% enforce limited permissions in real-time.
4. Security Based on Borrowed Controls
The security tools used by companies primarily come from model providers and hyperscalers. Among them, OpenAI's safeguards are employed by 51% of companies, along with controls from Google and Microsoft. Anthropic's agent management solutions are also used, but dedicated security specialists remain few.
Conclusion
The security gap of AI agents represents a major challenge, with increasing autonomy of agents and insufficient security controls. To reduce their exposure to incidents, companies must invest in managed identity systems and isolate high-risk agents.
Brief IA — L'actualité IA en français
L'essentiel de l'actualité de l'intelligence artificielle, décrypté et expliqué chaque jour.