Visa’s president of expertise, Rajat Taneja, walked the VB Transform 2026 viewers by means of aiming Anthropic’s Mythos at Visa’s own payment network. The mannequin stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that ruled the hunt.
That is what it appears to be like like when an enterprise has the engineering depth to act on what it finds. Most do not get there. Simply over half, or 53%, of enterprises have already had an agentic security incident or near-miss. Sixty-five p.c implement agent permissions at runtime, but solely 18% isolate their highest-risk brokers, and simply 8% pair enforcement with isolation.
Leaning on provider-native controls to do the heavy lifting of agentic safety simply exacerbates that hole. The July wave of VentureBeat Pulse Analysis discovered that 92% of enterprises naming a main safety layer default to their hyperscalers and AI platform suppliers.
Six waves of research have been accomplished since January, surveying 440 certified enterprise safety respondents. The important thing takeaway: the containment hole between what enterprises want and what’s getting finished is rising wider, usually unaddressed by enterprises whose agentic AI investments and futures are in danger.
The satisfaction information does not match the incident information
The analysis retains exhibiting enterprises ranking the instruments they know finest at a better rating, even when these instruments failed them or delivered mediocre outcomes. Three findings from the uncooked information lower in opposition to that intuition, and each says one thing about how younger this market nonetheless is.
The enterprises that obtained hit charge their instruments greater than the ones that did not
Final month’s survey discovered that 46 enterprises reported a confirmed incident or near-miss, then went on to charge their satisfaction with their safety tooling. Their common satisfaction was 4.39 out of 5. 30 of the 55 enterprises who skilled no incidents rated their safety tooling at 4.13. Enterprises are rewarding any software that saves them from a breach with a belief premium.
It’s a positive signal of a nascent market when model positioning, advertising, or different technique of persuading enterprises get simply outdated by saving a buyer from a breach. Close to-misses outnumber confirmed incidents 2-to-1 in each June and July, which implies enterprises are catching issues at the edge. That edge catch is being interpreted as validation of each the safety technique and the instruments acquired. Evident by means of seven months of knowledge is how fast enterprise safety leaders are to belief a brand new software that identifies an intrusion or breach and defeats it before it good points entry. VentureBeat believes the rescue itself is doing the advertising. The 4.13 common amongst never-hit enterprises exhibits the different aspect of the identical impact. Instruments which have by no means been seen working earn much less belief, not extra.
VentureBeat additionally discovered that of the 17 enterprises isolating their highest-risk brokers, the 14 that rated their tooling common 4.00. Enterprises that do not isolate charge it 4.35. The enterprises closest to actual safety are the least happy with their instruments — that dissatisfaction is what drives them towards the sort of engineering effort Visa put in.
4 of 5 enterprises that solved identification did not construct isolation
49%, or 57 of the 116 enterprises surveyed in July, gave every agent its personal scoped, managed identification. Only a month earlier, VentureBeat’s June wave recorded 32% of enterprises having assigned per-agent identities. July’s 17-point leap in a single month is the quickest single-month transfer this collection has recorded. Regardless of these good points, 63% nonetheless report credential sharing someplace in the fleet. Solely 11 of these 57 additionally isolate.
That ratio explains why the containment hole retains widening at the same time as each headline management improves. Enterprises are treating identification and isolation as substitutes. They want to see the longer-term imaginative and prescient of every being integral to a platform-based, layered technique. Two incidents VentureBeat has lined present why that distinction issues. A rogue AI agent at Meta handed each identification examine before its March publicity was contained. And CrowdStrike CEO George Kurtz disclosed, at his RSAC 2026 keynote, a Fortune 50 agent that rewrote its own security policy utilizing legitimate credentials. Giving an agent scoped credentials does not sure the blast radius when these credentials are misused. Sandboxing does.
The enforce-without-isolate inhabitants has a 58% incident charge
Fifty-three enterprises in July’s survey implement scoped permissions at runtime however do not isolate. 31 of these 53 have already had an agent safety incident or near-miss. That is 58%, 5 factors above the 53% pattern common. The enterprises residing inside the containment hole are getting hit extra usually than the enterprises exterior it.
Amy Chang, Cisco’s head of AI risk intelligence and safety analysis, presented findings on the Transform agentic security panel exhibiting that when Cisco ran 6,986 multi-turn assaults in opposition to 15 flagship fashions, attackers who tailored throughout the dialog broke by means of up to 88.3% of the time. Single-turn red-teaming missed it. An adaptive attacker who defeats the guardrails lands inside no matter structure sits behind them, and for 53 of the enterprises on this information, that structure enforces however does not comprise.
VentureBeat’s Q1 Pulse Analysis tracked the identical structural weak spot earlier this 12 months. Unauthorized software or information entry ranked as the most feared failure mode in each Q1 survey, rising from 42% in January to 50% in March. The April-Might survey discovered solely 4% of enterprises comfy relying on mannequin guardrails alone. Enterprises predicted they wanted external controls, selecting to construct enforcement over containment.
Enterprises constructed enforcement 35 factors forward of forecast. Isolation barely moved
The April-Might survey requested 109 enterprises how they anticipated agent habits to be managed by the finish of 2026, and 30% predicted runtime enforcement, 14% sandboxed execution, and 32% model-level guardrails. By July, 65% had constructed enforcement, greater than double the prediction, whereas isolation reached 18%, roughly the charge they stated it might. Enterprises constructed what was simple at twice the forecast and constructed what was laborious at roughly the forecast. The April query requested for the main management mechanism, single-select, whereas July’s posture query allowed a number of choices, so the comparability is directional slightly than precise.
Supplier lock-in accelerated throughout all three quarters
Supplier-native platforms already led utilization in April-Might, named by seven in ten enterprises describing their tooling. By June, 82% known as one their main agent safety layer, and by July that share reached 92%, with OpenAI’s guardrails main at 44%, Microsoft Azure at 42%, Anthropic’s managed-agent controls at 37%, and Google Cloud at 31%. Cloudflare at 11% and Cisco at 9% lead the devoted specialists combating over what stays. The identification instruments most related to the credential-sharing hole are the smallest of all, with Microsoft Entra Agent ID at 7%, whereas Okta for AI Brokers, non-human identification platforms, and runtime sandboxing tooling every sit at 3%. CrowdStrike CTO Elia Zaitsev told VentureBeat at RSAC 2026 that observing agent actions is a solvable downside however inferring intent is not. The supplier bundle proves his level, fixing statement whereas leaving containment unbuilt.
74% plan to substitute instruments they simply rated a career-high satisfaction rating
Satisfaction scores proceed rising as enterprises acquire extra expertise utilizing instruments and methods to cease agentic AI-based assaults. Rising to 4.29 out of 5 in July from 4.2 in June, satisfaction is the highest studying in the collection.
Regardless of the excessive satisfaction ranges, 74% plan to substitute their instruments inside 12 months, up from 59% in June. Solely 26% intend not to change. VentureBeat believes early adopters are impatient to acquire higher insights, and know what they don’t find out about agentic safety and resilience. Closing that data hole is forcing churn right into a market this younger, and the uncooked solutions resolve the paradox: 92% of enterprises naming a main layer title a provider-native one. The 4.29 measures how simple it is to flip on a supplier’s guardrails. It does not measure how efficient these guardrails are at stopping the incidents 53% of the identical respondents already had.
The organizations closest to the risk are the least assured about it
In June, defenders led attackers 35% to 21%, however by July the cut up was 30-30, a lifeless warmth. Amongst enterprises which have been hit, 39% now say attackers are forward, in opposition to 20% of those who have not. Getting hit practically doubles the pessimism however does not change the buying. Simply 10% of enterprises embody any agent-identity product of their consideration set. Runtime sandboxing attracts 6%, and people numbers maintain no matter incident historical past. VentureBeat lined the identical blind spot in the June information. The label modified from agent safety hole to containment hole, however the buying did not.
Methodology
The posture query was answered by 93 of the 116 certified July respondents, and the skippers are not hidden isolators. Twenty-three of the 25 who chosen no posture possibility are organizations nonetheless evaluating brokers, uncertain of their standing, or with no deployment plans, teams for which a safety posture largely does not but exist, so the 18% isolation determine reads on the enterprises truly working or piloting brokers. April-Might, June, and July are separate, independently fielded waves slightly than a single tracked collection, so month-over-month comparisons on this piece are directional slightly than a measured pattern. Base sizes for the cross-cuts differ by instrument. The identification query covers all 116 respondents, isolation covers the 93 who described a posture, and the satisfaction inversion of 4.39 versus 4.13 is computed on the 76 respondents who rated their tooling.
The underside line
VentureBeat’s cross-survey analysis of 573 enterprise respondents concluded in July that enterprises deployed AI brokers forward of the controls wanted to handle them, they usually did it knowingly. Three waves of security-specific information now present the place the realizing stops.
Enterprises proceed giving brokers scoped identities and treating that as containment, however that assumption is false, and the incident information retains proving it. In reality, 46 of 57 enterprises that solved identification did not construct isolation. The enforce-without-isolate inhabitants’s 58% incident charge is the clearest proof that identification alone is not sufficient. The containment hole will not shut by means of satisfaction with what is simple. Whether or not enterprises construct isolation and ruled identification intentionally, or whether or not a confirmed incident that propagates does it for them, is the query the subsequent wave will reply.
Disclaimer: This article is sourced from external platforms. OverBeta has not independently verified the information. Readers are advised to verify details before relying on them.