Enterprise security teams are confronting a fundamental flaw in the architecture of their AI agent deployments: 69% of organizations are running AI agents that share credentials, transforming a single compromised agent into a catastrophic, multi-system breach where attribution is impossible. This finding from VentureBeat’s June 2026 Pulse Research wave of 107 enterprises explains the unprecedented $22 billion acquisition spree by Palo Alto Networks, CrowdStrike, and Cisco, all of whom are betting that the next major security battleground is the identity and permissions layer of autonomous software.
The Shared Credential Problem: A Single Point of Catastrophic Failure
When one API key is shared across five AI agents, a compromise of any single agent inherits the cumulative permissions of all five workflows that key touches. The forensic trail goes cold immediately because five agents on a single account leave no record of which agent executed which action. Only 32% of enterprises grant every AI agent its own scoped, managed identity. Nearly half (48%) report that some agents have scoped identities while many still share credentials, and another 32% say agents largely run on shared API keys or borrowed human and service-account credentials. The survey allowed multiple selections from 107 respondents, and after deduplication, 69% flagged credential sharing in at least one answer.
The scale of the problem is staggering. CyberArk’s research puts machine identities at 82 for every human in organizations worldwide, with AI agents as the fastest-growing category. Cisco made the same diagnosis when it acquired Astrix Security, whose founders built the company specifically to manage the API keys, service accounts, and OAuth tokens that AI agents are now “using (and abusing)” to execute work at scale.
Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, described the mechanism directly. Some AI systems have their own identities, but in other cases, “people give their identity to the AI to take action on their behalf, and that also further kind of murkies the water and makes it very complex.” When the identity is shared, attribution dies with it.
Exposure Scales With Size While Containment Collapses
Forty-nine percent of enterprises enforce scoped permissions at runtime, and 47% monitor and log agent activity. Only 30% sandbox their highest-risk agents, the one control that limits blast radius when the first two fail. This containment gap widens dramatically with company size. The incident rate for companies with 101 to 1,000 employees is 49%, but it shoots up to 63% for companies with more than 1,000 employees. Sandbox isolation moves in the opposite direction, falling from 35% to 20% at larger enterprises.
At organizations with 101 to 250 employees, the gap between incident rate and isolation rate is just 7 points. Above 5,000 employees, that gap blows out to 60 points. Larger enterprises run more agents across more systems, which drives incidents up while sandboxing goes unfunded. The enterprises with the most agents have the least isolation around them, precisely the accounts where Palo Alto Networks, Cisco, and CrowdStrike are targeting their new product lines.
Borrowed Security Stacks: Default Guardrails Without Real Identities
The overwhelming majority of enterprises are relying on provider-native security stacks. OpenAI’s built-in guardrails lead at 51%, Google Cloud reaches 36%, Microsoft Azure’s Purview and Copilot Studio DLP reaches 35%, and Anthropic’s managed-agent controls reach 29%. Eighty-two percent of respondents name a provider-native or hyperscaler control as their single primary agent security layer. The purpose-built specialists are in single digits: Palo Alto Networks’ Prisma AIRS at 7%, CrowdStrike at 6%, and Okta for AI Agents at 4%.
Bundled controls lead because they ship free and are enabled by default. They filter prompts and outputs, but they do not give an agent its own identity or sandbox it. Prompt-and-output filters evaluate whether a call looks malicious, an intent problem that cannot be solved at the language layer. CrowdStrike CTO Elia Zaitsev drew the line clearly at RSAC 2026: “Observing actual kinetic actions is a structured, solvable problem. Intent is not.” A scoped identity and an isolation boundary give a sensor something to track, while a shared credential on a bundled guardrail does not.
Merritt Baer, chief security officer at Enkrypt AI and a former deputy CISO at AWS, described the risk succinctly: “Enterprises believe they’ve ‘approved’ AI vendors, but what they’ve actually approved is an interface, not the underlying system. The real dependencies are one or two layers deeper, and those are the ones that fail under stress.”
The Contradiction: High Satisfaction, Low Conviction, Active Shopping
Despite the glaring exposure, enterprises rate their agent security tooling 4.2 out of 5, with value for money at 4.1. Yet only 35% believe their AI-enabled defenses are ahead of AI-enabled attackers. Twenty-one percent say attackers lead, and another 21% say it is too early to tell. This contradiction reveals that enterprises trust their tooling more than they trust its outcomes.
Budgets confirm the mismatch. Forty-six percent allocate 6 to 10% of the security budget to agent security, and a full third spend 5% or less. Half the sample has already had an incident or near-miss, but the funding does not match the exposure. However, 59% plan to adopt, add, or replace agent security tooling within 12 months, and 29% plan to move this quarter. Satisfied customers do not reshuffle this fast unless they know the stack they are currently using is provisional.
Three Immediate Actions for Security Directors
Inventory every agent’s credentials this quarter. Map which agents share credentials with other agents and which run on borrowed human or service-account identities. The goal is zero shared credentials between agents and zero borrowed human identities. Agents that touch multiple systems need multiple scoped identities, not one.
Sandbox the riskiest agents first. Isolation is the least-adopted control at 30% and the only one that contains blast radius after prevention fails. Rank agents by the sensitivity of what they touch and isolate the top of the list. Above 1,000 employees, where isolation falls to 20%, this is the single highest-return move in the dataset.
Match the budget to the incident rate. A third of enterprises fund agent security at 5% or less of the security budget, even though more than half have already had an incident or near-miss. Nine percent allocate more than 25% today. The exposure-to-containment gap demands a proportional response.
The board’s question is simpler than any technical architecture. If one of our AI agents was compromised this afternoon, which systems did it touch, and whose credentials was it holding? For the 69% of enterprises running agents on shared credentials, the answer is a shrug. The trail goes cold at the key.
The full Q2 Agentic Security report, with the complete vendor matrix, industry cuts, and the full dataset behind these charts, is scheduled for release on July 14 and 15 at VB Transform, held at Hotel Nia in Menlo Park. The open question it leaves is whether enterprises close the agent security gap on their own terms, or whether a confirmed breach closes it for them.