{"id":62714,"date":"2026-07-10T00:41:35","date_gmt":"2026-07-10T04:41:35","guid":{"rendered":"https:\/\/overcentral.com\/en\/?p=62714"},"modified":"2026-07-10T00:41:35","modified_gmt":"2026-07-10T04:41:35","slug":"ai-agents-shared-api-keys","status":"publish","type":"post","link":"https:\/\/overcentral.com\/en\/ai-agents-shared-api-keys\/","title":{"rendered":"69% of enterprises expose AI agents with shared API keys"},"content":{"rendered":"<p>Enterprise security teams are confronting a fundamental flaw in the architecture of their <a href=\"https:\/\/overcentral.com\/en\/ai-agent-development-sluggish\/\" title=\"Zuckerberg Confirms AI Agents Development Slower Than Hoped\" data-iacss-internal=\"1\">AI agent<\/a> deployments: 69% of organizations are running <a href=\"https:\/\/overcentral.com\/en\/woodside-ai-agents-lng-startup\/\" title=\"Woodside Deploys 50 AI Agents to Optimize LNG Plant Startups\" data-iacss-internal=\"1\">AI agents<\/a> that share credentials, transforming a single compromised agent into a catastrophic, multi-system breach where attribution is impossible. This finding from VentureBeat\u2019s June 2026 Pulse Research wave of 107 enterprises explains the unprecedented $22 billion acquisition spree by <a href=\"https:\/\/www.paloaltonetworks.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Palo Alto Networks<\/a>, <a href=\"https:\/\/www.crowdstrike.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">CrowdStrike<\/a>, and <a href=\"https:\/\/www.cisco.com\/\" target=\"_blank\" rel=\"noopener noreferrer\" data-iacss-external=\"1\">Cisco<\/a>, all of whom are betting that the next major security battleground is the identity and permissions layer of autonomous software.<\/p>\n<h2>The Shared Credential Problem: A Single Point of Catastrophic Failure<\/h2>\n<p>When one API key is shared across five AI agents, a compromise of any single agent inherits the cumulative permissions of all five workflows that key touches. The forensic trail goes cold immediately because five agents on a single account leave no record of which agent executed which action. Only 32% of enterprises grant every AI agent its own scoped, managed identity. Nearly half (48%) report that some agents have scoped identities while many still share credentials, and another 32% say agents largely run on shared <a href=\"https:\/\/overcentral.com\/en\/freesov-ai-tracking-api-keys\/\" title=\"FreeSOV delivers low-cost AI tracking with just API keys\" data-iacss-internal=\"1\">API keys<\/a> or borrowed human and service-account credentials. The survey allowed multiple selections from 107 respondents, and after deduplication, 69% flagged credential sharing in at least one answer.<\/p>\n<p>The scale of the problem is staggering. CyberArk\u2019s research puts machine identities at 82 for every human in organizations worldwide, with AI agents as the fastest-growing category. Cisco made the same diagnosis when it acquired Astrix Security, whose founders built the company specifically to manage the API keys, service accounts, and OAuth tokens that AI agents are now \u201cusing (and abusing)\u201d to execute work at scale.<\/p>\n<p>Adam Meyers, senior vice president of counter adversary operations at CrowdStrike, described the mechanism directly. Some AI systems have their own identities, but in other cases, \u201cpeople give their identity to the AI to take action on their behalf, and that also further kind of murkies the water and makes it very complex.\u201d When the identity is shared, attribution dies with it.<\/p>\n<h2>Exposure Scales With Size While Containment Collapses<\/h2>\n<p>Forty-nine percent of enterprises enforce scoped permissions at runtime, and 47% monitor and log agent activity. Only 30% sandbox their highest-risk agents, the one control that limits blast radius when the first two fail. This containment gap widens dramatically with company size. The incident rate for companies with 101 to 1,000 employees is 49%, but it shoots up to 63% for companies with more than 1,000 employees. Sandbox isolation moves in the opposite direction, falling from 35% to 20% at larger enterprises.<\/p>\n<p>At organizations with 101 to 250 employees, the gap between incident rate and isolation rate is just 7 points. Above 5,000 employees, that gap blows out to 60 points. Larger enterprises run more agents across more systems, which drives incidents up while sandboxing goes unfunded. The enterprises with the most agents have the least isolation around them, precisely the accounts where Palo Alto Networks, Cisco, and CrowdStrike are targeting their new product lines.<\/p>\n<h2>Borrowed Security Stacks: Default Guardrails Without Real Identities<\/h2>\n<p>The overwhelming majority of enterprises are relying on provider-native security stacks. OpenAI\u2019s built-in guardrails lead at 51%, Google Cloud reaches 36%, Microsoft Azure\u2019s Purview and Copilot Studio DLP reaches 35%, and Anthropic\u2019s managed-agent controls reach 29%. Eighty-two percent of respondents name a provider-native or hyperscaler control as their single primary agent security layer. The purpose-built specialists are in single digits: Palo Alto Networks\u2019 Prisma AIRS at 7%, CrowdStrike at 6%, and Okta for AI Agents at 4%.<\/p>\n<p>Bundled controls lead because they ship free and are enabled by default. They filter prompts and outputs, but they do not give an agent its own identity or sandbox it. Prompt-and-output filters evaluate whether a call looks malicious, an intent problem that cannot be solved at the language layer. CrowdStrike CTO Elia Zaitsev drew the line clearly at RSAC 2026: \u201cObserving actual kinetic actions is a structured, solvable problem. Intent is not.\u201d A scoped identity and an isolation boundary give a sensor something to track, while a shared credential on a bundled guardrail does not.<\/p>\n<p>Merritt Baer, chief security officer at Enkrypt AI and a former deputy CISO at AWS, described the risk succinctly: \u201cEnterprises believe they\u2019ve \u2018approved\u2019 AI vendors, but what they\u2019ve actually approved is an interface, not the underlying system. The real dependencies are one or two layers deeper, and those are the ones that fail under stress.\u201d<\/p>\n<h2>The Contradiction: High Satisfaction, Low Conviction, Active Shopping<\/h2>\n<p>Despite the glaring exposure, enterprises rate their agent security tooling 4.2 out of 5, with value for money at 4.1. Yet only 35% believe their AI-enabled defenses are ahead of AI-enabled attackers. Twenty-one percent say attackers lead, and another 21% say it is too early to tell. This contradiction reveals that enterprises trust their tooling more than they trust its outcomes.<\/p>\n<p>Budgets confirm the mismatch. Forty-six percent allocate 6 to 10% of the security budget to agent security, and a full third spend 5% or less. Half the sample has already had an incident or near-miss, but the funding does not match the exposure. However, 59% plan to adopt, add, or replace agent security tooling within 12 months, and 29% plan to move this quarter. Satisfied customers do not reshuffle this fast unless they know the stack they are currently using is provisional.<\/p>\n<h2>Three Immediate Actions for Security Directors<\/h2>\n<p>Inventory every agent&#8217;s credentials this quarter. Map which agents share credentials with other agents and which run on borrowed human or service-account identities. The goal is zero shared credentials between agents and zero borrowed human identities. Agents that touch multiple systems need multiple scoped identities, not one.<\/p>\n<p>Sandbox the riskiest agents first. Isolation is the least-adopted control at 30% and the only one that contains blast radius after prevention fails. Rank agents by the sensitivity of what they touch and isolate the top of the list. Above 1,000 employees, where isolation falls to 20%, this is the single highest-return move in the dataset.<\/p>\n<p>Match the budget to the incident rate. A third of enterprises fund agent security at 5% or less of the security budget, even though more than half have already had an incident or near-miss. Nine percent allocate more than 25% today. The exposure-to-containment gap demands a proportional response.<\/p>\n<p>The board&#8217;s question is simpler than any technical architecture. If one of our AI agents was compromised this afternoon, which systems did it touch, and whose credentials was it holding? For the 69% of enterprises running agents on shared credentials, the answer is a shrug. The trail goes cold at the key.<\/p>\n<p>The full Q2 Agentic Security report, with the complete vendor matrix, industry cuts, and the full dataset behind these charts, is scheduled for release on July 14 and 15 at VB Transform, held at Hotel Nia in Menlo Park. The open question it leaves is whether enterprises close the agent security gap on their own terms, or whether a confirmed breach closes it for them.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Enterprise security teams are confronting a fundamental flaw in the architecture of their AI agent deployments: 69% of organizations are running AI agents that share credentials, transforming a single compromised agent into a catastrophic, multi-system breach where attribution is impossible. This finding from VentureBeat\u2019s June 2026 Pulse Research wave of 107 enterprises explains the unprecedented [&hellip;]<\/p>\n","protected":false},"author":7,"featured_media":74456,"comment_status":"closed","ping_status":"","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/iili.io\/C0VM0N4.jpg","fifu_image_alt":"69% of enterprises expose AI agents with shared API keys","footnotes":""},"categories":[349],"tags":[],"class_list":["post-62714","post","type-post","status-publish","format-standard","has-post-thumbnail","category-articles"],"fifu_image_url":"https:\/\/iili.io\/C0VM0N4.jpg","fifu_image_alt":"69% of enterprises expose AI agents with shared API keys","_links":{"self":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62714","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/users\/7"}],"replies":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/comments?post=62714"}],"version-history":[{"count":0,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/posts\/62714\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media\/74456"}],"wp:attachment":[{"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/media?parent=62714"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/categories?post=62714"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/overcentral.com\/en\/wp-json\/wp\/v2\/tags?post=62714"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}