Aug 12, 2026
AI

Agentic security survey finds containment lags runtime permissions

A July survey found 65% of active enterprise agent programs enforce scoped permissions, while only 18% isolate high-risk agents.

Wei-Lin Zhao

By Wei-Lin Zhao · AI Correspondent

· 3 min read

A VentureBeat Pulse Research agentic security survey found that 65% of organizations with AI agents live or in pilot enforce scoped identities and permissions at runtime, while 18% isolate high-risk agents in sandboxes. The 47-percentage-point difference is a directional sign that companies are more likely to control and observe agent activity than to contain the damage when controls fail.

The July 2026 survey covered 116 respondents at organizations with more than 100 employees. Its runtime-control results draw on the 93 respondents whose organizations had agents in production, pilot or limited rollout. VentureBeat says the sample was self-selected rather than probability-based, so the results describe this cohort, not all enterprises.

What does the agentic security survey show?

Logging and runtime permissioning were more common than isolation. Fifty-six percent of the 93 applicable respondents said they monitor and log agent activity, compared with 65% using runtime-scoped identities and permissions and 18% sandboxing their highest-risk agents.

Those are distinct layers of control. Monitoring provides a record of activity. Runtime permissions are intended to block actions outside an agent's approved scope. Isolation separates an agent or its environment from other systems, limiting the potential scope of harm if an agent is compromised, misconfigured or induced to take an unauthorized action.

The finding is particularly relevant as more respondents move agents out of experiments. Fifty-three percent said their organization had agentic AI systems in production, and another 27% reported a pilot or limited rollout. Among organizations with agents in production, 21% reported enforcing isolation; only 8% reported both enforcement and isolation, according to the research.

Identity controls remain uneven

The survey also points to a gap between per-agent identity practices and credential hygiene across the fleet. Forty-nine percent of all surveyed organizations said every agent had its own scoped, managed identity. Yet 63% reported credential sharing somewhere in their agent fleets, and only 29% reported both scoped identities and no credential sharing anywhere.

For operators, that distinction affects how easily an agent action can be traced and how broadly access can spread. A dedicated, scoped identity can constrain an individual agent's access, while shared credentials make it harder to separate responsibilities across agents and workflows. The survey does not identify the systems, workloads or credentials involved in those responses.

Incidents and tool buying add urgency

Fifty-three percent of respondents reported an agent-security event: 19% reported a confirmed incident and 38% said they had identified a near-miss before harm occurred. Those component figures should not be added together because the incident question allowed overlapping responses.

The buying signals are mixed. Among respondents naming a primary security layer, 92% named a hyperscaler- or model-provider-native option. At the same time, 74% said they planned to adopt, add or replace agent-security tooling within 12 months. The reported satisfaction score was 4.29 out of 5, based on 76 respondents who answered that question.

That combination does not establish a market-wide shift, but it suggests that teams deploying agents are still assembling control stacks. The survey was fielded in one July 2026 wave, and VentureBeat explicitly characterizes its 116-response sample as suitable for directional reading rather than precise measurement.

This story draws on original reporting from VentureBeat.

More from AI

All AI →