Companies are grading their AI security on a curve while 80% can't actually stop a rogue agent.
The Summary
- VentureBeat research found 53% of enterprises have had an agentic security incident or near-miss, yet those hit rated their security tools higher (4.39/5) than those spared (4.13/5)
- 65% enforce agent permissions at runtime, but only 18% isolate high-risk agents and just 8% do both
- 92% rely on hyperscaler and AI platform native controls as their primary security layer, creating a dangerous dependency gap
- Visa proved the threat by turning Anthropic's Mythos loose on its own payment network, where it chained minor weaknesses into working exploits
The Signal
Visa did something most companies won't. They aimed an AI model at their own infrastructure, gave it permission to hunt for vulnerabilities, and watched it turn scattered weak spots into exploit chains. Then they open-sourced the harness. That's what having actual engineering depth looks like. Most enterprises are nowhere close.
The data from VentureBeat's six waves of research since January tells a darker story. Over half of the 440 qualified enterprise security respondents surveyed have already experienced an agentic security incident or near-miss. Not theoretical risk. Actual events. And the gap between what companies think they're protecting and what they're actually securing is widening.
"65% enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents, and just 8% pair enforcement with isolation."
Here's where it gets interesting. The enterprises that got hit are more satisfied with their tools than the ones that dodged incidents. Companies that experienced breaches or near-misses rated their security at 4.39 out of 5. Companies with clean records rated theirs at 4.13. That's not a typo. Getting burned makes you more confident in your defenses, not less.
This is survivorship bias in real time. Any tool that saves you from disaster becomes your hero, regardless of whether it actually works or you just got lucky. The market is too young for pattern recognition. Nobody knows what good looks like yet, so they're grading on effort and proximity to pain, not actual capability.
The dependency problem is worse. 92% of enterprises name hyperscalers and AI platform providers as their primary security layer. That means most companies are betting their agentic futures on the native controls built into AWS, Azure, GCP, or OpenAI's platform. These controls weren't designed for the attack surface agents create. They're general-purpose identity and access tools stretched to cover a completely different problem.
Key gaps in enterprise agentic security:
- Only 8% combine runtime permission enforcement with agent isolation
- 47% have experienced no incidents yet, creating false confidence in inadequate tooling
- Reliance on provider-native controls leaves containment responsibility with platforms not built for agentic threats
The containment gap is the real story. Two-thirds of enterprises can check what an agent is allowed to do. But less than one in five can actually isolate a high-risk agent when it starts acting out. Those are table stakes getting confused for the whole game. Knowing what an agent should do and stopping it when it goes rogue are different problems. Most companies have solved the first and think they've solved both.
The Implication
If you're running agents in production, the question isn't whether you'll have an incident. It's whether you'll be able to contain it when it happens. Runtime permissions are necessary. Isolation is the difference between a contained event and a cascading failure.
The enterprises that will survive the next 24 months of agentic expansion are the ones building containment depth now, not the ones congratulating themselves on avoiding the first wave of incidents. If Visa can point Mythos at its own payment rails and live to tell about it, you can probably handle red-teaming your CRM automations. Start there. Build the muscle before you need it.