Skip to content
AI Tech

The AI Agent Security Gap: Why 82% of Executives Are Confident and Wrong

The AI Agent Security Gap: Why 82% of Executives Are Confident and Wrong
Cybersecurity
Enterprises are deploying AI agents faster than any technology in memory. Barely half of them are watching what those agents actually do.
By Mr Wangdoo  |  Wangdoo.com  |  August 5, 2026  |  9 min read
Transparency notice: This article is based on published survey data from Gravitee’s State of AI Agent Security 2026 report and independent reporting from VentureBeat. Wangdoo has not independently tested any of the security platforms mentioned. Sources are listed at the foot of this article.

Picture a mid-sized financial services firm on a Tuesday afternoon. Somewhere inside its systems, an AI agent is reading a customer’s account history, pulling data from three internal platforms, and deciding what to do next — without a human in the loop, and in nearly half of all cases like it, without anyone watching either.

That’s not a hypothetical scenario. It’s the baseline finding from Gravitee’s State of AI Agent Security 2026 report, a survey of 750 senior technology leaders across the UK and US conducted in April, layered on top of a December 2025 baseline. The number of AI agents running inside the average enterprise has roughly doubled in four months. The share of those agents actually being monitored has barely moved at all.

enterprise AI agent fleet growth in four months (Dec 2025–Apr 2026)
52% mean monitoring coverage — meaning 48% of agents run unsecured
82% of executives confident their policies stop unauthorized agent actions
88% of organizations reported an AI agent security incident in the past year

The confidence-control paradox

Here’s the number that should stop any security leader mid-scroll: 82% of executives say they’re confident their existing policies protect against unauthorized agent actions. Meanwhile, 88% of organizations reported a confirmed or suspected AI agent security incident in the past twelve months. Those two figures come from the same survey, describing the same organizations.

Executive confidence and operational reality have essentially decoupled. It isn’t that leaders don’t understand the risk in the abstract — awareness is high. What’s missing is execution: consistent identity for agents instead of shared credentials, policy enforced centrally instead of per-agent, named ownership before an agent goes live, and continuous monitoring instead of periodic spot-checks.

“Most organizations don’t know what AI is actually running inside their business. That’s a structural problem, not a gap in intention. An employee connects an AI agent to Salesforce on a Tuesday. By Thursday, that agent has access to customer data, is sending emails on someone’s behalf, and nobody in security knows it exists.” — Ofer Klein, co-founder and CEO, Reco
Video: How to Secure and Trace AI Agent Identities — Gravitee (not a Wangdoo production)

Adoption is outpacing governance by design, not accident

The scale of the shift is what makes this hard to fix with a policy memo. Gravitee’s April cohort of active deployers is running 76 to 100 agents on average, up from a range of 26 to 50 just one quarter earlier — and that fleet is doubling roughly every quarter, tracking the same exponential curve Gartner has projected for the broader market. By the end of 2026, Gartner expects 40% of enterprise applications to be integrated with task-specific AI agents, up from under 5% in 2025.

Mean monitoring coverage, by contrast, sat at roughly 47% in December 2025 and had inched up to only about 52% by April 2026 — even as the total agent fleet doubled. That means the absolute number of unmonitored agents in production is growing, not shrinking, quarter over quarter. Only 9.5% of organizations secure more than 80% of their deployed agents. Just 14.4% send agents to production with full security or IT approval.

Key vulnerability: Most organizations still treat AI agents as extensions of human users — assigning them to shared service accounts or existing employee credentials rather than giving each agent its own identity. That makes it nearly impossible to trace which agent took which action, or to revoke one agent’s access without breaking five others.

Independent reporting from VentureBeat adds a sharper edge to this: across a three-wave survey of 108 qualified enterprises, only 21% reported having runtime visibility into what their agents are doing while those agents are actually acting. Monitoring without enforcement, and enforcement without isolation, is described as the most common security architecture currently in production — not an edge case.

Why the risk is structural, not a patching problem

Conventional cybersecurity assumes a person or a known system is behind every action, and that access can be reviewed on a predictable cycle. AI agents break both assumptions. An agent can be spun up by an individual team in minutes, without going through procurement or security review — the kind of “shadow AI” deployment that mirrors the shadow SaaS problem security teams never fully solved, except agents don’t just read data, they write, delete, and execute actions across connected systems.

Governance processes, meanwhile, still operate on review cycles measured in weeks. By the time a formal review is completed, an agent may already be running in production with access to critical systems, no security review on record, and no mechanism in place to enforce what it’s actually permitted to do.

Sector detail: Healthcare organizations reported AI agent security incidents at a higher rate than any other sector — 92.7%, against an 88% all-industry average. For a health system running agents that touch protected health information, that gap sits close to the line between a reportable breach and a regulatory finding of willful neglect under current HIPAA enforcement guidance.

Deployment pressure isn’t slowing down

None of this is cooling enterprise appetite for agents. 81.7% of organizations plan to deploy significantly more agents over the next 12 months, with travel and transport companies showing the strongest intent to expand at 90%. At the same time, 81% of respondents feel pressure to deploy agents quickly even when governance isn’t fully in place — a pressure felt most acutely at smaller companies, where 86.2% of firms with 250–999 employees report significant deployment pressure, compared with 61.3% at firms of 2,500–5,000 employees.

Despite that, 79.7% of respondents still believe it’s possible to move fast without compromising security. Set against the incident and monitoring data in the same report, that belief reads more like optimism than an evidenced position.

What a working defence actually looks like

The consistent recommendation across the security researchers cited in this reporting isn’t to slow deployment — it’s to treat each AI agent as its own identity-bearing entity from the moment it’s created, rather than as an extension of a human account.

  • Give every agent its own identity and credentials — never a shared service account or a borrowed employee login.
  • Require named ownership and a security review before any agent reaches production, not after an incident surfaces.
  • Build continuous runtime monitoring into agent deployment from day one, rather than periodic audits that lag weeks behind actual activity.
  • Enforce policy centrally across the whole agent fleet, instead of configuring rules on a per-agent, per-team basis.
  • Establish a formal decommissioning process — agents that outlive their purpose but retain access are quietly accumulating what researchers call “retirement debt.”

None of this is exotic. It mirrors identity and access management practices security teams already understand from the cloud era. The obstacle isn’t a lack of technical solutions — it’s that agent deployment is happening faster than most organizations’ governance processes can move.

My Take — Mr Wangdoo

What strikes me most about this data isn’t the security incidents themselves — it’s the confidence gap sitting right next to them. Eighty-two percent of executives believing their policies work, while eighty-eight percent of their own organizations were already hit, tells me the problem isn’t a lack of awareness at the top. It’s that awareness and infrastructure are moving at completely different speeds, and nobody’s forcing the two to reconcile.

I’ve watched a version of this story play out before with shadow SaaS — employees signing up for tools without IT’s knowledge, security teams playing catch-up for years. What’s different this time is that AI agents don’t just store data somewhere unsanctioned. They act. They write to databases, they send emails on someone’s behalf, they call APIs and trigger workflows, all without necessarily waiting for a human to say yes. An unsanctioned spreadsheet tool is a nuisance. An unsanctioned agent with write access to a production database is a different category of problem entirely.

The honest reading of this report is that most organizations know exactly what they should be doing and are choosing deployment speed over governance anyway, because the productivity case is too compelling to pause for. That’s a rational business decision in the short term. Whether it stays rational depends entirely on how expensive the incidents get before the monitoring catches up — and right now, the monitoring isn’t catching up.

Frequently asked questions

What is the AI agent security gap?

The AI agent security gap refers to the widening distance between how quickly organizations are deploying autonomous AI agents in production and how well those agents are being monitored and secured. According to Gravitee’s 2026 research, enterprise agent fleets are doubling roughly every quarter while monitoring coverage has moved only marginally, from about 47% to 52%, over the same period.

How many organizations have experienced an AI agent security incident?

Gravitee’s State of AI Agent Security 2026 report found that 88% of organizations reported a confirmed or suspected AI agent security incident within the past twelve months. In healthcare specifically, that figure rose to 92.7%.

Why do executives feel confident despite the risk?

The report identifies a “confidence paradox”: 82% of executives believe their existing policies protect against unauthorized agent actions, even though the same survey population reported an 88% incident rate. Researchers attribute this gap to policies existing on paper without the runtime monitoring or enforcement needed to make them effective in practice.

What’s the biggest technical mistake organizations are making?

Most organizations still assign AI agents to shared service accounts or existing employee credentials rather than giving each agent its own distinct identity. This makes it difficult to trace which agent performed which action, or to revoke a single agent’s access without disrupting others that share the same credentials.

Is this slowing down AI agent adoption?

No. Despite the security incidents, 81.7% of organizations plan to deploy significantly more agents over the next 12 months, and 81% of respondents report feeling pressure to deploy quickly even when governance isn’t fully in place. Deployment pressure was highest among smaller companies.

Sources

  1. Gravitee — “State of AI Agent Security Report 2026.” gravitee.io
  2. VentureBeat — “The enforcement gap: 88% of enterprises reported AI agent security incidents last year.” venturebeat.com
  3. Yahoo Finance (Singapore) — “AI adoption is accelerating faster than its security layer.” sg.finance.yahoo.com
  4. Gravitee — “State of AI Agent Security 2026 Report: When Adoption Outpaces Control.” gravitee.io/blog
Mr Wangdoo avatar
Mr Wangdoo
Founder and editor-in-chief of Wangdoo.com. Covering AI, cybersecurity, EVs, smart home, and emerging tech from Dublin, Ireland. All opinions are documentation-based; nothing here has been hands-on tested unless explicitly stated.