Major Gaps in Enterprise AI Agent Management and Containment Strategies
According to VentureBeat's survey conducted six times from January 2025 (targeting 440 enterprise security professionals), 53% of companies have experienced security incidents related to AI agents, while only 18% of companies can properly isolate the highest-risk agents. Only 8% of companies implement both permission restrictions and isolation for agents simultaneously, revealing that the majority of companies lack effective containment mechanisms to address mounting risks.

A VentureBeat survey has revealed that many enterprises face a critical gap between "believing they have implemented security measures" and "actually having functioning protections" for AI agents—autonomous AI systems that perform tasks independently. Conducted six times starting in January 2025, this survey tracked 440 enterprise security professionals and has continuously monitored risk realities as AI agent adoption accelerates.
According to the survey results, 53% of responding companies have already experienced security incidents or near-incidents related to AI agents. While 65% of companies report limiting agent operational permissions in real time, only 18% of companies have isolated high-risk agents from other systems. Furthermore, only 8% of all enterprises implement both permission restrictions and isolation simultaneously. In other words, very few companies have established operational frameworks that can actually contain damage when problems occur.
Cloud providers and AI platform vendors fill this gap in security measures through the security features they provide. The July survey revealed that among companies deploying some form of tools as a primary security layer, 92% rely on native features from hyperscalers or AI platform providers. However, this dependence on external solutions may cause companies to fall behind in addressing their own unique risks.
The survey also uncovered an interesting trend regarding the evaluation of security tools. Among 46 companies that experienced incidents or near-incidents, the average tool satisfaction score was 4.39 out of 5, while among 55 companies without incident experience, 30 of them averaged 4.13. In other words, a reversal phenomenon occurs where tools that actually prevented problems receive higher ratings. Additionally, among 17 companies that isolated their highest-risk agents, the average tool rating was 4.00, while companies that did not isolate agents averaged 4.35—higher scores.
These figures reveal a structural issue: enterprise tool evaluations are heavily influenced by "experienced outcomes" rather than actual safety. Companies without incident experience have no opportunity to verify whether tools truly function, making their ratings lower. Conversely, companies that narrowly prevented problems elevate their trust based on the experience of being "saved." Through seven months of data, VentureBeat points out this structure where "rescue experience also serves as marketing."
As a notable individual case, Rajat Tanejia, Chief Technology Officer at Visa, announced that he conducted security testing on Visa's own payments network using Anthropic's AI model "Mythos" at VB Transform 2026. In this test, minor vulnerabilities linked together in sequence created a functioning attack path. Visa has released a complete set of tools to control this test as open source. Such efforts represent an example of an enterprise that possesses both the technical foundation and organizational framework to translate discovered problems into actual remediation measures.
While AI agents are increasingly being deployed in enterprises as a means to improve operational efficiency, the scope of impact from agent malfunction or external exploitation could be greater than with traditional software. The state revealed by this survey—"configured but unable to contain"—is a risk that cannot be overlooked as investment in agent AI continues to expand. The coexistence of permission management and isolation, along with moving away from external dependence, is likely to become the focus of enterprise security going forward.
This article is an original work independently written and edited by the AI issue editorial team based on factual reporting. © AI issue. Unauthorized reproduction, redistribution, or use for AI training is prohibited.