Back to News
Market Impact: 0.2

The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials

+2
Artificial IntelligenceCybersecurity & Data PrivacyTechnology & InnovationBanking & LiquidityRegulation & LegislationInvestor Sentiment & Positioning

VentureBeat reports an “agent security gap”: 54% of 107 surveyed enterprises already had a confirmed AI-agent security incident (18%) or near-miss (36%). Only 32% give every agent a scoped managed identity and just 30% sandbox their highest-risk agents, while security relies mostly on provider-native guardrails (e.g., OpenAI 51%) and spending is light (most allocate 6–10% of the security budget to agent security). Despite high satisfaction (4.2/5), only 35% think defenses are ahead of AI-enabled attackers and 59% plan to adopt or replace agent security tooling within 12 months.

Analysis

This is less a headline risk for AI adoption than a budget-allocation lag: the gap is widest where autonomous systems need scoped identity and blast-radius containment, which means the next dollars should migrate toward vendors that can sit at the control plane rather than the model layer. That favors OKTA first, then CRWD and NET, because identity, runtime enforcement, and isolation are the missing enforcement points; provider-native guardrails are convenient, but they are also easiest for enterprises to treat as “good enough” until the first material incident forces a rethink.

Near term, the trade is not about immediate revenue upside. The more important catalyst is the next 1-3 earnings cycles, when management teams start quantifying attach rates for agent security and procurement budgets re-open after incidents; the risk is that the current comfort with bundled controls delays spend, pushing the real inflection into 2027. If model providers improve their native identity and sandboxing fast enough, MSFT/GOOGL/AMZN can keep the budget inside the platform and cap standalone TAM for the specialists.

The contrarian view is that the market may be overestimating the standalone cyber winner set: the default path is still bundled, so this may be more of a feature expansion for hyperscalers than a clean category breakout for every “AI security” name. The cleanest falsifier is no visible increase in identity- or isolation-related win rates on upcoming earnings calls, or continued evidence that enterprises keep buying only provider-native controls despite repeated incidents. In that case, the thesis shifts from “new spend” to “reshuffled spend,” and the upside for pure-play specialists is much smaller.