AI & Automation

Nobody Agrees How Bad It Is: Three AI Agent Security Studies, Three Very Different Numbers

One survey puts AI agent security incidents at 65% of enterprises, another at 88%. The disagreement is itself the finding, because 82% of organisations are still discovering agents they did not know they had.

August 26, 2026 · AI & Automation
Two monitors and a tablet displaying code on a desk in a darkened workspace

Key Takeaways

  • The Cloud Security Alliance and Token Security, surveying 418 IT and security professionals in January 2026, found 65% had at least one AI agent-related security incident in the previous 12 months.
  • Gravitee's survey of more than 900 executives and practitioners, published in February 2026, put the same figure at 88% reporting confirmed or suspected incidents.
  • 82% of CSA respondents had discovered previously unknown AI agents in their environments, while 68% believed they already had strong visibility.
  • Only 21% of organisations have a formal process for decommissioning an agent, and Gravitee found an average of 47.1% of an organisation's agents are actively monitored.

Three credible surveys published within months of each other put enterprise AI agent security incidents at 50%, 65% and 88%. The Cloud Security Alliance, working with Token Security, surveyed 418 IT and security professionals in January 2026 and reported 65% experiencing at least one incident caused by an AI agent in the previous year. Gravitee, polling more than 900 executives and technical practitioners a month earlier, reported 88% with confirmed or suspected incidents. A DigiCert survey in July landed near 50%.

The instinct is to pick one. The better move is to notice that a 38-point spread on a question this basic tells you something the individual numbers cannot: organisations do not reliably know when an AI agent has caused a problem, because they do not reliably know what agents they are running. The CSA data makes that explicit. 82% of respondents had found previously unknown agents operating in their environment. In the same survey, 68% said they had strong visibility.

A 38-Point Spread Is a Measurement Problem

Read the definitions and the gap starts to make sense. Gravitee asked about confirmed or suspected incidents, a deliberately wide net that captures the anomaly nobody fully explained. CSA asked about incidents attributed to AI agents, which requires someone to have completed an attribution. DigiCert scoped to unauthorised or misconfigured agents over six months. Each is defensible. None is measuring quite the same thing, and the range between them is roughly the size of the population of incidents that happened but were never classified.

That matters more than a survey methodology footnote usually does, because the whole governance response depends on detection. A control framework built around reviewing agents before they go live is aimed at a population that Gravitee suggests is a minority of what is actually running: only 14.4% of its respondents said all their agents went live with full security or IT approval, while 80.9% of technical teams had already moved past planning into active testing or production.

“AI agents are outpacing the identity systems meant to secure and control them, and it's already showing up in unknown agents and real incidents in the enterprise.”

Itamar Apelblat, Chief Executive Officer and Co-Founder, Token Security

The Governance Gap Is Really a Lifecycle Gap

The single most revealing statistic in the CSA work is not about detection at all. Only 21% of organisations have a formal process for decommissioning an AI agent. Agents are created for a project, granted credentials and permissions to do their job, and then simply left running when the project ends. CSA calls the result retirement debt: identities with standing access, no owner, and no review date, accumulating quietly in exactly the places nobody is monitoring.

Gravitee's identity findings describe the same problem from the other end. Only 21.9% of teams treat agents as independent, identity-bearing entities, and 45.6% rely on shared API keys for agent-to-agent authentication. A shared key is, by construction, an identity that cannot be revoked without breaking something else and cannot be attributed to a single actor after the fact. It is also why an agent-caused incident is hard to classify as one: the logs show a key, not an agent.

On average, Gravitee found 47.1% of an organisation's agents actively monitored or secured. Slightly worse than a coin flip, on a class of software specifically designed to take actions without waiting to be asked.

Sector variation reinforces the point. Gravitee found the incident rate in healthcare at 92.7%, above its 88% overall figure, in an industry with more mature governance and stricter regulatory obligation than most. Better-governed sectors are not reporting fewer agent incidents. They are, plausibly, just detecting more of them.

“As agents gain greater autonomy, governance must evolve into a more unified, operational model.”

Hillary Baron, Assistant Vice President of Research, Cloud Security Alliance

What an Agent Incident Actually Looks Like

The consequences reported to CSA are mundane in a way that should be reassuring and is not. Data exposure featured in 61% of incidents, operational disruption in 43%, unintended business process actions in 41%, and financial losses in 35%. These are not exotic adversarial attacks on model weights. They are an automation with too much access doing something nobody intended, at machine speed, against production systems. The threat model that matters most is not a hostile actor subverting your agent. It is your own agent, correctly authenticated, doing the wrong thing.

The industry spent this year arguing about which incident number is right. The organisations that will come out of it well are the ones that noticed the argument was only possible because nobody can see the denominator.

Share

More in AI & Automation

All Resources →