One survey puts AI agent security incidents at 65% of enterprises, another at 88%. The disagreement is itself the finding, because 82% of organisations are still discovering agents they did not know they had.
Key Takeaways
Three credible surveys published within months of each other put enterprise AI agent security incidents at 50%, 65% and 88%. The Cloud Security Alliance, working with Token Security, surveyed 418 IT and security professionals in January 2026 and reported 65% experiencing at least one incident caused by an AI agent in the previous year. Gravitee, polling more than 900 executives and technical practitioners a month earlier, reported 88% with confirmed or suspected incidents. A DigiCert survey in July landed near 50%.
The instinct is to pick one. The better move is to notice that a 38-point spread on a question this basic tells you something the individual numbers cannot: organisations do not reliably know when an AI agent has caused a problem, because they do not reliably know what agents they are running. The CSA data makes that explicit. 82% of respondents had found previously unknown agents operating in their environment. In the same survey, 68% said they had strong visibility.
Read the definitions and the gap starts to make sense. Gravitee asked about confirmed or suspected incidents, a deliberately wide net that captures the anomaly nobody fully explained. CSA asked about incidents attributed to AI agents, which requires someone to have completed an attribution. DigiCert scoped to unauthorised or misconfigured agents over six months. Each is defensible. None is measuring quite the same thing, and the range between them is roughly the size of the population of incidents that happened but were never classified.
That matters more than a survey methodology footnote usually does, because the whole governance response depends on detection. A control framework built around reviewing agents before they go live is aimed at a population that Gravitee suggests is a minority of what is actually running: only 14.4% of its respondents said all their agents went live with full security or IT approval, while 80.9% of technical teams had already moved past planning into active testing or production.
“AI agents are outpacing the identity systems meant to secure and control them, and it's already showing up in unknown agents and real incidents in the enterprise.”
Itamar Apelblat, Chief Executive Officer and Co-Founder, Token Security
The single most revealing statistic in the CSA work is not about detection at all. Only 21% of organisations have a formal process for decommissioning an AI agent. Agents are created for a project, granted credentials and permissions to do their job, and then simply left running when the project ends. CSA calls the result retirement debt: identities with standing access, no owner, and no review date, accumulating quietly in exactly the places nobody is monitoring.
Gravitee's identity findings describe the same problem from the other end. Only 21.9% of teams treat agents as independent, identity-bearing entities, and 45.6% rely on shared API keys for agent-to-agent authentication. A shared key is, by construction, an identity that cannot be revoked without breaking something else and cannot be attributed to a single actor after the fact. It is also why an agent-caused incident is hard to classify as one: the logs show a key, not an agent.
On average, Gravitee found 47.1% of an organisation's agents actively monitored or secured. Slightly worse than a coin flip, on a class of software specifically designed to take actions without waiting to be asked.
Sector variation reinforces the point. Gravitee found the incident rate in healthcare at 92.7%, above its 88% overall figure, in an industry with more mature governance and stricter regulatory obligation than most. Better-governed sectors are not reporting fewer agent incidents. They are, plausibly, just detecting more of them.
“As agents gain greater autonomy, governance must evolve into a more unified, operational model.”
Hillary Baron, Assistant Vice President of Research, Cloud Security Alliance
The consequences reported to CSA are mundane in a way that should be reassuring and is not. Data exposure featured in 61% of incidents, operational disruption in 43%, unintended business process actions in 41%, and financial losses in 35%. These are not exotic adversarial attacks on model weights. They are an automation with too much access doing something nobody intended, at machine speed, against production systems. The threat model that matters most is not a hostile actor subverting your agent. It is your own agent, correctly authenticated, doing the wrong thing.
The industry spent this year arguing about which incident number is right. The organisations that will come out of it well are the ones that noticed the argument was only possible because nobody can see the denominator.
Whitepaper
When only 47.1% of agents are monitored, runtime is the one place an over-permissioned automation becomes visible.
Download
Guide
A governance structure for the lifecycle problem the 21% decommissioning figure exposes, rather than for the model itself.
Download
Whitepaper
Data exposure featured in 61% of these incidents, and agents reaching into the enterprise content store are where that exposure usually begins.
Download
IT ops teams are deploying AI models faster than governance frameworks can keep up.
A survey of 250 IT and operations leaders on where deployments truly stand.