VentureBeat Intelligence surveyed respondents at organizations with 100 or more employees in August about how they secure AI agents. OpenAI's guardrails are now the most common primary security layer for enterprise AI agents. The organizations relying on OpenAI's guardrails are more likely than other organizations to say attackers are ahead of their defenses. Among organizations running agents, 59% have had one cause a security incident or near-miss.
Enterprises now rely on OpenAI more than on any other company to secure their AI agents. In August, 40% of the organizations that named a primary security layer for their agents chose OpenAI's built-in guardrails, up from 21% in July. Microsoft Azure's share in August was 22%.
The model and cloud providers now dominate agent security. OpenAI, Microsoft Azure, Google Cloud, Anthropic and AWS are the primary security layer at 99% of the organizations that named one. The providers' controls include OpenAI's moderation tools, Microsoft's Purview data-protection tools and AWS's Bedrock Guardrails. Specialist security and identity vendors are the primary layer at about 1%.
The organizations relying on OpenAI are also more likely than other organizations to say attackers are ahead. Among organizations whose primary agent security layer is OpenAI's, 43% say attackers using AI are ahead of their defenses. Among organizations relying on any other primary layer, 16% say so.
We ran the August survey the month after Hugging Face and OpenAI disclosed, on July 16 and July 21, that OpenAI's own test models had broken into Hugging Face's production infrastructure. In an August 26 post, OpenAI said the models ran in an internal evaluation without the safeguards of its public products. OpenAI also said the incident did not affect OpenAI customer data or products. The survey did not ask about the incident.
Security teams still got a live example of what a capable AI agent can do. OpenAI's test models used software flaws that no one had reported before to escape a sandbox built to keep them off the internet.
Agent incidents are already common at enterprises. Among organizations running agents, 59% say an agent caused a confirmed security incident or a near-miss in the past 12 months, and 30% report a confirmed incident.
Most enterprises still let their agents share credentials. Only 38% of organizations with agents in production give every agent its own identity. The other 62% run some or all agents on shared API keys, or on a person's or a service account's login. Shared credentials make it harder for a security team to trace an action to one agent, and to shut off one agent without shutting off the others.
Few enterprises build their security program around isolation. Only 9% of respondents say isolating high-risk agents in a sandbox best describes their program, and no respondent named a sandboxing tool among the platforms they use.
Many enterprises that say they enforce agent permissions at runtime still run agents on shared credentials. Among organizations with agents in production that chose the enforce posture, 59% also say some or most of their agents share credentials.
The enterprises that have already had an incident or near-miss are far more likely to plan to adopt new agent security. Among organizations running agents, 91% of those that had an incident or near-miss plan to adopt new agent security within 12 months, against 45% of those that had neither. Yet 76% of organizations running agents put 10% or less of their security budget into AI and agent security.
Finding 1. OpenAI is now the primary security layer for AI agents at 40% of enterprises that named one, nearly double July's share
OpenAI, Microsoft Azure, Google Cloud, Anthropic and AWS together are the primary agent security layer at 99% of the organizations that named one, and OpenAI leads the group.
A primary agent security layer is the set of controls a company relies on first to keep its AI agents in bounds.
We asked respondents which agent security vendors or platforms they use today and which one is their primary agent security layer.
Finding 1 — Primary agent security layer
Base: 106 respondents who named a primary agent security layer. One answer each. The five model and cloud providers combined: 99%. The one specialist security and identity vendor named was Okta for AI Agents.
OpenAI was chosen as the primary layer by 40% of organizations that named one, nearly twice Microsoft Azure's 22%. OpenAI's share was 21% in July. Respondents rate their agent security tools well, with averages of 4.1 out of 5 for overall satisfaction, 4.1 for ease of implementation and 4.2 for value for money.
We count identity vendors such as Okta together with specialist security vendors as specialist security and identity vendors, because both sell agent controls that sit apart from the platform the agent runs on. Together they are the primary layer at about 1% of the organizations that named one.
Few respondents use specialist security and identity vendors at all. On a separate question, respondents named every platform they use for agent security, and could name more than one. Only 17% of the respondents who named their platforms use any of the specialist security and identity vendors.
Finding 1 — Platforms in use for agent security
Base: 108 respondents who named the platforms they use. Several answers allowed, so shares add up to more than 100%. The specialist row counts each respondent once and excludes Microsoft Entra Agent ID, which comes from Microsoft.
OpenAI appears at 49% of organizations, Microsoft Azure and Google Cloud at 44% each, Anthropic at 27% and AWS at 12%. No other platform reached more than 6% of respondents, and no respondent named SentinelOne, HiddenLayer or a runtime sandboxing tool.
Finding 2. Enterprises relying on OpenAI are nearly three times as likely to say attackers are ahead of their defenses
Among organizations whose primary agent security layer is OpenAI's, 43% say attackers using AI are ahead of their defenses, against 16% of organizations relying on any other primary layer.
Frontier AI models are getting better at finding and exploiting software flaws, and security teams now defend against attackers who use those models. We asked all respondents who has the advantage in their organization's security today.
Finding 2 — Who has the advantage
Base: 137 qualified respondents. One answer each.
Across all respondents, 34% say attackers and defenders are roughly even, 22% say their own defenses are ahead and 21% say attackers are. Seventeen percent answered "don't know."
Finding 2 — Who has the advantage, by primary agent security layer
Bases: 42 respondents who named OpenAI as their primary agent security layer, and 64 who named any other. One answer each.
We call organizations whose primary agent security layer is OpenAI's "organizations relying on OpenAI."
The gap between organizations relying on OpenAI and the rest holds among organizations that had an incident or near-miss. Among organizations that had an incident or near-miss, 48% of those relying on OpenAI say attackers are ahead, against 21% of those relying on another primary layer. The gap also holds outside technology and software companies, at 45% against 13%. Too few technology and software companies named a primary layer to compare.
The survey asked what respondents believe about attackers, and did not measure how exposed each organization is. Organizations relying on OpenAI reported incidents and near-misses at a rate too close to call against other organizations. We cannot tell why organizations relying on OpenAI are more likely to say attackers are ahead.
Finding 2 — Who has the advantage, organizations running agents
Bases: 64 organizations running agents that had an incident or near-miss, and 40 that had neither. One answer each.
Among organizations running agents, 33% of those that had an incident or near-miss say attackers are ahead, against 15% of those that had neither. We compared these two groups on five measures. Once we allow for the number of measures compared, the gap on attackers is too close to call. VentureBeat Intelligence will ask the question again in the next Pulse.
Finding 3. 59% of enterprises running AI agents have already had an agent cause a security incident or near-miss
Among organizations running agents, 59% report an incident or near-miss in the past 12 months, and 30% report a confirmed incident.
An agent already holds the permissions someone gave it. So an agent can take an unauthorized action or expose data even when no outside attacker is involved, and an attacker who hijacks an agent inherits its permissions.
We asked respondents whether an AI agent had caused a security incident or near-miss at their organization in the past 12 months. Examples included an unauthorized action, a data exposure, or a hijacked or manipulated agent.
Finding 3 — Agent security incidents or near-misses, past 12 months
Base: 109 respondents whose organizations run agents in production or in a pilot. One answer each.
We count confirmed incidents and near-misses together, because both are security events caused by an agent. A near-miss means a control caught the agent before it did harm. A near-miss does not show that the same control will catch the next one.
The methodology explains how answers that say nothing about incidents are counted.
Organizations with agents in production reported an incident or near-miss at 54%, against 66% of those still piloting, a gap too close to call.
Finding 4. 62% of enterprises with AI agents in production let those agents share credentials
Only 38% of organizations with agents in production give every agent its own scoped, managed identity; the rest run some or all agents on shared or human credentials.
When several agents share one API key, or run on a person's own login, the credential identifies the key or the person instead of the agent. Shared credentials make it harder for a security team to trace an action to one agent. Other activity logs may still show which agent acted, and this survey did not ask about them.
Shared credentials cause two more problems. Shutting off one misbehaving agent means revoking a key that every other agent on it also uses. And an agent running on a person's login can reach much of what that person can reach.
We asked all respondents how their organization handles credentials and identity for AI agents in production. The table shows the answers from organizations with agents in production.
Finding 4 — Credential handling
Base: 68 respondents whose organizations run agents in production. One answer each. Planning to adopt agent security within 12 months: 69% with per-agent identity throughout (Base: 26) and 69% sharing credentials (Base: 42).
Among the organizations with agents in production, 62% share credentials wholly or partly, and 38% give every agent its own identity.
Of the organizations sharing credentials, 55% give scoped identities to some of their agents but not all.
Among organizations with agents in production, those giving every agent its own identity reported incidents or near-misses at nearly the same rate as those sharing credentials, 54% against 55%. In the June Pulse, the gap between organizations sharing credentials and those giving every agent its own identity was too close to call.
None of the organizations with agents in production that share credentials named Okta, a non-human identity platform or Microsoft Entra Agent ID among the platforms they use.
Finding 5. 59% of enterprises with agents in production that say they enforce agent permissions at runtime also say some or most agents share credentials
Among respondents with agents in production who chose the enforce posture, 59% also say some or most of their agents run on shared or human credentials.
We asked all respondents which of four postures best describes their organization's agent security program. On a separate question, we asked how their agents' credentials are handled.
Three of the postures describe different kinds of defense. Observing means monitoring and logging what agents do, which tells a security team what happened. Enforcing means checking each agent's permissions at runtime, which tries to stop an agent from doing what it should not. Isolating means running high-risk agents in a sandbox, which limits the damage when an agent gets past other controls.
Finding 5 — Agent security program
Base: 137 qualified respondents. One answer each.
Finding 5 — Credentials reported by respondents who say they enforce and run agents in production
Base: 37 respondents with agents in production who chose the enforce posture, cross-referenced against their own answer on agent credentials. One answer each.
The enforce option reads "agents have scoped identities and permissions, enforced at runtime." Only 41% of the respondents with agents in production who chose it also said every agent has its own identity. The other 59% said some or most agents share credentials. Among those in production who chose it, 43% said some agents are scoped and many still share, and 16% said their agents mostly run on shared or human credentials.
Two explanations fit the data. Respondents may be describing the program they are building toward, not the coverage they have reached. Or they may be claiming more enforcement than their credential setup reflects.
In August, 29% of respondents chose the observe posture, and only 9% chose the isolate posture.
In the Hugging Face incident, OpenAI's test models escaped a sandbox built to keep them off the internet. OpenAI's response included more isolated sandboxes for workloads that run code its models write.
We can test this finding on August data only, because July's respondents could choose several answers on both questions. VentureBeat Intelligence will test it again in the October Pulse.
Finding 6. Enterprises that have had an agent incident or near-miss are far more likely to plan to adopt agent security
Among organizations running agents, 91% of those that had an incident or near-miss plan to adopt agent security within 12 months, against 45% of those that had neither.
A new or replacement agent security solution changes the controls that keep a company's agents in bounds, such as how each agent is identified, which actions it may take at runtime and where it runs. Choosing, testing and connecting a new solution to the agents a company already runs takes time. Until the new solution is running, those agents keep operating under the company's current controls.
We asked all respondents whether they plan to adopt a new, additional or replacement agent security solution in the next 12 months, and when.
Finding 6 — Adoption plan
Base: 137 qualified respondents. One answer each.
Seventy-two percent of respondents plan to adopt agent security within 12 months, and 32% plan to adopt it within three months.
Finding 6 — Adoption plan, organizations running agents
Bases: 64 organizations running agents that had an incident or near-miss, and 40 that had neither. One answer each.
Organizations that had an agent incident or near-miss also plan to adopt sooner. Among organizations running agents, 55% of those that had an incident or near-miss plan to adopt within three months, against 18% of those that had neither.
VentureBeat Intelligence will check in the next Pulse whether the gap holds.
Budget share tells a different story. Among organizations running agents, 25% of those that had an incident or near-miss put more than 10% of the security budget into AI and agent security. The figure is 23% for those that had neither, a gap too close to call.
Finding 6 — Share of security budget on AI and agent security
Base: 109 respondents whose organizations run agents in production or in a pilot. One answer each. AI and agent security at 10% or less of the security budget: 76%.
What changed since the July Pulse
VentureBeat Intelligence asked the same questions in July and August, but of different people each month. With different people answering each month, a small difference can come from chance instead of a real change in the market. The table shows each measure in both months and whether the difference is large enough to count as a real change. Three measures qualify, and all three concern which vendor is the primary agent security layer.
What changed enough to call
Since the July Pulse — What changed enough to call, July → August
Base: 92 or 93 respondents in July and 106 or 109 in August, depending on the question. "Changed enough to call" means the difference is larger than chance alone would produce at these sample sizes. "Too close to call" means the difference is within that range, so this report does not describe it as a change. The methodology gives the test used for each line.
The five model and cloud providers were the primary layer at 92% of organizations that named one in July and at 99% in August. Within that group, OpenAI rose from 21% to 40%, and Anthropic fell from 26% to 13%.
Technology and software companies made up a smaller share of respondents in August, 15% against 38% in July. OpenAI's share rose among technology and software companies, from 19% to 53%, a real change. Among all other respondents, the move from 22% to 37% is too close to call on its own. Reweighting August's answers to July's mix of technology and software companies and other companies gives OpenAI about 44%, so the change in who answered did not produce the rise.
What did not change enough to call
The incident rate, the figure most likely to be quoted, is the one measure in the table that did not change enough to call: 55% in July and 59% in August. We do not claim that agent security incidents rose.
What we did not compare
The table leaves out five measures: security program posture, credential handling, budget share, the attacker-versus-defender question and the confirmed-incident figure on its own. In July, respondents could choose several answers on those questions although each asked for one, as the methodology explains.
We also did not test July's gaps between organizations that had an incident or near-miss and those that had neither. Those gaps cover plans to adopt within 12 months and the view that attackers are ahead.
The bottom line: Enterprises are trusting the model and cloud providers to secure their AI agents, while most still let those agents share credentials
In July, OpenAI's test models showed what a capable AI agent can do once it escapes its sandbox. Among organizations with agents in production, 62% let their agents share credentials. Only 9% of respondents say isolating high-risk agents best describes their security program.
Enterprises have made the model and cloud providers their primary agent security layer, and OpenAI leads them at 40%. Yet the organizations relying on OpenAI are more likely than other organizations to say attackers using AI are ahead of their defenses. Among organizations running agents that had an incident or near-miss, 91% plan to adopt new agent security within a year.
Respondent profile
Company size | Share of 137 |
100 to 250 employees | 31% (42) |
251 to 1,000 employees | 36% (50) |
1,001 to 5,000 employees | 18% (24) |
5,001 to 10,000 employees | 7% (9) |
More than 10,000 employees | 9% (12) |
Base: 137 respondents. One answer each.
Role | Share of 137 |
Manager | 46% (63) |
Individual contributor | 20% (28) |
C-suite | 18% (24) |
VP or director | 16% (22) |
Base: 137 respondents. One answer each.
Role in AI purchasing | Share of 137 |
Final decision maker on AI purchasing | 51% (70) |
Recommender or influencer | 32% (44) |
User | 9% (13) |
No involvement | 7% (10) |
Base: 137 respondents. One answer each.
AI agent deployment | Share of 137 |
Agents in production | 50% (68) |
Agents piloting or in limited rollout | 30% (41) |
Not yet, actively evaluating | 15% (20) |
No plans in the next 12 months | 3% (4) |
Don't know | 3% (4) |
Base: 137 respondents. One answer each.
Industry | Share of 137 |
Healthcare and life sciences | 25% (34) |
Technology and software | 15% (21) |
Retail and e-commerce | 12% (16) |
Financial services | 12% (16) |
Manufacturing | 11% (15) |
Transportation and logistics | 9% (12) |
Education | 5% (7) |
Telecommunications and media | 4% (6) |
Professional services and consulting | 4% (5) |
Government and public sector | 3% (4) |
Energy and utilities | 1% (1) |
Base: 137 respondents. One answer each.
Methodology
VentureBeat Intelligence fielded this VB Pulse survey in August and received 141 responses. Of those, 137 qualified for this report. Every figure is based on those 137 respondents unless a smaller number is stated with the figure; the note under each table gives its base.
Organizations running agents. Where this report refers to organizations running agents, it combines the 68 with agents in production and the 41 piloting or in limited rollout, 109 in all.
Credential figures. The credential question asked about agents in production, so credential figures in Findings 4 and 5 are for the 68 organizations with agents in production.
The incident figure. The incident figure is reported on all 109 organizations running agents. Five percent gave answers that say nothing about incidents: 3% do not track them, and 2% chose "not applicable," which read "no agents in production" and was chosen only by organizations still piloting. They stay in the base, counted as neither an incident nor a clean record. Excluding them would raise the figure from 59% to 62%, and this report uses the lower figure. The question offered no "don't know" option, although "we don't track this" was available.
Program posture. Every respondent whose organization does not run agents chose "no dedicated agent security program yet," as did 1% of organizations running agents. That figure therefore describes organizations without agents almost entirely.
Ratings. About 100 respondents answered each of the three rating questions in Finding 1.
Statistical tests. A difference between two groups, or between July and August, counts as real only when its test gives p below 0.05; otherwise it is too close to call. Two percentages are compared with a two-proportion z-test, or with Fisher's exact test when either group has fewer than 40 respondents. To rank two answers to one single-answer question, we use an exact binomial test. When the report compares the same two groups on many measures, it describes only differences that stay clear after allowing for the number of comparisons. We compared organizations relying on OpenAI with all other organizations that named a primary layer on 13 measures, and the attackers-ahead gap is the one that stays clear.
Some groups in this report have fewer than 40 respondents: enforce-posture respondents with agents in production, 37; organizations in production giving every agent its own identity, 26; organizations relying on OpenAI that had an incident or near-miss, 29; organizations relying on another primary layer that had an incident or near-miss, 34; organizations outside technology and software companies relying on OpenAI, 33; technology and software companies that named a primary layer in August, 17. Percentages for groups this small are less precise; for a group of 17, a result could differ by about 24 percentage points either way from the true figure.
The July comparison. VentureBeat Intelligence surveyed a separate sample each month, so July and August comparisons describe two different groups of respondents. The question text was the same in both months, but in July respondents could choose several answers on five single-answer questions: program posture, credential handling, budget share, the attacker-versus-defender question and the incident question. The month-to-month table therefore compares the incident question only on the combined incident-or-near-miss rate and leaves the other four out. For the same reason, July's published enforcement figure among organizations running agents, 65%, cannot be compared with August's 50%.
VentureBeat Intelligence surveys a self-selected group of VentureBeat readers and panel respondents. The results describe those respondents, not every enterprise, and apply to the wider market only as far as this mix of respondents allows.
