According to the findings of a new study, most organizations grant AI agents extensive access to their systems and data, yet only a third secure each agent with a dedicated identity, with most agents continuing to share credentials. Only 30% of companies have segregated and isolated high-risk agents, and commonly used security tools are mainly those provided by AI model vendors, such as OpenAI, Google, and Microsoft, rather than specialized or customized solutions.
Despite these structural weaknesses, security budgets for these agents remain low, and only one-third of companies believe their defenses against AI-driven attacks are effective. The majority of organizations also plan to change or replace their security tools in the coming year. This research shows that the growth in the use of AI agents has outpaced security controls, and the main issues remain in agent identity and isolation.

