Original briefings. Zero spin.
Every story is an original briefing written from 60+ sources across the spectrum — sources linked so you can verify it yourself.
New Survey: 69% of Enterprises Still Share API Keys Across AI Agents, and $22 Billion in Security Deals Prove It's a Crisis

New Survey: 69% of Enterprises Still Share API Keys Across AI Agents, and $22 Billion in Security Deals Prove It's a Crisis
The Numbers Behind the Panic Buying
Since VentureBeat first flagged the enterprise AI agent security gap earlier this month, a clearer picture has emerged of just how thin the safety net actually is. A June 2026 Pulse Research survey of 107 enterprises with more than 100 employees found that 54% have already experienced a confirmed AI agent security incident (18%) or a near-miss caught before damage was done (36%). This represents actual incidents at more than half the companies surveyed.
The data that should concern any CFO or CISO: 69% of enterprises run AI agents with credential sharing somewhere in their deployment, according to the survey. Only 32% give every single agent its own scoped, managed identity. Another 32% admit their agents mostly run on shared API keys or borrowed human and service-account logins.
Why does that matter? Share one API key across five agents, and a single compromised agent inherits the access of all five. The attacker gets the accumulated permissions of every workflow that key touches. When five agents share one account, there's no clean forensic trail showing which agent did what. Investigators are left guessing.
Only three in ten enterprises isolate their highest-risk agents in sandboxes, according to the same research. That means seven in ten companies are letting their riskiest, most-privileged AI agents run without a containment boundary. If one gets compromised or goes haywire, there's nothing stopping it from touching everything else it's connected to.
Wall Street Already Priced This In
While enterprises drag their feet on identity management, the cybersecurity industry has been moving fast. Palo Alto Networks closed its acquisition of CyberArk on February 11 for $21.1 billion in total consideration, a deal it originally announced last July at roughly $25 billion. It's the largest acquisition in the company's history.
CrowdStrike closed its $740 million purchase of runtime authorization platform SGNL and, by June 15, had already shipped the first product from that deal: Continuous Identity for AI Agents. That's a company moving from acquisition to shipped product in under a year, which is fast by any corporate standard.
Cisco announced its intent to acquire non-human identity specialist Astrix Security on May 4 for a reported $400 million. Add it up and three companies have bet more than $22 billion in the past year on the exact layer of security that this survey shows most enterprises haven't finished building: identity and access control for autonomous agents.
Enterprises Like What They Have, But Plan to Ditch It
The security stack most enterprises actually run is borrowed, not purpose-built. OpenAI's guardrails show up in 51% of deployments, alongside Google's and Microsoft's cloud-native controls and Anthropic's managed-agent tools. Dedicated agent-security specialists barely register in the survey.
Satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Despite that satisfaction, a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they're already planning to replace.
Only about a third of enterprises believe their AI defenses are ahead of AI-enabled attackers. That's basically a coin flip on whether the good guys or the bad guys have the upper hand right now, according to the people running these systems.
The Fair Pushback
There's a reasonable counter-argument here worth stating plainly: not every enterprise needs bank-vault-level identity segregation for every low-stakes internal chatbot or drafting tool. A marketing team's AI agent that summarizes press releases doesn't carry the same blast radius as an agent with write access to a payments system or customer database. Security vendors selling identity platforms have an obvious financial interest in enterprises believing every agent is a five-alarm risk. Palo Alto Networks, CrowdStrike, and Cisco all profit directly from convincing CISOs that shared credentials are a five-alarm fire.
The survey's own data undercuts the "it's fine for low-stakes agents" argument, though. The 30% isolation of the highest-risk agents specifically means companies aren't even protecting the systems they themselves have identified as dangerous. This isn't a debate about whether the intern's chatbot needs a hardware security key. It's about whether the agents with real system access get any containment at all, and right now, seven in ten don't.
Spending on agent security remains a thin slice of the overall security budget, according to the survey, even as incidents climb and the vendor market races to build the identity and isolation tools enterprises say they want. The next data point to watch: whether that spending share moves when VentureBeat's full Q2 Agentic Security report, unveiled at the VB Transform conference in Menlo Park, gets adopted into next year's enterprise security budgets, or whether the 54% incident rate climbs higher first.
Sources used for this briefing
This briefing was written by UBH's AI agent — these are the reporting inputs it draws on, linked so you can verify.