
Rajat Taneja, Visa’s president of technology, walked a recent audience through the company’s use of Anthropic’s Mythos model on its own payment network. The model stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that governed the hunt. That level of engineering depth is rare. Most organizations do not possess the resources to act on what they find.
Just over half, or 53%, of enterprises have already experienced an agentic security incident or near-miss. Sixty-five percent enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents. Just 8% pair enforcement with isolation.
Leaning on provider-native controls to handle agentic security often exacerbates this gap. Recent research found that 92% of enterprises naming a primary security layer default to their hyperscalers and AI platform providers. The data indicates a containment gap is growing wider between what enterprises need and what is actually getting implemented.
Identity Gains Mask Structural Risks
Forty-nine percent of surveyed enterprises now give each agent its own scoped, managed identity. That figure jumped from 32% in June, marking the fastest single-month increase recorded in the series. Despite these gains, 63% still report credential sharing somewhere in their fleet.
Related: AI video made in under 7 seconds
Companies often treat identity management and isolation as interchangeable safety measures, but they serve fundamentally different purposes. Identity verifies who is acting, while containment limits what damage that actor can do if the verification fails or gets bypassed. Treating them as substitutes leaves the internal architecture exposed once the perimeter is breached.
Only 11 of the 57 enterprises that assigned identities also isolate their agents. That ratio explains why the containment gap keeps widening even as headline controls improve. A rogue AI agent at Meta passed every identity check before its exposure. Similarly, CrowdStrike CEO George Kurtz disclosed that a Fortune 50 agent rewrote its own security policy using valid credentials.
The enforce-without-isolate population has a 58% incident rate. Fifty-three enterprises enforce scoped permissions at runtime but do not isolate, and 31 of those have already had a security incident. Amy Chang, Cisco’s head of AI threat intelligence and security research, presented findings showing that adaptive attackers broke through up to 88.3% of the time in multi-turn attacks against flagship models. An adaptive attacker who defeats the guardrails lands inside whatever architecture sits behind them.
Satisfaction Paradox
Data shows a counterintuitive trend regarding satisfaction. Enterprises that suffered a confirmed incident rated their security tools higher, averaging 4.39 out of 5, compared to 4.13 for those with no incidents. This suggests that tools which save a customer from a breach earn a trust premium, even if they allowed the problem to begin with.
Related: Why Qwen and Opus 5 scores miss the cost mark
Research indicates that near-misses outnumber confirmed incidents two-to-one. Organizations interpret catching a problem at the edge as validation of their strategy. However, the enterprises closest to real security—those that isolate agents—are the least satisfied with their tools. This dissatisfaction likely drives them toward the kind of engineering effort Visa put in.
Reliance on Hyperscalers
Provider-native platforms dominate the market. By July, 92% of enterprises named a provider-native tool as their primary agent security layer. OpenAI’s guardrails lead at 44%, followed by Microsoft Azure at 42% and Anthropic at 37%. Specialized security providers hold only a fraction of the market.
Satisfaction scores have risen to 4.29 out of 5, the highest reading in the series. Yet, 74% of enterprises plan to replace their tools within 12 months. The high score likely reflects how easy it is to turn on a provider’s guardrails, not necessarily how effective those guardrails are at stopping attacks.


