July 2026 · 7 min read · Research
92% of Security Pros Are Worried About AI Agents
Darktrace's 2026 Report Reveals the New Normal
AI agents are reshaping the enterprise security landscape, but most security teams are not ready for the change. Darktrace's March 2026 State of AI Cybersecurity report reveals an uncomfortable reality: 92% of security professionals are concerned about the impact of AI agents on enterprise security, and the majority of enterprises lack both the monitoring tools and the defensive mechanisms to address the threat.

Key Definitions
Darktrace State of AI Cybersecurity Report AI agents are reshaping the enterprise security landscape, but most security teams are not ready for the change. Darktrace's March 2026 State of AI Cybersecurity report reveals an uncomfortable reality: 92% of security professionals are concerned about the impact of AI agents on enterprise security, and the majority of enterprises lack both the monitoring tools and the defensive mechanisms to address the threat.
92% Concerned, 80.9% Already Deployed: Security Lags Behind Speed
Darktrace's survey of over 900 global security executives and practitioners reveals a fundamental misalignment: enterprise enthusiasm for AI agent deployment is far outpacing security readiness. 80.9% of technical teams have already moved past planning into active testing or full deployment of AI agents. Yet among those organizations, more than half of all AI agents operate without any runtime security monitoring or logging.
This means a large number of AI agents are running "invisibly" inside enterprise networks — accessing data, calling APIs, executing actions — while security teams remain completely unaware. When an agent is compromised or begins exhibiting anomalous behavior, there are no logs to trace what happened.
The direct consequence of this monitoring gap: a separate Gravitee survey found that only 24.4% of organizations have full visibility into agent-to-agent communication. In environments where AI agents can autonomously invoke other agents, monitoring blind spots compound rapidly — a compromised agent can silently call other agents to execute malicious actions, and the entire sequence unfolds outside the security team's field of view.
Ransomware Up 48% YoY: Agents Are Reshaping the Attack Surface
Darktrace's report also provides quantitative evidence of ransomware evolution. In May 2026, 698 ransomware attacks were reported globally, a 48% increase compared to 472 in May 2025. This is not an isolated spike — it reflects the systematic expansion of the attack surface in the age of AI agents.
As major ransomware groups (such as LockBit) are disrupted by international law enforcement actions, the ransomware ecosystem is shifting from a small number of dominant actors to a more distributed landscape of smaller groups. The proliferation of AI agents accelerates this trend: attackers can now use agents to automate reconnaissance, vulnerability scanning, and social engineering attacks with lower costs and higher efficiency.
For enterprise security teams, this means traditional defense strategies — focused on known large threat actors — are no longer sufficient. AI agents have democratized attack capability, enabling small threat groups to launch attacks at the same scale as major organizations.
The Visibility Gap: You Can't Secure What You Can't See
The core finding of Darktrace's report can be summarized in one word: visibility. The biggest problem facing enterprise AI agent security today is not insufficient defense technology — it is the inability to see what agents are doing.
More than half of agents operate without monitoring, meaning enterprises have virtually no awareness of their actual AI agent ecosystem — how many agents are running, what data they access, which systems they interact with, whether they communicate with other agents. In this state, any security defense is blind.
"You can't secure what you can't see" — this is the first principle of enterprise AI agent security. Before deploying any security controls, enterprises must first achieve comprehensive visibility into their AI agent ecosystem: agent discovery, behavioral baselining, communication topology mapping, and real-time behavioral monitoring.
What Security Teams Need to Do Now
Facing the security challenges posed by AI agents, enterprise security teams need to take three immediate actions:
First, establish agent discovery. Understand how many agents are running in the enterprise, where they operate, and who deployed them. Shadow agent discovery is the first line of defense.
Second, enforce mandatory monitoring. All agents must have complete logging and behavioral monitoring. No agent should be allowed to run without being recorded.
Third, build agent-to-agent communication visibility. The agent call chain must be traceable so that when an attack occurs, security teams can quickly identify the propagation path and affected scope.
92% of security professionals are concerned about the impact of AI agents — that number speaks for itself. The concern is justified, but staying at the concern stage is not enough. Gaining visibility is the prerequisite for solving every AI agent security problem.
References
- Darktrace: "State of AI Cybersecurity 2026: 92% of Security Professionals Concerned About AI Agents"
- miniOrange: "AI Agent Security Risks: What Enterprises Need to Know in 2026"
- AGAT Software: "AI Agent Security in 2026: What Enterprises Are Getting Wrong"
FAQ
How far does security readiness lag behind AI agent deployment speed?+
Darktrace's survey of over 900 global security executives and practitioners reveals a fundamental misalignment: enterprise enthusiasm for AI agent deployment is far outpacing security readiness. 80.9% of technical teams have already moved past planning into active testing or full deployment of AI agents. Yet among those organizations, more than half of all AI agents operate without any runtime security monitoring or logging.
How much did ransomware attacks increase year over year?+
Darktrace's report also provides quantitative evidence of ransomware evolution. In May 2026, 698 ransomware attacks were reported globally, a 48% increase compared to 472 in May 2025. This is not an isolated spike — it reflects the systematic expansion of the attack surface in the age of AI agents.
What is the visibility gap in AI agent security?+
The core finding of Darktrace's report can be summarized in one word: visibility. The biggest problem facing enterprise AI agent security today is not insufficient defense technology — it is the inability to see what agents are doing.
What do security teams need to do now?+
Facing the security challenges posed by AI agents, enterprise security teams need to take three immediate actions:
相关文章
AI 网关只告诉你请求去了哪,JetStream 回答它该不该发
JetStream Clearance 把零信任的信任边界从身份下移到单次动作:AI Blueprints 契约 + 参数级权限 + 序列检测,在 MCP 调用执行前逐动作授权。网关已成商品,授权引擎是下一个战场。
审查过的 MCP 工具在第四次调用开始背叛你:Deadbugz 的运行时门控投毒
Pillar Security 披露活跃 MCP 供应链活动 Deadbugz:恶意服务器伪装成文本格式化工具,前三次调用一切正常,第四次起改写返回的工具元数据,指示 agent 搜寻 SSH 密钥、AWS 凭证并隐藏行为。一次性审查被系统性绕过——工具描述是运行时安全边界,批准应发生在动作执行之时。
AI Agent执行层安全缺口:模型安全不是全部,工具调用才是真正的攻击面
企业投入大量资源保护 AI 模型层,但忽略了 Agent 工具调用执行层的安全——2026 年 80% 的 Agent 攻击发生在执行层而非模型层。本文解析执行层为何被忽视、主要安全厂商的响应,以及执行层安全的五项关键措施。
AI Agent网关:2026年企业Agent安全架构的新控制平面
Cisco、CrowdStrike、TrueFoundry相继推出AI Agent网关产品。拦截每一次工具调用、评估风险、实时阻断——Agent网关正在成为安全基础设施的新标配。