August 2026 · 6 min read
Half of Enterprises Hit by AI Agent Incidents

Key Definitions
Unauthorized or misconfigured AI agent An AI agent that enters production without proper identity authentication, a defined access scope, or audit logging — an uncontrolled attack surface that is hard to trace and contain.
Proactive identity control Controls established at the point of agent deployment — a verifiable identity, a defined access scope, and an audit trail before it touches production data — as opposed to reactive revocation after an incident.
In the past six months, half of enterprises experienced a security incident directly tied to an unauthorized or misconfigured AI agent. That figure — from a DigiCert survey of 1,001 IT and cybersecurity leaders across the US, UK, and Australia, reported by The Deep View on July 7, 2026 — puts a concrete number on a risk that many security teams have been tracking but few have fully governed.
I. Half an Incident Rate: From Hypothetical to Historical
The survey found that 50% of respondents reported an actual breach or disruption tied to an unauthorized or misconfigured AI agent in the past six months, and another 28% identified vulnerabilities without a confirmed incident — nearly eight in ten encountered some form of AI-related security issue. By sector, science and technology firms logged the highest incident rates, followed by banking and financial services, telecommunications and media, and retail.
The structural exposure vectors matter most: prompt injection attacks, data poisoning, unauthorized access to sensitive systems, and an inability to trace which model produced a given output. These are not edge cases — they are the normal risk of agents at scale.
II. Deployment Pace Is Widening the Governance Gap
In the same window, 75% of organizations deployed four or more AI-powered systems and 35% deployed more than ten. Each additional model or agent integration extends the attack surface without necessarily adding a corresponding control layer. Deployment speed is systematically outstripping the speed at which identity and control can be put in place.
DigiCert's senior vice president of product, Brian Trzupek, notes that AI agents present a fundamentally different identity problem from traditional endpoints: they operate autonomously at machine speed, yet most enterprises have not applied the same identity, authentication, and audit controls they already require of human users, devices, and applications. Governance discussions are widespread — 90% have addressed AI governance at the leadership level — but only half have dedicated budgets and formal programs. The gap between conversation and operational control is where the legal, regulatory, and reputational risk lives.
III. Revocation Exists; Proactive Identity Controls Do Not
One area where enterprises are ahead: 86% report having at least some process, formal or informal, for revoking access to a compromised AI system. But that reactive capability only applies after something has gone wrong. The harder operational problem is establishing controls at the point of deployment, so each agent carries a verifiable identity, a defined access scope, and a logged audit trail before it ever touches production data.
Agents operating at machine speed will not wait for your revocation workflow. Reactive revocation is useful, but it cannot replace the proactive control of governing an agent before it ever reaches your data. The gap between the two is where most security teams are genuinely weakest.
IV. The Invisible Decision: The Traceability Gap
Nearly half of the 1,001 respondents reported limited or no visibility into how their AI systems arrive at decisions, making post-incident investigation significantly harder. When a regulator or general counsel asks within hours of a breach — what AI is running, what it can access, and who is responsible — a lack of traceability means you cannot answer.
Traceability is not an abstract compliance concern. It is the answer to the questions an incident response team, a regulator, or a general counsel will ask within hours of a breach. The ability to map every decision back to its source model and training data is becoming a non-negotiable requirement of enterprise AI procurement.
V. The Action List: Govern Your Agents
Trzupek's recommendations are blunt and actionable. First, audit your AI agent inventory now: confirm every production agent has an assigned identity, defined permissions, and an audit log — if it does not, treat it as an unmanaged endpoint. Second, close the governance budget gap: a 50% incident rate is a number risk committees and boards will recognize. Third, extend your IAM framework to cover non-human actors, including third-party and embedded models. Fourth, build traceability into procurement requirements: require vendors to demonstrate output traceability so you can map a decision back to its source model after an incident.
AI agent security governance is no longer a future consideration. Agents are in production, and the incidents are real. Whether your enterprise becomes a statistic or the exception depends on whether you build identity, access, and audit controls before agents ever reach your data.
References:
FAQ
Where does the 'half of enterprises' number come from?+
It comes from a DigiCert survey of 1,001 IT and cybersecurity leaders in the US, UK, and Australia, reported by The Deep View on July 7, 2026. In the past six months, 50% reported an actual breach or disruption directly tied to an unauthorized or misconfigured AI agent, 28% identified vulnerabilities without a confirmed incident, and about 78% encountered some form of AI-related security issue.
Why is deployment pace widening the governance gap?+
In the same window, 75% of organizations deployed four or more AI systems and 35% deployed more than ten. Each new model or agent integration extends the attack surface without necessarily adding a corresponding control layer. While 90% of organizations have addressed AI governance at the leadership level, only half have dedicated budgets and formal programs in place.
Why is revocation not enough?+
86% of organizations have some process, formal or informal, for revoking access to a compromised AI system — but that reactive capability only applies after something goes wrong. The harder problem is establishing controls at the point of deployment, so each agent carries a verifiable identity, a defined access scope, and an audit trail before it ever touches production data. Agents running at machine speed won't wait for your revocation process.
What does the traceability gap mean?+
Nearly half of respondents reported limited or no visibility into how their AI systems arrive at decisions, making post-incident investigation significantly harder. Exposure vectors include prompt injection, data poisoning, unauthorized access to sensitive systems, and an inability to trace which model produced a given output. Without traceability, you cannot answer what a regulator or general counsel will ask within hours of a breach.
What should enterprises do right now?+
Audit your AI agent inventory: confirm every production agent has an identity, defined permissions, and an audit log — if not, treat it as an unmanaged endpoint. Close the governance budget gap, extend your IAM framework to cover non-human actors, and build output traceability into procurement requirements so you can map a decision back to its source model after an incident.
Related Articles
88% Hit by AI Agent Incidents: Agents Left Naked
Gravitee 2026: 88% of orgs saw agent incidents in the past year; most deployed agents lack security monitoring.
65% Hit by AI Agent Incidents: The Data-Layer Gap
CSA and Token Security: 65% of firms saw agent-caused incidents in a year; 61% involved data leakage.
The Execution Layer: Where Agent Attacks Really Hit
In 2026, 80% of agent attacks occur at the execution layer, not the model — tool calls are the attack surface.
AI Agent Security 2026: Adoption Outpaces Control
Gravitee survey of 900+ execs: 81% past planning, yet only 14.4% of agents launch with full security approval.