TL;DR: A survey of 300 enterprise leaders found 97% expect a material AI-agent-driven security or fraud incident within 12 months, with nearly half expecting one within six months, while only 6% of security budgets are allocated to the risk, according to Arkose Labs. The gap is now governance, visibility, and attribution, because autonomous access can move faster than review cycles can respond.
Editorial analysis by NHI Mgmt Group, based on content published by Arkose Labs: “97% of Enterprises Expect a Major AI Agent Security Incident Within the Year”.
By the numbers:
- 97% of respondents expect a material AI-agent-driven security or fraud incident within the next 12 months.
- Only 6% of security budgets are currently allocated to this risk.
Key questions
Q: What breaks when AI agents are connected directly to enterprise systems?
A: Direct connections often break auditability, predictable authorisation, and operational containment.
Q: Why do AI agents create more risk than traditional automation?
A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.
Q: How do security teams know if AI governance is working?
A: Look for evidence that access decisions are reviewable, permissions are revocable, and exceptions are not becoming permanent.
Practitioner guidance
- Map AI agents to governed identities Create a definitive inventory of agents, the service accounts or tokens they use, and the business workflows they can execute.
- Separate authorised from suspicious agent activity Define which runtime behaviours are expected, which are forbidden, and which require escalation.
- Link credentials to decision chains Log which identity initiated each action, which systems were touched, and what outcome followed.
Bottom line: The article describes a widening mismatch between expected AI agent incidents and the controls enterprises have actually funded or deployed.
Explore further
View Full Forum → | NHI Foundation Course → | Our Services → | Read the full analysis →
Legitimate credentials are now the insider threat surface for agentic AI. Arkose Labs' findings reinforce a structural shift that identity teams cannot ignore: malicious behaviour is no longer defined by compromised human logins alone. When AI agents operate through service accounts and API tokens, the enterprise must treat machine identities as active participants in insider-risk analysis, not passive infrastructure.
A few things that frame the scale:
- 97% of respondents expect a material AI-agent-driven security or fraud incident within the next 12 months, according to AI Agents: The New Attack Surface report.
- Only 52% of companies can track and audit the data their AI agents access, leaving 48% with a complete blind spot for compliance and breach investigation.
A question worth separating out:
Q: What should teams do first when AI agents are already in production?
A: Teams should first inventory all agent identities, map the credentials they use, and verify that each one has a named sponsor and monitored workflow. That creates the minimum basis for containment, investigation, and accountability before broader policy changes are attempted.
👉 Read our full editorial: AI agent security readiness lags incident expectations in enterprises
AI agent security is an identity governance problem before it is a detection problem: The article shows that enterprises already expect incidents, but most still lack the governance controls to classify, bound, and monitor autonomous actors. AI agents are not just another workload because they can choose actions inside approved workflows and move between systems with legitimate credentials. That changes the identity model from account ownership to runtime authority, which means practitioners must treat agent identity as a first-class governance domain.
A few things that frame the scale:
- A May 2025 Gartner poll of 147 CIOs and IT leaders found that 24% had already deployed AI agents, 50% were experimenting and 17% planned to deploy by the end of 2026.
A question worth separating out:
Q: Should organisations allow AI agents to use production credentials?
A: Only if those credentials are task-scoped, closely monitored, and revocable without affecting unrelated systems. In most cases, production credentials create unnecessary blast radius. A safer pattern is short-lived access, explicit approvals for non-read actions, and strong separation between agent identity and human privilege.
👉 Read our full editorial: AI agent security readiness lags incident expectations in enterprises