エンタープライズ、エージェント権限管理の2/3が実行中だが高リスク隔離は5%未満
本文の状態
日本語全文を表示中
詳細モードで約26分の本文を読めます。
同じ出来事の情報源
この情報源を基点に整理
VentureBeat AI
VentureBeat の調査によると、AI エージェントのセキュリティ対策において権限管理は進んでいるものの、高リスクエージェントの分離が極めて不十分であり、実害を伴うインシデントが半数で発生していることが明らかになった。
Continue in AI NEW LAB
このニュースを、実務の判断につなげる
AI NEW LABで、試したことや先に確認したい条件を共有できます。まずはログインなしで読めます。
AI NEW LABで論点を見るAI深層分析を開く2026年8月12日 17:08
AI深層分析
キーポイント
コンテインメントギャップの存在
エージェンシーの監視や権限管理は進んでいる一方で、高リスクエージェントをサンドボックスに隔離する対策が実施されているのはわずか18%であり、防御の最下層である「影響範囲の限定」が機能していない。
セキュリティインシデントの頻発
調査対象企業の53% がすでにエージェント関連のセキュリティイベントまたはニアミスを経験しており、そのうち19% は確定的なインシデントとして確認されている。
認証情報の共有問題
エージェンシーの個別管理されたアイデンティティを持つ企業は49%に達しているが、依然として63% の組織でクレデンシャル(認証情報)の共有が発生しており、完全な分離を実現できているのは29%のみである。
セキュリティスタックへの依存と信頼低下
セキュリティ対策は OpenAI や Microsoft などのモデルプロバイダーやハイパースケーラーに依存する傾向が強く、AI を武装した攻撃者が防御を上回っているという認識が広がりつつある。
アイデンティティ管理の課題とセキュリティスタックの依存
エージェントにスコープ付きIDが割り当てられている割合は高いものの、クレデンシャル共有が発生しており、完全な分離を実現している組織は少数である。セキュリティ対策はハイパースケーラーやモデルプロバイダーネイティブのツールに過度に依存している。
重要な引用
The gap between what enterprises watch and what they contain is the central finding of this wave of VentureBeat Pulse Research.
Only 18% of enterprises isolate their highest-risk AI agents, even as 65% of enterprises enforce scoped permissions at runtime.
As many enterprises now believe AI-armed attackers are ahead of their defenses as believe the reverse.
Confidence has slipped, with 30% now saying AI-armed attackers are ahead of their defenses, exactly as many as say their defenses are ahead.
Source Article
元記事を日本語で読む
本文に関係しない購読案内、埋め込み通知、サイト内プロモーションは除いています。
116 社の企業を対象とした調査では、AI エージェントが本番環境で稼働している一方で、セキュリティインシデントも実際に発生しています。過半数の企業がすでに確認されたエージェント関連のセキュリティ事象やニアミスを経験しており、2/3 の企業がランタイムでのスコープ制限付き権限を適用しています。しかし、最もリスクの高いエージェントを隔離している企業は 5 社に 1 社未満にとどまり、自律化が進む中でコンテナリング(封じ込め)がセキュリティスタックの中で最も脆弱な層となっています。
また、認証情報の共有がほぼ 2/3 のエージェント群で継続しており、53% の企業がすでに確認されたセキュリティ事象やニアミスを報告しています。これが「エージェンシー・セキュリティ」に対する信頼の低下につながっています。セキュリティスタックは依然としてモデルプロバイダーやハイパースケーラーからの借用に頼る傾向が強く、その信頼も低下しています。現在では、AI を武装した攻撃者が自社の防御を凌駕していると感じる企業と、逆だと考える企業の数がほぼ拮抗する状況です。
今回の VentureBeat Pulse Research は、企業がどのように AI エージェントを保護しているかを検証します。具体的には、どのようなツールを採用し、エージェントのアイデンティティ管理や隔離をどう行っているか、すでに何が問題を起こしたのか、投資額はいくらか、そして防御が AI 搭載型攻撃者の進歩に追いついていると信じているかどうかについて調査しました。
最もリスクの高い AI エージェントを隔離している企業はわずか 18% です。一方で、65% の企業がランタイムでのスコープ制限付き権限を適用し、56% がエージェントの活動監視とログ記録を行っています。この調査の中核となる発見は、企業が「監視」している範囲と実際に「封じ込め」ている範囲との間に大きな乖離があるという点です。
現在、企業の過半数(53%)が実稼働中のエージェント型 AI システムを導入しており、さらに 27% がパイロット運用または限定展開の段階にあります。これに伴い、エージェント関連のセキュリティインシデントも相次いで発生しています。組織の 53% で既にエージェントセキュリティ事象が発生しており、そのうち 19% は実際に被害を伴うインシデントとして確認され、38% は被害が出る前に検知されたニアミスでした。
核心的な課題は「封じ込めの欠如」です。企業はエージェントの監視や権限付与といった制御手段は整えていますが、万が一それらが機能しなかった際に被害を限定する仕組みが不足しています。セキュリティ体制について回答した企業のうち、65% がランタイムでスコープ付きの ID と権限を適用しており、56% がエージェントの活動監視とログ記録を実施していますが、高リスクのエージェントをサンドボックスに隔離しているのはわずか 18% です。実稼働中でさえ、隔離措置が講じられているのは 21% に過ぎず、権限付与と隔離を組み合わせているケースは 8% にとどまります。これは防御の多層化(ディフェンス・イン・デプス)の観点からすると順序が逆です。SOC チームから CISO まで、セキュリティ担当者は「監視は事後の分析に役立ち、権限付与は予防を試みるが、隔離こそが予防が失敗した際の被害範囲を限定する」という原則を理解しています。
アイデンティティ管理は改善されたものの、まだ完全には解決されていません。企業の 49% が「各エージェントにスコープを限定した管理された ID を付与している」と回答する一方、63% は「エージェント群のどこかで認証情報の共有が発生している」と報告しており、スコープ限定 ID を持ち、かつ一切の共有がない環境を整えているのはわずか 29% に過ぎません。こうした対策を実施しているセキュリティスタックは、依然としてクラウドプロバイダーやモデルベンダーが提供するネイティブ機能に依存する傾向が強いです。具体的には、OpenAI のガードレール(44%)、Microsoft Azure(42%)、Anthropic の管理型エージェント制御機能(37%)、Google Cloud(31%)が主要な役割を果たしており、セキュリティ層の主要部分を名指しした企業の 92% が、その基盤としてクラウドプロバイダーまたはモデルベンダー製のネイティブ機能を挙げています。
しかし、この楽観的な状況には二つの大きな変化が生じています。まず、自信の低下です。AI を活用した攻撃者が自社の防御体制を凌駕していると回答する企業が 30% に達し、逆に「防御が攻撃を上回っている」と答えた企業も同数となりました。次に、ツールの変更意欲の高まりです。満足度がシリーズ最高値の 4.29(5 点満点)に達しているにもかかわらず、74% の企業が今後 12 ヶ月以内にエージェントセキュリティツールの導入、追加、または入れ替えを計画しています。企業はこれまで以上にセキュリティスタックに対して不満を抱きつつも、その変更への決意は強まっています。
調査手法
VentureBeat は、継続的な「Pulse Research」シリーズの一環として本調査を実施しました。この調査は、自律型 AI エージェントを保護するために組織が使用するツール、ID 管理、隔離、および権限執行コントロールといった「エンタープライズ・エージェントセキュリティ」に焦点を当てています。
回答は従業員数 100 人以上の組織に限定され(サンプル数 n=116)、最小規模帯である 1~100 人の組織は除外されています。データは 2026 年 7 月の単一波から抽出されたものです。これは数ヶ月にわたる統合サンプルではなく単一の調査波のため、報告書は断面分析として読み解かれ、月次間の推移を推測するものではありません。すべての数値は 7 月の実施分のみに基づいています。また、複数の回答が可能な質問も含まれているため、各項目の割合を合計すると 100% を超える場合があります。
役割別に見ると、サンプルは意思決定権を持つシニア層とバイヤーとしての信頼性が高い層で構成されています。AI 購入における最終決定権者(44%)や推奨者・影響力のある立場(38%)が大半を占めています。役職別の内訳は、マネージャー(36%)、個人貢献者(27%)、VP やディレクター(18%)、そして C レベル役員(16%)です。
組織規模別では、中堅市場に重点を置きつつも、大企業層も一定数含まれる構成となっています。従業員数 101~250 人(34%)と 251~1,000 人(23%)が上位を占め、その後に 1,001~5,000 人(18%)、10,001 人以上(17%)、5,001~10,000 人(7%)が続きます。業界別では、テクノロジー・ソフトウェアが 38%で最大を占め、次いでヘルスケア・ライフサイエンス(11%)、金融サービス(10%)となっています。
本調査では、3 つの質問にすべての回答者が答える必要があります。一方、エージェントを稼働中またはパイロット段階にある企業のみを対象とした質問が 2 つあります。
姿勢に関する数値(監視/強制/隔離)は、93 名の回答者に基づいて報告されています。また、主要なセキュリティ層を特定した 92 名については、その層に関するデータも示しています。残りの 23 名は評価中、または導入計画がなく、現状ではエージェントのセキュリティ姿勢が適用されない組織です。
なお、いくつかの複数回答形式の質問では、本来は単一選択を想定していたにもかかわらず重複した回答が寄せられました(アイデンティティ:33 名が複数のパターンを選択、軍拡競争評価:23 名、予算配分:10 名、インシデント発生:9 名)。これらのデータは回答者レベルで集計され、重なり合いが生じる重要な箇所ではその旨を説明しています。満足度スコアは各質問に回答した対象者に計算されており、全体の満足度スコアは 116 名の有効回答者のうち 76 名に基づいています。
回答者数は 116 名であり、このサンプルは方向性を示すには十分ですが、精密な測定を可能にするものではありません。これは自己選抜型の非確率サンプリングです。したがって、本調査結果は大手オペレーター全体の視点というよりも、積極的にエージェントセキュリティの構築に取り組んでいる組織の視点として捉えるべきです。
発見事項 1:エージェントは実環境で稼働しており、インシデントも発生している
過半数がすでにエージェント関連のセキュリティ事象を経験
本調査では、組織がプロダクション環境でエージェント型 AI を運用しているか、またエージェントセキュリティに関するインシデント(確定的な侵害や、被害が生じる前に検知されたニアミス)を経験したことがあるかを尋ねました。
この種のエージェントはすでに本番環境に導入されています。企業の過半数(53%)が現在、エージェント型 AI システムを実稼働させており、27% がパイロット運用または限定展開中、残りの 3% は今後 12 ヶ月以内に導入する計画を持っていません。セキュリティリスクも拡大しており、組織の 53% で既にエージェント関連のセキュリティ事象が発生し、そのうち 19% で確認されたインシデント、38% で被害が出る手前のニアミスが検知されています。
確認されたインシデントよりもニアミスのほうが 2 対 1 の割合で多いことは、注意深く読み取る必要があります。これは企業が問題を把握している一方で、その対応が限界に近い段階で行われていることを意味します。一度機能した制御措置は、今後も常に機能する保証があるわけではありません。本レポートの残りで検討される制御措置、特に「発見事項 2」と「発見事項 3」で指摘されているアイデンティティと分離(隔離)の欠陥こそが、次のニアミスが本当に被害に発展しないかを決定づける要因です。
これまでの調査で見られたあるパターンは、今回は再現されませんでした。組織規模による暴露度の差は明確ではありません。従業員数 1,000 人以上の大企業ではインシデントまたはニアミスの発生率が 47% であるのに対し、101〜1,000 人の中小企業では 57% です。この差は統計的なばらつきの範囲内であり、むしろこれまでの調査で確認されてきた「規模が大きいほどリスクが高い」という傾向とは逆の方向を示しています。今回の調査では、被害に遭ったかどうかを分けるのは従業員の人数ではありません。
発見事項 2:アイデンティティ管理は改善しつつあるが、依然として共有されている
エージェントにスコープ付きの ID を付与する企業は半数ですが、認証情報の一部を共有している企業は依然として 3 分の 2 に達しています。
企業は AI エージェントのアイデンティティをどのように管理しているのか。各エージェントが個別の認証情報を持つのか、それとも共有するのかについて調査しました。回答者は複数のパターンを同時に記述することができました。
「エージェントごとのアイデンティティ」が最も多く挙げられたパターンとなりました。企業の 49% が、各エージェントにスコープ付きで管理された独自のアイデンティティを持たせていると回答しています。これは最小権限の原則を実現し、発生事象の追跡を明確にするための前提条件です。この調査シリーズが繰り返し指摘してきた「構造的な弱点」に対する、実りある進展と言えます。
しかし、回答には重複があり、その重複こそが重要な発見です。33 件の回答で複数のアイデンティティパターンが混在していると記述されました。これを回答者レベルで集計すると、企業の 63% が何らかの形で認証情報の共有を行っていることがわかります。具体的には、主に共有 API キーや借用された人間用・サービスアカウントの認証情報で動作するエージェント群(37%)と、一部はスコープ付きだが多くはそうでないハイブリッドな環境(34%)です。
一方、どこでも共有を行わず、すべてのエージェントにスコープ付きアイデンティティを適用している企業は 29% に留まります。本番環境でエージェントを導入している企業のうち 60% が「エージェントごとのアイデンティティ」を採用していますが、改善が進んでいるのは実際の運用現場に限られており、そこには依然として認証情報の共有が残っているのです。
改善しても結果は変わらない。認証情報を共有している場合、権限が過剰に付与されたエージェントや侵害されたエージェントは、意図した範囲をはるかに超えた影響力を行使し、インシデント発生後の調査でも「どのエージェントが何をしたか」を明確に特定できない。スコープ付きのID を持つ fleet の半分があっても、持たない半分の場合と同じ爆発半径(影響範囲)が生じる。非人間アイデンティティは、エンタープライズにおけるエージェントセキュリティで最も未完成な部分であり、Finding 8 が示す通り、企業が現在購入を検討している領域からほぼ完全に抜け落ちている。
Finding 3: 隔離こそが誰も構築しない制御機能
ランタイムでの適用は 2/3 に達するが、サンドボックス化は 5 割未満
組織の実践的なエージェントセキュリティ体制はどうなっているのか。監視するか、権限を強制するか、隔離するか、あるいはその組み合わせか。ダメージを限定する「隔離」機能は、圧倒的に最も普及していない制御だ。数値は、体制について回答した 93 社のデータに基づく。
これは「封じ込めギャップ」であり、本レポートで最も大きな構造的な隙間である。権限の強制と監視はすでに一般的になっている。ランタイムでスコープ付きの権限を適用する企業が 65%、エージェントの活動を追跡・ログ化する企業が 56% に達している一方、隔離機能を採用しているのはわずか 18% だ。両方を組み合わせて「予防と封じ込め」を実現できる体制をとっている企業は、全体の 8% に過ぎない。
デプロイの成熟度は、集計値が示す以上に重要な予測因子です。エージェントを完全に本番環境で運用している企業では隔離対策の実施率が 21% に達する一方、まだパイロット段階にある企業では 13% です。これは単なるリスク曝露の違いではなく、成熟度に応じた明確な差と言えます。
また、ファインディング 2 で示されたような「クレデンシャル共有」が広範に発生している可能性が高いと回答した企業のグループにおいても、隔離対策の実施率は 15% に留まります。つまり、最もリスク曝露の大きい組織ほど、そのリスクを封じ込める制御体制を整備しているとは言い難いのです。
この状況は、多層防御(ディフェンス・イン・デプス)の観点から見ると順序が逆転しています。監視(Observation)は事後的に何が起きたかを把握するものであり、強制(Enforcement)はそれを未然に防ぐためのものです。そして、隔離(Isolation)こそが、強制策が失敗した際に被害を限定するための最後の砦です。
強制策が失敗することは避けられないものとして前提されており、ファインディング 1 で指摘された「ニアミス」の背景にはまさにこの事実があります。監視と権限管理は整っているものの、隔離(ボックス化)されていないエージェント群は、単一の制御障害がシステム全体に波及する危険な構成です。多くの企業は防御モデルの最初の 2 つの層を構築しましたが、3 つ目の層である「隔離」についてはほぼ無視しているのが実情です。
ファインディング 4:セキュリティ対策はまだ、借り物のプロバイダーネイティブ制御に依存したまま
9 割の企業が、主要な防御層としてモデルプロバイダーまたはハイパースケーラーを挙げています
企業は、エージェントセキュリティのためにどのツールを採用しているか、またその中で主軸となるレイヤーはどこかを尋ねられました。その回答は依然として、専用ベンダーよりもモデルプロバイダーやハイパースケーラーに偏っています。
企業がエージェントを保護する際に利用しているのは、モデルやクラウドプラットフォームに標準で付属するツールです。OpenAI のガードレールが 44% でトップに立ち、Microsoft Azure(42%)、Anthropic のマネージドエージェント制御(37%)、Google Cloud(31%)が続きます。
主要なセキュリティ層を一つだけ選ぶよう問われた回答者のうち 92% が、これらのプロバイダーネイティブなソリューションのいずれかを挙げています。特に Azure が 27%、Anthropic が 26% で首位を争っています。
エージェントセキュリティに特化したカテゴリはゼロではありませんが、依然として限定的です。Cloudflare(11%)と Cisco(9%)が専門分野でリードしており、CrowdStrike、Palo Alto、Zenity、Check Point の Lakera、HiddenLayer、F5、SentinelOne はそれぞれ 1〜7% のシェアを占めています。
「発見事項 2」に直接関連するアイデンティティ専門のソリューションは最も規模が小さく、Microsoft Entra Agent ID が 7%、Okta for AI Agents が 3%、非人間用アイデンティティプラットフォームも 3% です。また、「発見事項 3」で欠落していたランタイムサンドボックス機能に特化したツールを導入しているのは全体の 3% に過ぎません。
これらの統計データを読む際の注意:方法論のセクションで説明した通り、回答者サンプルは自己選択型であり、「利用状況」に関する質問では、各ベンダーやアプローチを重複してカウントしているため、この数値はセキュリティスタック内での「存在率」を示しており、支出額や排他性を表すものではありません。したがって、個別のベンダーの割合には、一般的なサンプル調査における注意点をすべて適用する必要があります。ただし、構造上のパターンは確固たるものです。プロバイダネイティブおよびハイパースケラーによる制御が圧倒的な差をつけてリードしており、エージェントセキュリティに特化した専門ソリューションはまだ一桁台にとどまっています。個別の数値は概観として捉え、その背後にあるパターンには自信を持って信頼してください。
発見事項 5:満足度はシリーズ最高を更新し、離脱意向も同様に上昇
企業はツールを 4.29/5 と評価しながら、3 分の 2 が置き換えを検討
今回の調査では、企業が現在のエージェントセキュリティツールにどの程度満足しているか、そして今後 12 ヶ月以内に新しいツールの導入や既存ツールの交換を検討しているかを尋ねました。しかし、この二つの回答は決して矛盾するものではありません。
エージェントセキュリティツールに対する満足度は、本シリーズで過去最高を記録しました。全体的な満足度と実装の容易さともに 4.29/5 を達成し、「コスト対効果」も 4.11 と僅差で続きます。これは、大半がプロバイダ側のガードレールを借用したスタックであるにもかかわらず、驚くべきスコアです。なぜなら、同じ企業の過半数はすでにインシデントまたはニアミスを経験しており、リスクの高いエージェントを隔離している企業は 5 社に満たないからです。
購入意欲のデータは、物語のもう一つの側面を語っています。74%が12ヶ月以内にエージェントセキュリティツールの採用、追加、または置き換えを計画しており、そのうち30%は来四半期中に実施する予定と回答しています。これは同シリーズでこれまでこのカテゴリーで見られたどの数値よりも高い変更意欲です。一方で、現状維持を選ぶのはわずか26%に過ぎません。
企業はツールに対して以前より満足している一方、変更への決意も強まっています。これは、満足感が「実証された防御能力」ではなく、「プロバイダーネイティブなコントロールの利便性と低摩擦性」に基づいていることを示唆しています。つまり、十分であるという確信ではなく、手軽に使えることへの安心感です。
発見6:予算がようやく動き出した
セキュリティ予算の1割以上をエージェントに充てる企業が3分の1に達しました
企業はAIエージェントの保護にセキュリティ予算のどの程度の割合を割り当てているのかを尋ねました。その割合は増加傾向にありますが、依然として限られた範囲です。
エージェントセキュリティへの支出はまだ柱というよりは「一部門」ですが、確実に拡大しています。最も一般的な配分はセキュリティ予算の6〜10%(44%)で、約35%の企業が1割以上を割り当てています。これは資金が投入されている少数派ながら、無視できない規模です。一方、28%の企業は5%以下しか支出していません。
Findings 1 から 3 の結果を踏まえると、予算は後追いでありながら反応的な指標に過ぎません。過半数の企業がインシデントまたはニアミスを経験しており、認証情報の共有がフリートの約 2 分の 3 で継続している一方、ハイリスクなエージェントを隔離できているのは 5 人に満たないのが実情です。こうしたギャップを、予算配分の 6〜10% の増額だけで短期間に埋めることは困難でしょう。
予算の 1 割以上を投じている企業は、モデルプロバイダが提供する標準機能に頼るのではなく、スコープを限定したアイデンティティ管理や隔離制御を自前で構築できるリソースを持っています。この少数派が増えるかどうかは、今後「封じ込め」のギャップが縮小するかどうかを示す合理的な先行指標となり得ます。
Finding 7: 軍拡競争の行方が傾いた
攻撃側と防御側のどちらが優勢かについて、多くの企業で意見が二分しています。
私たちは、企業が AI を活用した防御体制と、AI を駆使する攻撃者の間でバランスをどう評価しているかを尋ねました。その結果、自信は失われ、見解が完全に拮抗しました。
企業の多くは、もはやこの競争に対して楽観的ではありません。AI を武装させた攻撃者が防御を上回っていると答えた企業(30%)と、防御側が優勢だと答えた企業(30%)の割合が全く同じです。さらに 33% が「ほぼ同等」、24% は「まだ判断時期尚早」と回答しました。これらを合わせると、63% の企業が現状を「拮抗しているか、それより劣っている」と評価しています。
経験が悲観的な見方を後押ししており、その関係性は統計的に明確です。実際にインシデントやニアミスを経験した企業のうち 39% が「攻撃者が先手を打っている」と回答しましたが、そのような経験がない企業ではその割合は 20% に過ぎません。この差は、サンプルサイズがこれほど大きい場合でも偶然生じる可能性は極めて低いものです。
被害に遭うことは、企業が何を購入するかを変えるだけでなく、その戦いをどう捉えるかさえも変えてしまいます。実際に脅威の最前線にいる組織ほど、その脅威に対して自信を失っているのです。
この評価は、「発見 5」における満足度が過去最高水準にあるという事実と、あまりに不協和音を生んでいます。企業は自社のツール群を 5 段階中 4.29 と高く評価しています。しかし、AI を活用して攻撃力を高めている敵対者に対して、現状維持が精一杯だと考える企業が過半数を占めています。互角の戦いなど、決して快適な状況ではありません。実際に試練に晒されたグループは、その評価をさらに低いものとしています。
発見 8:再編成の波が来る——しかしアイデンティティはまだリストに含まれていない
インシデントが緊急性を生み、関連する制御への関心は 10% に達しています。
企業が検討しているエージェントセキュリティソリューションについて尋ねました。その検討対象は広がっていますが、インシデントデータが示す方向性とは一致していません。
インシデント発生がセキュリティツールの導入サイクルを加速します。確認されたインシデントやニアミスを経験した組織の 38% が、今後 90 日以内にエージェントセキュリティツールの採用、追加、または入れ替えを検討しています。一方、インシデント経験のない組織ではその割合は 22% です。特に明確なインシデントが発生した場合、この数字は 41% に達します。
今回のデータにおいて、過去の経験が緊急性の最も強力な予測因子となっていることは、第 7 の発見における悲観主義の要因とも一致しています。
検討対象となるベンダーはまだプロバイダネイティブに偏っていますが、OpenAI(38%)、Microsoft Azure(37%)、Anthropic(35%)、Google Cloud(28%)がトップを占めています。一方で、セキュリティ専門ベンダーからの関心も着実に高まっており、Cisco が 10%、Cloudflare が 9%、Zenity と CrowdStrike がそれぞれ 8%、Palo Alto、Check Point の Lakera、そしてオープンソースのガードレールが各 6% を獲得しています。多くの専門ベンダーにとって、これは現在の市場シェアよりも将来への期待を示す数字と言えます。
まだ導入されていないのが、ID レイヤーです。エージェント用 ID 製品(Okta for AI Agents、Microsoft Entra Agent ID、非人間 ID プラットフォームなど)を考慮している企業はわずか 10% に過ぎません。認証情報を共有しており、かつ実際に攻撃を受けた経験がある企業のうち、最も直接的な証拠があるグループでも、ID 対策の検討率は高まっていません。約 10% です。
ランタイムサンドボックスツールの採用率は 6% に留まります。今回のインシデントデータから特に懸念される「ID 管理」と「分離」の 2 つの制御策は、購入計画において最も不足している項目です。これは前回の調査でも指摘された盲点であり、1 年間にわたるインシデントを経ても改善されていません。
結論:予防策だけでは埋められないセキュリティギャップ
従業員数 100 人以上の組織では、すでにエージェントを実環境に導入しています。現在稼働中としているのは 53% です。そして、インシデントも同時に発生しており、過半数が確認された事案またはニアミスを報告しています。
制御策の実施状況を見ると、一概に「悪い」とは言えません。ほぼ半数の企業が各エージェントにスコープ付き ID を付与し、3 分の 2 の企業がランタイムで権限を強制しています。また、セキュリティ予算の 10% 以上をエージェント対策に充てる企業も 3 割に達します。企業は本格的にエージェントセキュリティの構築を進めています。
彼らが構築していないのは、隔離(コンテインメント)です。高リスクのエージェントを隔離している企業は 5 社に満たず、権限管理と隔離を組み合わせているケースもわずか 8% です。さらに、本番環境でエージェントを実行している企業に限っても、隔離の導入率は 21% に過ぎません。認証情報の共有が 63% のファームで依然として発生しており、隔離によって抑止されるはずの被害範囲(ブラスト・レイディアス)は広がり続けています。
原文を表示
Across 116 enterprises, agents are in production and so are the incidents: A majority have already had a confirmed agent security event or a near-miss. Two-thirds of enterprises enforce scoped permissions at runtime. Barely one in five isolates its highest-risk agents, making containment the weakest layer in the stack precisely as autonomy scales. Credential sharing persists across nearly two-thirds of agent fleets, and 53% have already had a confirmed agent security event or near-miss, contributing to a growing lack of confidence in agentic security. Security stacks remain overwhelmingly borrowed from model providers and hyperscalers, and confidence has slipped. Today, as many enterprises now believe AI-armed attackers are ahead of their defenses as believe the reverse.
This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers.
Only 18% of enterprises isolate their highest-risk AI agents, even as 65% of enterprises enforce scoped permissions at runtime and 56% monitor and log agent activity. The gap between what enterprises watch and what they contain is the central finding of this wave of VentureBeat Pulse Research.
More than half of enterprises (53%) have agentic AI systems in production today, and another 27% are piloting or running a limited rollout. The agentic security incidents are arriving with them: 53% of organizations have already had an agent security event, with 19% confirming an incident and 38% having identified a near-miss that was caught before it caused harm.
The central finding is a containment gap. Enterprises have built the controls that watch and permission agents but not the one that bounds the damage when those fail. Among enterprises describing their security posture, 65% enforce scoped identities and permissions at runtime and 56% observe and log agent activity, yet only 18% isolate high-risk agents in sandboxes. Even among enterprises running agents in production, isolation is enforced just 21% of the time, and just 8% pair enforcement with isolation. That ordering is backward from a defense-in-depth standpoint. From SOC teams to CISOs, security teams know that observation tells you what happened and enforcement tries to prevent it, but isolation is what limits the blast radius when prevention fails.
Identity has improved without being solved. 49% of enterprises say each of their agents has its own scoped, managed identity, but 63% report credential sharing somewhere in the agent fleet, and only 29% describe a fleet with scoped identities and no sharing anywhere. The security stack doing this work remains overwhelmingly hyperscaler or model provider-native: OpenAI’s guardrails (44%), Microsoft Azure (42%), Anthropic’s managed-agent controls (37%), and Google Cloud (31%) lead, and 92% of enterprises naming a primary security layer name a hyperscaler/model provider-native one.
Two things have shifted against the comfortable picture. Confidence has slipped, with 30% now saying AI-armed attackers are ahead of their defenses, exactly as many as say their defenses are ahead. And churn intent is the highest this series has recorded, with 74% planning to adopt, add, or replace agent security tooling within twelve months, despite satisfaction scores at a series high of 4.29 out of 5. Enterprises are more satisfied than ever with a stack they are more determined than ever to replace.
Methodology
VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=116; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single July 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends; all figures are drawn from the July fielding only. Several questions were multiple-select, so those shares can sum to more than 100%.
By role the sample is senior and buyer-credible: 44% are final decision-makers for AI purchases and another 38% recommenders or influencers. Managers (36%), individual contributors (27%), VPs and directors (18%), and the C-suite (16%) make up the seniority mix. By organization size the sample is mid-market-weighted with a meaningful enterprise tail: 101–250 (34%) and 251–1,000 (23%) employees lead, with 1,001–5,000 (18%), 10,001+ (17%), and 5,001–10,000 (7%) above them. Technology/Software is the largest industry at 38%, followed by Healthcare/Life Sciences (11%) and Financial Services (10%).
Three questions require a base note. Two questions were asked only of enterprises with agents live or piloting. Posture figures (observe / enforce / isolate) are reported on those 93 respondents, and primary-security-layer figures on the 92 of them who named a layer. The 23 respondents outside this base are those still evaluating, without plans, or unsure — organizations for which an agent security posture would not yet apply. And several multiple-select questions permitted overlapping answers where one was intended — identity (33 respondents selected more than one pattern), arms-race assessment (23), budget share (10), and incidents (9) — so those are computed at the respondent level and the overlap is described where it matters. Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 76 of the 116 qualified respondents.
At 116 respondents, the sample supports directional reads but not precise measurement; it is self-selected and is not a probability sample. It is best read as the view from organizations actively standing up agent security rather than from the largest operators.
Finding 1: Agents are in production, and so are the incidents
A majority have already had an agent security event
We asked whether organizations run agentic AI in production, and whether they had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm.
Agents have moved into production for this cohort. More than half of enterprises (53%) run agentic AI systems live today, another 27% are piloting or running a limited rollout, and only 3% have no plans in the next twelve months. The security exposure has scaled with the deployment: 53% of organizations have already had an agent security event, 19% a confirmed incident and 38% a near-miss caught before it caused harm.
That the near-misses outnumber confirmed incidents two to one is worth reading carefully. It means enterprises are catching problems, but catching them close to the edge — and a near-miss is a control that worked once, not a control that will work every time. The controls examined in the rest of this report, particularly the identity and isolation gaps in Findings 2 and 3, are what determine whether the next near-miss stays a near-miss.
One pattern from earlier waves does not replicate here. Organization size makes no reliable difference to exposure: enterprises above 1,000 employees report an incident or near-miss at 47%, against 57% among those between 101 and 1,000 — a difference well inside sample noise, and pointing the opposite direction from the size gradient this series has previously recorded. In this wave, what separates the hit from the not hit is not headcount.
Finding 2: Identity is improving — and still shared
Half give agents scoped identities; two-thirds still share credentials somewhere
We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Respondents could describe more than one pattern across the fleet.
Per-agent identity is now the most-cited pattern: 49% of enterprises say each agent carries its own scoped, managed identity, the precondition for least-privilege access and clean attribution. That is real progress on the control this series has repeatedly identified as the structural weakness beneath agent incidents.
But the answers overlap, and the overlap is the finding. Thirty-three respondents described more than one identity pattern across their fleet, and rolled together at the respondent level, 63% of enterprises report credential sharing somewhere — either agents mostly running on shared API keys and borrowed human or service-account credentials (37%), or a mixed fleet where some agents are scoped and many are not (34%). Only 29% describe a fleet with scoped identities and no sharing anywhere at all. Among enterprises with agents in production, 60% report per-agent identity, so the improvement is concentrated where the agents actually are — but so is the residual sharing.
The consequence is unchanged by the improvement. Where credentials are shared, an over-permissioned or compromised agent acts with far more reach than intended, and post-incident forensics cannot cleanly establish which agent did what. Half a fleet with scoped identities still has the blast radius of the half without. Non-human identity remains the largest unfinished piece of enterprise agent security, and as Finding 8 shows, it is still almost entirely absent from what enterprises are shopping for.
Finding 3: Isolation is the control nobody builds
Two-thirds enforce at runtime; fewer than one in five sandbox
We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is by far the least common. Figures are reported on the 93 respondents who described a posture.
This is the containment gap, and it is the widest structural gap in the report. Enforcement and observation are now common — 65% enforce scoped permissions at runtime and 56% monitor and log agent activity — while isolation sits at 18%. Only 8% of enterprises run both enforcement and isolation together, the posture that both prevents and contains.
Deployment maturity is a better predictor than the aggregate figures suggest. Isolation reaches 21% among enterprises with agents fully in production, compared with 13% among those still piloting — a meaningful gap that tracks maturity rather than exposure. Among enterprises that report credential sharing in the fleet, the group with the widest potential blast radius per Finding 2, isolation reaches 15%. The organizations with the most exposure are not meaningfully more likely to have built the control that bounds it.
The ordering is backwards from a defense-in-depth standpoint. Observation tells you what happened after the fact. Enforcement tries to stop it. Isolation is what limits the damage when enforcement fails — and enforcement will sometimes fail, which is the entire premise of the near-misses in Finding 1. An agent fleet that is watched and permissioned but not boxed in is precisely the configuration in which a single control failure propagates across systems. Enterprises have built the first two layers of the model and largely skipped the third.
Finding 4: Security still runs on borrowed, provider-native controls
Nine in 10 name a model provider or hyperscaler as their primary layer
We asked which agent security tooling enterprises use, and which is their primary layer. The answer continues to favor the model providers and hyperscalers over the dedicated security vendors.
Enterprises secure agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 44%, followed closely by Microsoft Azure (42%), Anthropic’s managed-agent controls (37%), and Google Cloud (31%). Asked to name a single primary security layer, 92% of those who answered named one of these provider-native offerings, with Azure (27% of answerers) and Anthropic (26%) leading.
The purpose-built agent-security category is no longer at zero, but it remains marginal. Cloudflare (11%) and Cisco (9%) lead the specialists, with CrowdStrike, Palo Alto, Zenity, Check Point’s Lakera, HiddenLayer, F5, and SentinelOne each between 1% and 7%. The identity specialists most directly relevant to Finding 2 are the smallest of all: Microsoft Entra Agent ID at 7%, Okta for AI Agents at 3%, and non-human identity platforms at 3%. Dedicated runtime sandboxing tooling — the control missing in Finding 3 — is in place at 3%.
A note on reading these shares: As described in the methodology section, the respondent sample is self-selected, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern is the durable part: provider-native and hyperscaler controls lead by a wide margin, and dedicated agent-security specialists remain in single digits. Read the individual shares loosely and the pattern with confidence.
Finding 5: Satisfaction is at a series high — and so is churn intent
Enterprises rate their tooling 4.29 of 5 and three-quarters plan to replace it
We asked how satisfied enterprises are with their current agent security tooling, and whether they plan to adopt a new, additional, or replacement solution within twelve months. The two answers do not sit comfortably together.
Satisfaction with agent security tooling is the highest this series has recorded — 4.29 out of 5 for both overall satisfaction and ease of implementation, with value for money close behind at 4.11. That is a striking set of scores for a stack that is mostly borrowed provider guardrails, given that a majority of the same enterprises have already had an incident or near-miss and fewer than one in five isolates high-risk agents.
The purchase intentions tell the other half of the story. Three-quarters (74%) plan to adopt, add, or replace agent security tooling within 12 months, and 30% within the next quarter alone — higher churn intent than this series has previously seen in this category. Only 26% intend to stand pat. Enterprises are simultaneously more satisfied with their tooling and more determined to change it than at any prior reading, which suggests the satisfaction rests on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is comfort with what is easy, not confidence in what is sufficient.
Finding 6: Budgets are finally moving
A third now spend more than a tenth of the security budget on agents
We asked what share of the security budget enterprises allocate to securing AI agents. The allocation has grown, though it remains a modest slice.
Agent security spending is still a slice rather than a pillar, but it is a growing one. The most common allocation remains 6–10% of the security budget (44%), and roughly a third of enterprises (35%) now devote more than a tenth — a meaningful funded minority. Just over a quarter (28%) spend 5% or less.
Read against Findings 1 through 3, the budget looks like a lagging but responsive indicator. A majority of enterprises have had an incident or near-miss, credential sharing persists across two-thirds of fleets, and fewer than one in five isolates high-risk agents — gaps that a 6–10% allocation is unlikely to close quickly. The enterprises spending above a tenth are the ones with the resources to build scoped identity and isolation controls rather than adopt whatever their model provider ships, and whether that minority grows is a reasonable leading indicator for whether the containment gap narrows.
Finding 7: The arms race has tilted
As many say attackers are ahead as say their defenses are
We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence has slipped into an even split.
Enterprises are no longer net-optimistic about the contest. Exactly as many say AI-armed attackers are ahead of their defenses (30%) as say their defenses are ahead (30%), with another 33% calling it roughly even and 24% saying it is too early to tell. Taken together, 63% rate the balance as even or worse.
Experience is what drives the pessimism, and the relationship is statistically clear. Among enterprises that have had a confirmed incident or near-miss, 39% say attackers are ahead; among those that have not, 20% do — a gap large enough to be unlikely to arise by chance in a sample this size. Getting hit does not just change what enterprises buy; it changes how they read the contest. The organizations closest to the actual threat are the least confident about it.
That assessment sits uneasily beside the series-high satisfaction of Finding 5. Enterprises rate their tooling 4.29 out of 5 while a clear majority believe it is, at best, holding even against an adversary that is also compounding with AI. An even race is not a comfortable place to be, and the group that has actually been tested rates it worse than even.
Finding 8: A reshuffle is coming — but identity still isn’t on the list
Incidents drive urgency; the control they implicate draws 10% interest
We asked which agent security solutions enterprises are considering. The consideration set has broadened, but not in the direction the incident data points.
Incidents start the buying cycle. Among organizations that have had a confirmed incident or near-miss, 38% plan to adopt, add, or replace agent security tooling within the next ninety days, against 22% of organizations with no incident; after a confirmed incident specifically the figure reaches 41%. Experience remains the strongest predictor of urgency in this data, as it is of pessimism in Finding 7.
The consideration set still leans provider-native — OpenAI (38%), Microsoft Azure (37%), Anthropic (35%), and Google Cloud (28%) lead — though the dedicated security vendors now draw meaningful early interest: Cisco (10%), Cloudflare (9%), Zenity and CrowdStrike (8% each), and Palo Alto, Check Point’s Lakera, and open-source guardrails (6% each). For most of the specialists that is more forward interest than current footprint.
What the shopping still does not include is the identity layer. Just 10% of enterprises include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set. Among the enterprises that both share credentials and have already been hit, the group with the most direct evidence that the control matters, identity consideration is no higher: roughly one in ten. Runtime sandboxing tooling draws 6%. The two controls most directly implicated by the incident data, identity and isolation, are the two least present in the purchase plans — the same blind spot this series recorded in the prior wave, unchanged despite a year of incidents.
The bottom line: A security gap that prevention alone won’t close
Organizations with more than 100 employees have put agents into production — 53% run them live today — and the incidents have arrived alongside them, with a majority already reporting a confirmed event or near-miss. On the controls, the picture is genuinely mixed rather than uniformly poor: nearly half now give each agent its own scoped identity, two-thirds enforce permissions at runtime, and a third devote more than a tenth of the security budget to agents. Enterprises are building agent security in earnest.
What they are not building is containment. Fewer than one in five isolates high-risk agents, only 8% pair enforcement with isolation, and among enterprises running agents in production isolation reaches just 21%. Credential sharing persists across 63% of fleets, so the blast radius that isolation would bound remains wide. The stac
今日のまとめ
AIデイリーブリーフで今日の重要ニュースをまとめ読み