Monday Jul 6

88% Of Firms Hit By Agent Breach

6JUL
IT LEADER88% HIT

AI agents are already causing real security incidents at scale. AvePoint surveyed 750 IT leaders and found 88.4% had an incident this year. Adoption is outrunning governance almost everywhere.

This isn't one outlier study. Three separate research shops ran the numbers this year, using different samples and different questions.

One found 88% among 900 executives it polled. Another separately found most organizations run tools nobody officially tracks. The methods differ; the conclusion doesn't.

Governance keeps landing behind deployment speed. That gap is what procurement teams will ask about next.

full brief & sources

Why this matters

  • Multiple independent surveys now agree: most enterprises already had an AI agent security incident, not a hypothetical risk.
  • Governance and security tooling are lagging well behind deployment speed.
  • This is the number procurement and security teams will cite in every AI agent vendor conversation from here.

🔍 What happened

  • AvePoint published its third annual State of AI report on June 29, surveying 750 global IT leaders.
  • 88.4% of respondents reported at least one AI agent-related security incident in the past 12 months.
  • Gravitee's separate survey of 900+ executives found 88% reporting confirmed or suspected agent incidents.
  • Cloud Security Alliance's survey found two in three orgs had agent-related incidents, and many have unknown agents running unmanaged.
  • All three surveys ran independently across financial services, healthcare, and government sectors.

💬 Smart takes

  • AvePoint: agent adoption and agent governance are moving at two very different speeds inside most organizations.
  • Cloud Security Alliance: a large share of enterprises don't even have full visibility into which agents are running.
  • Skeptic: 'security incident' is a broad bucket, it can mean anything from a minor scope violation to an actual breach, so the number may overstate severity.

🧭 Where this goes

  1. LikelyAI agent governance tooling becomes a standard enterprise security purchase within a year.
  2. Likelyvendors like Anthropic and OpenAI face more procurement questions about agent scoping and audit trails.
  3. Likelythis stat gets cited in every enterprise AI security vendor pitch through 2027.
  4. Possiblea major public agent-caused breach becomes the forcing function for regulation.
  5. Wild Carda large enterprise pauses agent rollouts entirely after a public incident.

🥄 The Spoon Take

Every survey this year lands near the same number. Most companies already had an AI agent security incident. That is the default state now, not an edge case. The next edge in enterprise AI is proving which agents are running and what they touch.

🤔 Pushback

Different surveys use different definitions of 'incident,' so the headline number may be inflated by minor scope violations.