54% of enterprises already had an AI agent incident
New VentureBeat research across 573 enterprise respondents finds AI agent governance shipped late — security incidents, unmetered spend, and a coming vendor churn wave.
Everyone deployed AI agents first and figured out the controls later. Now there's a number on it. VentureBeat Research published findings today from 573 qualified respondents showing that 54% of enterprises had an AI agent security incident or near-miss in the past 12 months, and that more than a quarter don't learn what an agent costs until the invoice arrives. The AI agent governance gap isn't a prediction anymore — it's a retrofit bill coming due.
What actually happened
The research is five parallel surveys fielded in June 2026 across the agentic stack: orchestration (101 respondents), reliability and evals (157), security and identity (107), infrastructure and compute (107), and context layers/RAG (101). All respondents were at organizations with 100 or more employees.
Three numbers do the work. Security: 54% reported an incident or near-miss — 18% a confirmed incident, 36% a near-miss caught before harm. Cost: 27% exercise only reactive control over agent spend, with no per-agent budget or ceiling. Churn: in every one of the five control layers measured, 57–68% of enterprises plan to switch vendors or add new ones within 12 months, and roughly a third plan to move within the quarter.
Read those together and the story isn't that agents are dangerous. It's that companies shipped them knowingly ahead of the controls, and are now paying to bolt the controls on — which is always more expensive than building them in.
Why this matters for your business
You're not a 500-person enterprise, and that cuts both ways. You have fewer agents to govern. You also have no security team, no FinOps function, and nobody whose job is noticing that an agent quietly ran up $3,000 in tokens on a retry loop.
The three gaps map to three things you can do this week, none of which require a platform purchase.
Meter every agent separately. One API key per agent or per workflow, with a hard spend ceiling on each. Not for accounting — so a runaway loop fails instead of billing. That 27% figure is the cheapest problem on the list to fix and the most common one we find.
Give agents their own credentials. Not a shared key, not your personal token. Scoped, revocable, per-agent. When something goes wrong you want to kill one credential, not rotate everything.
Log the decision, not just the output. Which model, which tools, which inputs, what it did. The 36% who caught a near-miss caught it because something was visible. If your agent's work is a black box between prompt and result, you don't get a near-miss — you get an incident.
The vendor-churn number is the quiet warning. Two-thirds of these teams are about to swap governance tooling, meaning most of what got bought in 2025 didn't hold. Build controls into your own systems where you can, and treat any governance vendor as replaceable.
Key takeaways
- 54% of enterprises had an AI agent security incident or near-miss in 12 months — 18% confirmed, 36% caught early
- 27% have no per-agent budget or ceiling and discover agent cost when the bill lands
- 57–68% plan to switch or add vendors in every control layer within 12 months; ~a third within the quarter
- Findings come from five VentureBeat Research surveys fielded June 2026, 573 respondents at orgs with 100+ employees
- Small teams get most of the benefit from three cheap moves: per-agent keys, hard spend ceilings, and decision-level logging
If you can't say what each agent cost you last month, you don't have controls — you have invoices. We build automations that meter and log themselves from day one. Model the cost per workflow or have us audit what you're already running.
Sources: VentureBeat Research, VentureBeat.
- #ai-agents
- #governance
- #ai-security
- #ai-costs
- #automation
Tommy Rush — Founder, Rush Commerce
Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More
Get The Rush Report weekly — one email, zero fluff.
Keep reading
Pilot Protocol's $4.5M: a directory isn't a standard
A seed-stage AI agent network wants to be where agents discover each other. Useful, but know the difference between an open spec and someone else's front door.
Read itNvidia backs Safe Superintelligence, discloses no terms
Nvidia's Safe Superintelligence partnership names no dollar figure and no term length. Reported at $5B. Here's how to read AI deals that omit the numbers.
Read it