Learning Center · AI agent security
AI agent security, in numbers.
What security leaders report about AI agents, what agents have already done, what attackers manage in public challenges, and what the security authorities say. Every figure links to its primary source.
What security leaders report
Fewer than half can say what their agents may do.
of CISOs are confident they can authorize what individual AI agents can do. 46% can centrally control what agents access; 47% can identify all agents in their environment.
Okta, Global CISO Insights 2026, 306 CISOsof organisations have no defined approach to limit AI agent access, or rely on predefined human access.
Gartner, 297 cybersecurity leaders, September 2026of security leaders are deeply concerned about excessive AI access not being properly reviewed. 21% govern agent access with shared credentials or broad-permission service accounts.
Okta, July 2026of companies say their AI agents have taken unintended actions. The most common: accessing unauthorized systems or resources (39%).
SailPoint and Dimensional Research, 353 respondents, May 2025. Self-reportedof CISOs say AI has access to core business systems. Only 16% say they govern that access effectively. 92% of organisations lack full visibility into AI identities.
Cybersecurity Insiders, 235 security leaders, January 2026, sponsored by Saviyntof security professionals worry about the security implications of integrating AI agents.
Darktrace, 1,540 respondents, 14 countries, February 2026of US CISOs say AI agents are a critical or significant security risk. 30% saw suspicious AI agent activity in 2025.
Vorlon and Consensuswide, 500 US CISOs, February 2026name over-permissioned access among the most significant pain points. 78% have no formally adopted policy for creating or removing AI identities.
Cloud Security Alliance, 383 respondents, January 2026of IT application leaders believe AI agents are a new attack vector. Only 13% strongly agree they have the right structures in place to manage them.
Gartner, 360 IT application leaders, September 2025What agents have already done
Agent actions, with the cost stated.
for a coding agent to delete a production database and its backups, using a token it found. The latest recoverable backup was about three months old, as the founder reported it.
Consequence Library: PocketOS, April 2026of course data, and every automated snapshot, removed when an agent ran a destroy command against production. About 24 hours to recover.
Consequence Library: DataTalks.Club, February 2026attacker actions against Hugging Face over four days, by evaluation agents that broke out of their environment.
Hugging Face technical timeline, July 2026 · The recordreal systems ran a malicious package an evaluation agent published during roughly one hour online.
Anthropic, July 2026 · The recordunsanctioned live-internet actions in 10 of 122 runs during cyber testing of AI agents.
Consequence Library: UK AI Security Institute, August 2026of organisations that reported a breach of AI models or applications had no AI access controls in place. 13% reported such a breach. The global average cost of a data breach: $4.44 million.
IBM Cost of a Data Breach 2025What attackers manage in public challenges
Public challenges, and what attackers managed.
of participants in a public prompt injection challenge got a generative AI bot to reveal information it was told to protect.
Immersive Labssuccessful policy violations from 1.8 million prompt injection attacks on AI agents, including unauthorized data access and illicit financial actions.
Gray Swan with the UK AI Security Institute, July 2025of the target frontier models had at least one successful attack found against them in a 2026 indirect prompt injection competition.
Competition paper, March 2026, reported by NIST CAISIWhat the authorities say
The security authorities, in their own words.
Where the money is going
Securing AI, forecast.
forecast spend on securing AI in 2026, up 83%.
Gartner, August 2026forecast for 2027, a further 68.7% rise.
Gartner, August 2026Survey figures are as each publisher reports them, with the sample stated. Several surveys are run or commissioned by companies that sell security products; the publisher is named on every figure.
Next
