Skip to content
Regulayer™Human Control for AI
Book a live demo

Learning Center · AI agent security

AI agent security, in numbers.

What security leaders report about AI agents, what agents have already done, what attackers manage in public challenges, and what the security authorities say. Every figure links to its primary source.

What security leaders report

Fewer than half can say what their agents may do.

45%

of CISOs are confident they can authorize what individual AI agents can do. 46% can centrally control what agents access; 47% can identify all agents in their environment.

Okta, Global CISO Insights 2026, 306 CISOs
54%

of organisations have no defined approach to limit AI agent access, or rely on predefined human access.

Gartner, 297 cybersecurity leaders, September 2026
81%

of security leaders are deeply concerned about excessive AI access not being properly reviewed. 21% govern agent access with shared credentials or broad-permission service accounts.

Okta, July 2026
80%

of companies say their AI agents have taken unintended actions. The most common: accessing unauthorized systems or resources (39%).

SailPoint and Dimensional Research, 353 respondents, May 2025. Self-reported
71%

of CISOs say AI has access to core business systems. Only 16% say they govern that access effectively. 92% of organisations lack full visibility into AI identities.

Cybersecurity Insiders, 235 security leaders, January 2026, sponsored by Saviynt
76%

of security professionals worry about the security implications of integrating AI agents.

Darktrace, 1,540 respondents, 14 countries, February 2026
75%

of US CISOs say AI agents are a critical or significant security risk. 30% saw suspicious AI agent activity in 2025.

Vorlon and Consensuswide, 500 US CISOs, February 2026
51%

name over-permissioned access among the most significant pain points. 78% have no formally adopted policy for creating or removing AI identities.

Cloud Security Alliance, 383 respondents, January 2026
74%

of IT application leaders believe AI agents are a new attack vector. Only 13% strongly agree they have the right structures in place to manage them.

Gartner, 360 IT application leaders, September 2025

What agents have already done

Agent actions, with the cost stated.

9 seconds

for a coding agent to delete a production database and its backups, using a token it found. The latest recoverable backup was about three months old, as the founder reported it.

Consequence Library: PocketOS, April 2026
2.5 years

of course data, and every automated snapshot, removed when an agent ran a destroy command against production. About 24 hours to recover.

Consequence Library: DataTalks.Club, February 2026
17,600

attacker actions against Hugging Face over four days, by evaluation agents that broke out of their environment.

Hugging Face technical timeline, July 2026 · The record
15

real systems ran a malicious package an evaluation agent published during roughly one hour online.

Anthropic, July 2026 · The record
19

unsanctioned live-internet actions in 10 of 122 runs during cyber testing of AI agents.

Consequence Library: UK AI Security Institute, August 2026
97%

of organisations that reported a breach of AI models or applications had no AI access controls in place. 13% reported such a breach. The global average cost of a data breach: $4.44 million.

IBM Cost of a Data Breach 2025

What attackers manage in public challenges

Public challenges, and what attackers managed.

88%

of participants in a public prompt injection challenge got a generative AI bot to reveal information it was told to protect.

Immersive Labs
60,000+

successful policy violations from 1.8 million prompt injection attacks on AI agents, including unauthorized data access and illicit financial actions.

Gray Swan with the UK AI Security Institute, July 2025
All

of the target frontier models had at least one successful attack found against them in a 2026 indirect prompt injection competition.

Competition paper, March 2026, reported by NIST CAISI

What the authorities say

The security authorities, in their own words.

“It is unclear if there are fool-proof methods of prevention for prompt injection.”OWASP, LLM01:2025
Prompt injection “may never be totally mitigated in the way that SQL injection attacks can be.”UK NCSC, December 2025
Prompt injection “is unlikely to ever be fully ‘solved’.”OpenAI, December 2025
“Prevent agents from autonomously executing high‑impact actions or outputs without prior human approval.”CISA, NSA, NCSC-UK and partners, May 2026
Govern agents “based on action privileges rather than model intelligence.”Gartner, September 2026
“How can an agent prove its authority to perform a specific action?”NIST NCCoE concept paper, February 2026

Where the money is going

Securing AI, forecast.

$2.8bn

forecast spend on securing AI in 2026, up 83%.

Gartner, August 2026
$4.8bn

forecast for 2027, a further 68.7% rise.

Gartner, August 2026

Survey figures are as each publisher reports them, with the sample stated. Several surveys are run or commissioned by companies that sell security products; the publisher is named on every figure.

Next

Try to talk an agent into it. Watch what reaches the systems.