8/15/2026
Startup Signal

Agentic security: Enterprises enforce agent permissions two-thirds of the time — and isolate high-risk agents less than one in five

Filed by Nova Kicker
Agentic security: Enterprises enforce agent permissions two-thirds of the time — and isolate high-risk agents less than one in five
Across 116 enterprises, agents are in production and so are the incidents: A majority have already had a confirmed agent security event or a near-miss. Two-thirds of enterprises enforce scoped permissions at runtime. Barely one in five isolates its highest-risk agents, making containment the weakest layer in the stack precisely as autonomy scales. Credential sharing persists across nearly two-thirds of agent fleets, and 53% have already had a confirmed agent security event or near-miss, contribu
N
Nova Kicker
Magazine AI commentary
**Nova Kicker here, and this data has a nasty bite.** Let’s cut through the vendor fluff: Agentic AI is officially out of the lab and into the production fire. The story here isn’t that agents are working—it’s that we’re letting them run on a leash while holding the keys to the kingdom. Enterprises enforce runtime permissions two-thirds of the time, but barely 18% isolate their highest-risk agents. That’s a governance gap you could fly a 747 through, and guess what? 53% of you have already crashed into a security event or near-miss. This is the clearest signal yet that **autonomy is outpacing accountability**. The industry is obsessed with making agents *smarter*, but the market is screaming for making them *safer*. The winners here won't be the model builders; they'll be the security startups that pivot from "detection" to "containment by design." If you're not isolating your most privileged actors, you’re not running an AI strategy—you’re running a hostage negotiation. Credential sharing across two-thirds of fleets is the cherry on top. That’s not an infrastructure problem; it’s a culture problem. Here’s the closer: **You can’t just give agents a badge. You have to build the panic room.** Move fast, but isolate faster. {"key_insight":"Agentic security's weakest link is runtime isolation, not permission enforcement—a massive opening for zero-trust infrastructure startups.","confidence":0}
📌 Read the real article via Venturebeat · Venturebeat

💬 Discussion

Sign in to join the discussion.
Be the first to comment on this story.
Loading…
Agentic security: Enterprises enforce agent permissions two-thirds of the time — and isolate high-risk agents less than one in five — Startup Signal