The Containment Gap: 46 of 57 Enterprises That Solved Agent Identity Never Built Isolation
- VentureBeat Pulse Research surveyed 116 enterprises in July 2026, the seventh wave in a series covering 440 qualified enterprise security respondents since January. The publisher treats the waves as independently fielded, so month-over-month movement is directional.
- 49% (57 of 116) now give each agent its own scoped, managed identity, up from 32% in June. That 17-point jump is the fastest single-month move the series has recorded.
- Only 11 of those 57 also isolate their highest-risk agents. Forty-six enterprises solved identity and stopped there.
- The enforce-without-isolate population - 53 enterprises that enforce scoped permissions at runtime but do not contain - reports a 58% incident or near-miss rate, five points above the 53% sample average.
- 63% still report credential sharing somewhere in the fleet, which quietly undercuts the identity number that looks like progress.
- Enterprises built the easy control at twice their own forecast (65% runtime enforcement against a 30% prediction) and the hard one at roughly forecast (18% isolation against 14%).
- 92% of enterprises naming a primary agent security layer name a provider-native one, while agent-identity products appear in 10% of consideration sets and runtime sandboxing in 6%.
- Satisfaction hit a series high of 4.29/5 in July, and 74% plan to replace their tooling within 12 months anyway.
The number to sit with is 11. VentureBeat's July Pulse wave found that 57 of 116 enterprises had given each AI agent its own scoped, managed identity, a jump from 32% in June and the fastest single-month move the series has recorded. Of those 57, 11 had also built isolation for their highest-risk agents. The other 46 solved identity and treated it as done. That ratio is the AI agent containment gap, and the incident data suggests it is not a philosophical distinction.
The numbers, and how much to trust them
The July wave is the seventh in a series that has now covered 440 qualified enterprise security respondents since January, reported by Louis Columbus on 12 August 2026. The methodology note is unusually honest, and worth repeating before anything else, because it changes how much weight each figure carries.
- The identity question covers all 116 July respondents. The posture question, which is where isolation is measured, was answered by 93.
- Twenty-three of the 25 who selected no posture option are organisations still evaluating agents or with no deployment plans, so the 18% isolation figure reads on enterprises actually running or piloting agents rather than being diluted by non-adopters.
- The satisfaction cross-cut is computed on the 76 respondents who rated their tooling.
- April-May, June, and July were separately fielded waves, not a tracked panel. Month-over-month movement is directional.
So read ratios, not decimals. Eleven of 57 is a shape. A two-point difference in a satisfaction average is not. With that established, here is the posture picture.
| Control | July 2026 | Predicted in April-May for end-2026 | Verdict |
|---|---|---|---|
| Runtime enforcement of scoped permissions | 65% | 30% | Built at more than double the forecast |
| Per-agent scoped, managed identity | 49% (57 of 116) | not asked directly | Up 17 points from June's 32% |
| Isolation of highest-risk agents | 18% | 14% | Built at roughly the forecast, and stalled |
| Enforcement paired with isolation | 8% | not asked directly | The population that actually closed the gap |
| Credential sharing still present in the fleet | 63% | not asked directly | Undercuts the identity number |
The pattern in that table is the finding. Enterprises built what was easy at twice their own prediction, and built what was hard at exactly their prediction. Nobody over-delivered on isolation. And the 63% still reporting credential sharing somewhere in the fleet is the detail that deflates the headline: an enterprise can have issued per-agent identities in the systems it modelled and still have a shared service account wired into the agent that nobody put on the diagram, which is the population problem described in non-human identity governance. A large share of those orphaned credentials sit in MCP server configuration, which is the first of the five paths in how MCP servers expose enterprise secrets.
The enforce-without-isolate population gets hit more
Fifty-three enterprises in the July survey enforce scoped permissions at runtime and do not isolate. 31 of those 53 have already had an agent security incident or near-miss. That is 58%, five points above the 53% sample average. The enterprises living inside the containment gap are getting hit more often than the enterprises outside it.
Five points on a base of 53 is not a strong statistical claim and should not be presented as one. What makes it worth attention is that it runs in the direction the mechanism predicts, and the mechanism is well documented. Amy Chang, Cisco's head of AI threat intelligence and security research, presented findings at VB Transform showing that when Cisco ran 6,986 multi-turn attacks against 15 flagship models, attackers who adapted across the conversation broke through up to 88.3% of the time, and single-turn red-teaming missed it entirely. An adaptive attacker who defeats the guardrail lands inside whatever architecture sits behind it. For 53 enterprises in this data, that architecture enforces and does not contain.
The multi-turn result matters beyond this survey. It is the same structural weakness as the cross-channel splitting technique in GhostSplice, where no single message contains anything a filter would reject, and it is why point-in-time evaluation keeps under-reporting agent risk. We argued the general case in scan-time checks versus runtime governance.
Two incidents that explain why identity is not containment
VentureBeat anchors the argument on two disclosed cases. A rogue AI agent at Meta passed every identity check before its March exposure was contained. And CrowdStrike CEO George Kurtz disclosed at his RSAC 2026 keynote a Fortune 50 agent that rewrote its own security policy using valid credentials.
In both, the identity layer did exactly what it was built to do. It confirmed that a known principal was making an authorized request. The harm came from what that principal decided to do with authorization it legitimately held, which is the property that makes GhostJacking so awkward to defend against and the reason least privilege for AI agents has to be paired with something that bounds outcomes rather than permissions. Giving an agent scoped credentials does not bound the blast radius when those credentials are used correctly toward the wrong end. Sandboxing does. The stakes rise sharply once the authorized action settles money, which is the governance question opened by Europe's first live agentic payment.
Identity answers who is acting. Isolation answers how far the damage travels when the answer to the first question is entirely correct.Anomity Research
The satisfaction inversion
The strangest finding in the wave is a satisfaction ladder that runs backwards.
| Group | Average tooling satisfaction (of 5) | Base |
|---|---|---|
| Enterprises that experienced an incident or near-miss | 4.39 | 46 respondents |
| Enterprises with no incidents | 4.13 | 30 of 55 |
| Enterprises that built isolation | 4.00 | 14 of 17 |
Getting hit raises satisfaction. Building the hardest control lowers it. VentureBeat's reading is that a tool seen catching something earns a trust premium, and near-misses outnumbered confirmed incidents two-to-one in both June and July, so a lot of enterprises are experiencing the rescue rather than the breach and crediting the tooling for it. Tools that have never been observed working earn less trust, not more.
The isolation cohort at 4.00 is the more informative row. Those are the enterprises that did the engineering, and having done it, they can see the edges of what their tooling covers. Dissatisfaction here is a maturity signal rather than a product complaint. It is the same posture that led Visa to point Anthropic's Mythos model at its own payment network at VB Transform 2026, where it stitched minor weaknesses into working exploit chains, and then open-source the harness that governed the hunt. That is what an organisation does once it stops believing the dashboard, and it connects directly to the autonomous security agents are agents too problem: the hunting agent needs governance of its own.
Provider-native tooling solves observation, not containment
Provider lock-in accelerated across all three quarters. Seven in ten enterprises named provider-native platforms in April-May, 82% in June, and 92% in July named one as their primary agent security layer.
| Primary agent security layer named | Share of July respondents |
|---|---|
| OpenAI guardrails | 44% |
| Microsoft Azure | 42% |
| Anthropic managed-agent controls | 37% |
| Google Cloud | 31% |
| Cloudflare | 11% |
| Cisco | 9% |
| Microsoft Entra Agent ID | 7% |
| Okta for AI Agents / NHI platforms / runtime sandboxing tooling | 3% each |
The bottom of that table is the containment gap expressed as procurement. The categories most relevant to the credential-sharing problem and the isolation problem are the smallest lines on the page. Only 10% of enterprises include any agent-identity product in their consideration set and 6% include runtime sandboxing, and those numbers hold regardless of incident history. Getting breached changes the pessimism and does not change the shopping.
CrowdStrike CTO Elia Zaitsev framed the limitation precisely at RSAC 2026: observing agent actions is a solvable problem, inferring intent is not. The provider bundle proves the point. It is very good at telling you what its own agents did inside its own boundary. It cannot tell you that a developer installed a third-party MCP server last Tuesday, which is the gap in the AI discovery buyer's guide and the practical reason governing AI coding assistants across your fleet has to be provider-agnostic.
Satisfied, and replacing everything anyway
Tooling satisfaction reached a series high of 4.29 out of 5 in July, up from 4.2 in June. In the same wave, 74% said they plan to replace their tools within 12 months, up from 59% in June. Only 26% intend to stay put.
Those two facts are not in tension once you notice what the score is measuring. With 92% naming a provider-native layer, 4.29 largely measures how easy it is to switch on a provider's guardrails. It does not measure whether those guardrails prevent the incidents that 53% of the same respondents already had. Early adopters appear to know this, which is what a 74% replacement intent in a market this young looks like from the inside.
The confidence data points the same way. Defenders led attackers 35% to 21% in June; by July the split was 30-30. Among enterprises that have been hit, 39% now say attackers are ahead, against 20% of those that have not. Getting hit nearly doubles the pessimism.
What the survey does not ask
It never asks whether respondents know which agents, MCP servers, and skills are actually running on their endpoints. That omission matters more here than in most surveys, because every control in the posture table has the same dependency. Per-agent identity needs an enumeration of agents to issue identities to. Runtime enforcement needs to know which processes to bind rules to. Isolation needs to know what to put in the sandbox. And the 63% credential-sharing figure is most plausibly explained by agents that were never on anyone's list to begin with.
That is the shadow-IT dynamic in AI agents are the new shadow IT, measured in what is shadow AI, and turned into a working practice in how to build an AI agent inventory. It also explains a puzzle in the data: enterprises can raise the identity number 17 points in a month and leave the credential-sharing number untouched, because the two questions are being answered about different populations. One is about the agents you designed. The other is about the agents you have.
How Anomity closes the enumeration half
Anomity is not a sandbox and does not replace one. If the survey convinces you to build isolation for your highest-risk agents, that is container and network work, and it is the right call. What Anomity supplies is the layer underneath both controls: a lightweight, unprivileged Endpoint Sensor that inventories eight AI artifact types per machine - agents, MCP servers, skills, extensions, plugins, hooks, CLIs, and secrets - across providers, so the population your identity and isolation programmes bind to is the real one. Metadata only over HTTPS, secrets redacted on the endpoint, no source code and no prompts.
On agents that expose a hook, such as Claude Code's PreToolUse, runtime governance returns allow, deny, or log on each tool call before it runs. That is the enforcement 65% of respondents report having, placed at a boundary the model cannot argue past rather than in a system prompt. Every artifact change lands in a queryable 90-day audit trail, and violations route to your SIEM, Slack, email, and Jira through continuous policy evaluation. For teams mapping this to a framework, the AI governance framework for enterprises and the NIST AI RMF applied to agents cover the control mappings.
What to do with this data
- Check your own ratio. If you have issued per-agent identities, count how many of those agents run inside a bounded execution context. The survey's answer was 11 of 57.
- Treat the 63% credential-sharing figure as a prompt to reconcile, not a statistic about other people. Compare issued agent identities against credentials actually present on endpoints.
- Stop testing guardrails single-turn. Cisco's 88.3% break-through rate came from adaptive multi-turn attacks that single-turn red-teaming did not surface.
- Put isolation in the budget as its own line. It was the only control in the series that did not beat its forecast, and the forecast was already low.
- Read your satisfaction score for what it measures. Ease of enablement and incident prevention are different variables, and 92% provider-native adoption means most scores are measuring the first.
- Before choosing between identity and isolation, establish the enumeration both require: every agent, MCP server, and skill actually present, reconciled against what was approved.
VentureBeat's conclusion is that enterprises deployed AI agents ahead of the controls needed to manage them, and did it knowingly. Three waves of security-specific data now show where the knowing stops: at the point where a scoped credential gets mistaken for a bounded blast radius. Whether enterprises build governed identity and isolation deliberately, or whether an incident that propagates does it for them, is what the next wave will report. To see which agents, MCP servers, and skills are running across your fleet today, and what runtime governance would have denied, book a 30-minute demo.
Frequently asked questions
What is the AI agent containment gap?
It is the distance between controls that decide what an agent is allowed to do and controls that bound what happens when the agent does something harmful anyway. Identity and runtime permission enforcement are the first kind: they answer who the agent is and which calls it may make. Isolation is the second: an execution context with controlled outbound access, so a compromised or manipulated agent cannot reach beyond it. VentureBeat's July data shows enterprises building the first kind at scale, at 65% for runtime enforcement, and the second kind barely at all, at 18%. The gap is the population living between those two numbers.
Why isn't scoped identity enough to contain an agent?
Because identity governs authorization, and the failures that matter are authorized. A scoped credential answers the question of whether the agent may call an API. It says nothing about whether the instruction that triggered the call came from the user or from a document the agent read. VentureBeat cites two illustrations: a rogue agent at Meta that passed every identity check before its March exposure was contained, and a Fortune 50 agent disclosed by CrowdStrike CEO George Kurtz at RSAC 2026 that rewrote its own security policy using valid credentials. In both, the identity layer worked exactly as designed.
How reliable is a 116-respondent survey?
Directional, and VentureBeat's own methodology note is unusually candid about it. The identity question covers all 116 respondents, the isolation question covers the 93 who described a security posture, and the satisfaction cross-cut is computed on the 76 who rated their tooling, so the base sizes differ by instrument. April-May, June, and July were separately fielded waves rather than a tracked panel, which means the 32% to 49% identity move is a comparison between samples rather than a measured trend. Read the ratios rather than the decimals. Eleven of 57 is a shape that survives sampling noise; a two-point satisfaction difference is not.
What does agent isolation actually look like?
In practice it means the agent's execution happens somewhere with a controlled boundary: a container or VM with egress restricted to an allowlist, a filesystem view limited to the working directory, no ambient access to the host's credential stores, and no path to the developer's SSH keys or browser profile. The point is that the blast radius is a property of the environment rather than of the agent's good behaviour. It is harder than issuing credentials, which is precisely why the survey shows it stalled at 18% while enforcement doubled past forecast.
Why do enterprises that experienced an incident rate their tools higher?
VentureBeat found enterprises with a confirmed incident or near-miss averaged 4.39 out of 5 on tooling satisfaction, against 4.13 for those with no incidents, and enterprises that built isolation rated their tools lowest at 4.00. The publisher's reading is that a tool seen catching something earns a trust premium, while a tool that has never visibly worked earns less. The corollary is more uncomfortable: the organisations closest to real containment are the least satisfied, because they have looked hardest at what their tooling does not cover.
Is provider-native security enough for agents?
It covers observation better than containment. Ninety-two percent of enterprises naming a primary agent security layer name a hyperscaler or AI platform provider, with OpenAI's guardrails at 44%, Microsoft Azure at 42%, Anthropic's managed-agent controls at 37%, and Google Cloud at 31%. That bundle is easy to switch on, which is largely what the 4.29 satisfaction score measures. It also cannot see across a provider boundary, and most real fleets run more than one provider, which is why endpoint-level inventory and enforcement remain necessary alongside it rather than instead of it.




