All AI News
    Discovery — CIO / CTOWednesday, August 5, 2026 19 min read
    AI

    State of AI Agent Security Report 2026

    Enterprise AI agent fleets doubled in 4 months; security coverage barely moved, leaving 48% of agents unsecured.

    Koko brief

    Enterprise AI agent fleets doubled in 4 months; security coverage barely moved, leaving 48% of agents unsecured.

    A confidence-reality gap is opening at enterprise scale. Gravitee's April 2026 survey of 750 senior technology leaders finds agent deployments have roughly doubled since December 2025, with 38% of organizations now running over 100 agents. Yet mean monitoring coverage sits at 52%, 54% of organizations have already suffered a security incident, and accountability structures remain largely absent. Deployment appetite is accelerating; governance is not.

    Watch: Whether identity standards and centralized enforcement frameworks emerge fast enough to match the quarterly doubling rate before a high-profile incident forces regulatory intervention.

    gravitee.io Menu ✅ Unified API, event, agent management platform ✅ Event-native, streaming-first API gateway ✅ Multi-gateway, multi-broker governance ✅ Unified API, event, agent management platform ✅ Event-native, streaming-first API gateway ✅ Multi-gateway, multi-broker governance Adoption Is Outpacing Control The State of AI Agent Security 2026 Updated April 2026. Our second survey of 750 senior technology leaders across the UK and USA reveals that the enterprise AI agent estate has doubled in four months, while security coverage has barely moved. Download the whitepaperBuild Your First Agent April 2026 | n=750 CIOs, CTOs, VPs Engineering, Heads of Platform | Financial Services, Healthcare, Telecoms, Manufacturing, Travel & Transport 2× Agent estates doubled in 4 months since Dec 2025 48% of production AI agents are running unsecured 54% of organisations have already had a security incident Analyze the Report with AI Ask ChatGPT, Claude, or Perplexity to explain the State of AI Agent Security for you chatgpt.comgoogle.comperplexity.aiclaude.ai Last updated on: April, 2026 |Published: June 15th, 2026 |Author: Jorge Ruiz Executive Summary: The confidence-reality gap is widening 💡 AI agent fleets have roughly doubled since December 2025. Confidence in security has risen. But monitoring coverage, accountability structures, and pre-deployment controls have barely moved. Organisations are becoming more comfortable with a risk they haven't actually reduced. This update combines findings from our latest survey of 750 executives in April 2026 with results from December 2025. The message is clear: organizations understand the risks of AI agents, but struggle to manage them in practice. Incidents are already occurring at scale. What's missing is cohesion: consistent identity models, centralised enforcement, clear ownership, and continuous visibility. 0% plan to deploy significantly more agents in the next 12 months 0% have no formal accountability structure for AI agent behaviour 0% of orgs secure at least 80% of their agents, even though 92% report having visibility. Download the whitepaper Finding 1: Deployment Scale The agentic enterprise is already here at scale 📈 AI agent fleets have roughly doubled since December 2025. Confidence in security has risen. But monitoring coverage, accountability structures, and pre-deployment controls have barely moved. Organisations are becoming more comfortable with a risk they haven't actually reduced. Enterprise AI agents have roughly doubled in a single quarter. The December 2025 survey showed a mean of ~37 agents per organization. By April 2026, the distribution had shifted sharply, with nearly 38% of organizations saying they already have more than 100 agents deployed. Number of AI agents currently deployed: Dec 2025 vs Apr 2026 None / 1-10: Dec 2025: 8.6%, Apr 2026: 0.6% 11-25: Dec 2025: 29.7%, Apr 2026: 7.5% 26-50: Dec 2025: 37.3%, Apr 2026: 19.6% 51-75: Dec 2025: 17.7%, Apr 2026: 13.5% 76-100: Dec 2025: 6.5%, Apr 2026: 21.1% 101-125: Dec 2025: 0%, Apr 2026: 18.4% 126-150: Dec 2025: 0%, Apr 2026: 12.8% 151+: Dec 2025: 0%, Apr 2026: 6.7% 81.7% of organisations plan to deploy more agents in the next 12 months, with 28% planning significantly more. Travel & transport leads intent to expand (90%), while healthcare shows the most caution. The only direction is forward, which makes every security gap identified today a larger risk within the year. By 2028, an average global Fortune 500 enterprise will have over 150,000 agents in use, up from fewer than 15 in 2025. Gartner 2026: Beyond Agent Sprawl - The Rise of AI Agent Management Platforms Our survey data validates this trajectory. The April 2026 cohort of active deployers among senior technology leaders is already running at 76–100 agents and doubling every quarter, placing them on the same exponential growth curve predicted by Gartner. Beyond the data To learn more about the agent growth trajectory and what it means for governance, explore ourA2A Summit Hub. Finding 2: The Monitoring Gap 90% of organisations have unmonitored agents in production 🔍 Only 9.5% of organisations are securing more than 81% of their deployed agents. The mean monitoring coverage is 52%, meaning 48% of all AI agents in production are running unsecured. This is the most critical operational finding in the report. % of deployed AI agents actively monitored and secured (Apr 2026) 1-20%: 1.8% 21-40%: 24.7% 41-60%: 35.6% 61-80%: 28.3% 81-100%: 9.5% The monitoring mean has barely moved since December 2025 (46.96% → ~52%), even as the total fleet has doubled. The absolute number of unmonitored agents is increasing, not because organisations are becoming less vigilant, but because deployment velocity is dramatically outpacing governance implementation. 0% of production AI agents are running without security or governance 0% of organisations secure more than 80% of their agents 0% feel confident in their visibility, up from 83% in December The confidence-reality inversion is getting worse. Stated confidence in agent visibility rose 9 percentage points in four months (82.6% → 91.8%), while monitoring coverage barely moved. This is a classic precursor to a major incident: organisations growing more comfortable with a risk they haven't actually reduced. Beyond the data 80% of organisations are already deploying AI agents but only 10% feel they have control. This documentary filmed at MIT and other locations asks why, and what happens if we do not act now. Hosted by AI journalist Alex Kantrowitz, featuring former White House CIO Theresa Payton, MIT researcher Ramesh Raskar, Alibaba's former executive Sharon Gai, Michelin's CDAO Ambica Rajagopal, and our own CEO. Watch here -> gravitee.io Finding 3: Pre-Deployment Governance 8 in 10 orgs ship AI agents to production without full security controls ⚠️ Only 19.7% of organisations say all their agents are fully secured and governed before going live. The majority (59.1%) say "most" are, meaning a meaningful proportion of their fleet routinely enters production without adequate controls. Agents fully secured and governed before going live (Apr 2026) All of them: 19.7% Most of them: 59.1% Some of them: 19.7% Very few of them: 1.6% This represents a surface improvement from December 2025, when only 13.6% said all agents were secured, but the "most but not all" category expanded dramatically (41.4% → 59.1%), suggesting organisations may be reclassifying their posture more optimistically rather than genuinely closing the gap. When asked what controls are in place before an agent goes live, no single control is used by even 40% of organisations: Pre-deployment security controls in place (Apr 2026, % of organisations) Named person accountable for agent behaviour: 37.8% Security review from IT or CISO: 35% Documented process to pause or revoke access: 34.1% Plan for how agent will process sensitive data: 33% Data access controls specific to that agent: 32% Defined scope of what agent is permitted to access: 30.5% None of the above: 0.7% Beyond the data Only 1 in 5 organizations fully secures its AI agents in production.Gravitee gives you the visibility and control to be one of them. Finding 4: Security Incidents 54% of organisations have already suffered a

    Key takeaways
    • 01A confidence-reality gap is opening at enterprise scale.
    • 02Gravitee's April 2026 survey of 750 senior technology leaders finds agent deployments have roughly doubled since December 2025, with 38% of organizations now running over 100 agents.
    • 03Yet mean monitoring coverage sits at 52%, 54% of organizations have already suffered a security incident, and accountability structures remain largely absent.
    • 04Deployment appetite is accelerating; governance is not.

    Don't miss tomorrow's

    The Daily Pulse in your inbox each morning — sourced and linked.

    How often
    Keep going — across the app