
During VB Transform 2026, Visa’s president of technology, Rajat Taneja, demonstrated how Anthropic’s Mythos was applied to Visa’s payment network. The model was able to identify and exploit minor weaknesses in the system, leading Visa to release the harness used in the process as open-source.
However, the reality is that most enterprises lack the necessary engineering depth to effectively address security issues. A staggering 53% of enterprises have experienced a security incident or near-miss, highlighting the urgent need for better security measures. While 65% of enterprises enforce agent permissions at runtime, only 18% isolate their highest-risk agents, and a mere 8% combine enforcement with isolation.
Relying solely on provider-native controls for security measures further widens the gap. Research conducted by VentureBeat revealed that 92% of enterprises default to using security layers provided by hyperscalers and AI platform providers.
Multiple waves of research conducted since January have shown that there is a growing disparity between what enterprises require in terms of security and what is actually being implemented. This gap is often overlooked, putting enterprises’ agentic AI investments and futures at risk.
The disparity between satisfaction and incidents
Interestingly, enterprises tend to rate familiar tools higher, even if they have failed them in the past. A recent survey found that enterprises that experienced security incidents rated their satisfaction with security tools higher than those that did not. This suggests that enterprises reward tools that prevent breaches with higher satisfaction scores.
Furthermore, the research revealed that enterprises that do not isolate their highest-risk agents are more satisfied with their security tools compared to those that do isolate. This dissatisfaction among enterprises that prioritize security over convenience is what drives them towards more robust security measures.
It is crucial for enterprises to prioritize both identity and isolation in their security strategies. The failure to do so can result in breaches, as demonstrated by incidents involving rogue AI agents and credential sharing.
Enforcing permissions without isolating agents has proven to be ineffective, with enterprises that follow this approach experiencing a higher incident rate. This highlights the importance of implementing comprehensive security measures that include both enforcement and isolation.
The shift towards provider-native platforms
Provider-native platforms have become increasingly popular among enterprises, with a significant majority naming them as their primary security layer. The convenience of turning on guardrails provided by these platforms may contribute to high satisfaction levels, but it does not necessarily translate to effective security measures.
Despite the high satisfaction levels, a significant number of enterprises plan to replace their security tools within the next year. This indicates a growing awareness among enterprises about the need for more advanced security measures to combat agentic AI-based attacks.
Challenges in addressing security threats
While enterprises have made progress in deploying AI agents, there is still a lack of adequate controls to manage them effectively. The incident data highlights the false assumption that scoped identities alone can provide sufficient containment.
It is crucial for enterprises to prioritize building isolation and implementing governed identity controls to effectively address security threats. The next wave of research will likely shed more light on whether enterprises are proactively addressing these challenges or waiting for incidents to prompt action.



