VFF - The signal in the noise
News

69% of Enterprises Deploy AI Agents With Shared Credentials

Read original
Share
69% of Enterprises Deploy AI Agents With Shared Credentials

VentureBeat research of 107 enterprises found that 69% run AI agents with shared API keys, a critical security gap where a single compromised agent gains access to all permissions tied to that credential. The finding has triggered a $22 billion acquisition spree by Palo Alto Networks, CrowdStrike, and Cisco targeting non-human identity management. Only 32% of enterprises give each AI agent its own scoped identity, leaving the majority exposed to lateral movement and forensic blind spots.

  • 69% of enterprises deploy AI agents with shared credentials, exposing multiple workflows to single-point compromise
  • Only 32% of enterprises assign scoped, managed identities to individual AI agents
  • 54% of respondents have experienced an agent security incident or near-incident, with 18% confirming actual breaches
  • Palo Alto Networks, CrowdStrike, and Cisco have invested over $22 billion in acquisitions targeting non-human identity and runtime authorization layers

Shared API keys create a compounding risk where compromising one AI agent immediately grants attackers the accumulated permissions of every workflow using that credential. This eliminates forensic visibility into which agent performed which action, making incident response and attribution nearly impossible. The scale of the problem, affecting nearly 7 in 10 enterprises, indicates a fundamental gap in how organizations are deploying autonomous systems.

Security teams are currently catching most credential-sharing incidents at the last control point, but the margin is thin. Organizations without scoped identities for agents face higher breach risk, potential compliance violations, and operational blind spots that could delay incident detection and response. The acquisition activity signals that vendors view this as a critical market gap, likely to drive security spending and tool consolidation.

  • Credential sharing converts a single compromised agent into a multi-agent attack vector, amplifying blast radius and attacker reach across workflows
  • Lack of individual agent identities prevents security teams from determining which agent performed which action, breaking forensic chains and complicating breach investigations
  • The 69% figure suggests most enterprises are still in early stages of agent deployment and have not yet implemented identity and access controls designed for non-human actors

Monitor whether the recent acquisitions by Palo Alto Networks, CrowdStrike, and Cisco result in integrated products that enterprises actually adopt for agent identity management. Track whether incident rates among the 54% of respondents who have experienced agent security events increase or stabilize as more agents are deployed. Watch for emerging standards or frameworks around scoped identities for AI agents, as the current 32% adoption rate suggests the market is still defining best practices.

OneUpAI
OneUp Your Business. Get More Done. OneUp Your Business. Get More Done. OneUp Your Business. Get More Done.
Learn More
Share

Subscribe to the newsletter

The latest stories and analysis, delivered to your inbox.

Free. No spam. Unsubscribe any time.

Related stories

Anthropic Expands Cyberdefender Access to Claude Models
TrendingNews

Anthropic Expands Cyberdefender Access to Claude Models

Anthropic announced Tuesday that it is expanding and restructuring its cybersecurity access programs to give more cyberdefenders access to its most advanced Claude models for securing systems against potential AI attacks. The changes broaden participation in Anthropic's Cyber Verification program. The move positions Anthropic's models as tools for defensive security work against emerging AI-based threats.

by Rocket Drew· The Information
GLM 5.3 Now Available on Amazon Bedrock
TrendingNews

GLM 5.3 Now Available on Amazon Bedrock

GLM 5.3, a 753-billion-parameter mixture-of-experts model from Zhipu AI, is now available on Amazon Bedrock with managed APIs and cross-region inference. The model is optimized for coding and long-horizon agentic tasks, with reported improvements in coding benchmarks and emergent cybersecurity capabilities. Enterprise customers can access it without managing infrastructure, with support for prompt caching and OpenAI-compatible APIs.

by Alex Thewsey· AWS Machine Learning Blog
Google Freezes Open Source Bug Bounty Over AI Spam Surge

Google Freezes Open Source Bug Bounty Over AI Spam Surge

Google has temporarily frozen its open source bug bounty program due to a significant rise in AI-generated submissions. The influx of low-quality, AI-produced bug reports has overwhelmed the program's ability to process legitimate security findings. This action highlights a growing problem across bug bounty platforms where AI tools are being used to generate volume rather than quality submissions.

by Anthony Ha· TechCrunch AI
U.S. Data Centers Caught Between Security Policy and Chinese Suppliers
TrendingNews

U.S. Data Centers Caught Between Security Policy and Chinese Suppliers

U.S. data center operators including Amazon, Google, Microsoft, and Oracle depend on Chinese manufacturers for critical equipment like batteries, cooling systems, and optical transceivers despite growing national security concerns from the Trump administration and bipartisan congressional opposition. Chinese suppliers maintain a competitive advantage over American counterparts due to shorter lead times and more reliable delivery amid ongoing supply chain constraints. This dependency creates a tension between security policy and operational necessity for major cloud infrastructure providers.

by Claudia Chong· The Information