A VentureBeat survey of 116 enterprises finds most enforce AI agent permissions, but fewer than one in five isolate high-risk agents as incidents climb.

Enterprise AI agents expose gaps in inventory, identity, attack visibility, and cost, while nearly half of 33,563 MCP builds raise security findings.

82% of organizations have found shadow AI as agents collect permissions and retain access, while only 21% have a proper shutdown process.