Skip to content
MarketScale
‹ Back to IndustriesSoftware & Technology

Half of enterprises hit by AI agent security incidents as deployments surge, DigiCert finds

A DigiCert survey reveals that 78% of IT leaders have faced AI-related security incidents in the past six months, though only half have implemented formal governance programs. This highlights the growing challenge enterprises face as AI deployment increases. Effective governance and security mechanisms are critical to mitigating these risks.

This story was produced through MarketScale. See how Software & Technology teams put it to work with Executive Thought Leadership.

By MarketScale Newsroom · DigicertAi SecurityAi GovernanceEnterprise Ai
Share
Learn this in 60 seconds

Key facts, context, and what it means, in one minute.

:60
0:001:00
Half of enterprises hit by AI agent security incidents as deployments surge, DigiCert finds

Key takeaways

01

78% of IT leaders experienced AI security issues recently.

02

Only half of the organizations have formal governance programs for AI.

03

There's an urgent need to enhance AI security measures.

Get featured

Want MarketScale to feature Software & Technology?

Book a 15-minute demo and we'll map your Software & Technology expertise to the content buyers are searching for.

Book a demo

Half of enterprises experienced a security incident directly tied to an unauthorized or misconfigured AI agent in the past six months. That figure, drawn from a DigiCert survey of 1,001 IT and cybersecurity leaders across the US, UK, and Australia, reported by The Deep View on July 7, puts a concrete number on a risk that many security teams have been tracking but few have fully governed.

In total, nearly eight in ten survey respondents said their organization encountered some form of AI-related security issue during the period. About 28% identified vulnerabilities without a confirmed incident, while the remaining 50% reported an actual breach or disruption. Science and technology firms logged the highest incident rates, followed by banking and financial services, telecommunications and media, and retail.

AI security exposure by outcome (past 6 months)
DigiCert / The Deep View, July 2026 · © MarketScaleDownload chart

Agents are moving faster than identity controls

Brian Trzupek, DigiCert's senior vice president of product, told The Deep View that AI agents present a fundamentally different identity problem from traditional endpoints. They operate autonomously at machine speed, yet most enterprises have not applied the same identity, authentication, and audit controls to them that they already require of human users, connected devices, and enterprise applications.

The exposure vectors Trzupek cited include prompt injection attacks, data poisoning, unauthorized access to sensitive systems, and an inability to trace which model produced a given output. That last point is operationally significant: nearly half of the 1,001 respondents reported limited or no visibility into how their AI systems arrive at decisions, making post-incident investigation significantly harder.

Deployment pace is widening the governance gap

The volume of AI systems being pushed into production is accelerating the problem. In the same six-month window, 75% of organizations deployed four or more AI-powered systems. More than a third, 35%, deployed over ten. Each additional model or agent integration extends the attack surface without necessarily adding a corresponding control layer.

AI governance readiness vs. deployment activity
DigiCert / The Deep View, July 2026 · © MarketScaleDownload chart

Governance discussions are widespread, with 90% of organizations reporting they have addressed AI governance at the leadership level. Acting on those discussions is another matter. Only half have dedicated budgets and formal programs in place, according to the DigiCert data. The gap between conversation and operational control is where most of the legal, regulatory, and reputational risk lives.

Revocation exists; proactive identity controls do not

One area where enterprises are ahead of the curve: 86% reported having at least some process, formal or informal, for revoking access to a compromised AI system. That reactive capability is meaningful, but it only applies after something has gone wrong. The harder operational problem is establishing controls at the point of deployment, so that each AI agent carries a verifiable identity, a defined access scope, and a logged audit trail before it ever touches production data.

Trzupek framed the accountability gap directly in his comments to The Deep View: without governance, organizations cannot answer the basic questions of what AI is running, what it can access, and who is responsible when it fails. Those are not abstract compliance concerns. They are the questions an incident response team, a regulator, or a general counsel will ask within hours of a breach.

What this means for your team

  • Audit your AI agent inventory now: identify every agent running in production and confirm whether it has an assigned identity, defined access permissions, and an audit log. If it does not, treat it as an unmanaged endpoint.
  • Close the governance budget gap: if your organization has discussed AI governance but has not funded a formal program, the DigiCert data makes the business case. A 50% incident rate is a number risk committees and boards will recognize.
  • Extend your IAM framework to cover non-human actors: apply the same authentication and least-privilege access standards you require of users and devices to every AI agent, including third-party and embedded models.
  • Build traceability into procurement requirements: before onboarding any new AI platform or agent-based tool, require vendors to demonstrate output traceability, so you can map a decision back to its source model and training data if an incident occurs.

Sources

Featured companies

Your experts belong here

Every story in MarketScale Software & Technology starts with a company putting its solutions engineers, product teams, and customer engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Buyers ask AI engines who to consider, and published expert answers are what those engines cite.

Get your team featuredSee how it works15 minutes, straight to a calendar.

About the author

MarketScale Newsroom
MarketScale NewsroomEditorial Team, MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

Follow Software & Technology Insights

Get new expert content in your inbox.

Software & Technology: are you visible to AI?

Before they reach out, Software & Technology buyers ask AI engines which vendors to trust. See how AI describes your company today, and where competitors show up instead.

Free workspace

You just read one Software & Technology expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your solutions engineers, product teams, and customer engineers into the articles, video, and social content Software & Technology buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale Studio workspace
One video edit a month, on us
AI writing, editing, and publishing tools
In-platform coaching to learn the system

More Software & Technology Insights

Anthropic’s mega-IPO prep is forcing enterprise buyers to treat AI vendors like long-term critical infrastructure

Anthropic’s mega-IPO prep is forcing enterprise buyers to treat AI vendors like long-term critical infrastructure

Anthropic is preparing for a large IPO, comparable to SpaceX's record-setting one. This move is causing enterprise buyers to consider AI vendors as long-term critical infrastructure. The company's revenue run rate and policies are influencing this shift in procurement strategy.

  • 01Anthropic is planning an IPO that could rival SpaceX's in size.
  • 02Enterprise buyers are starting to view AI vendors as essential long-term infrastructure.
  • 03Anthropic's current revenue run rate and policies are driving changes in procurement approaches.

Aug 22, 2026

Airwallex’s $320 million Series H pushes fintech buying teams to price “autonomous finance” into payables and treasury RFPs

Airwallex’s $320 million Series H pushes fintech buying teams to price “autonomous finance” into payables and treasury RFPs

Airwallex has secured $320 million in Series H funding to enhance its agentic bookkeeping and wallet checkout solutions. This investment will prompt finance and IT teams to rethink payment stacks for better control. The focus on 'autonomous finance' suggests a shift towards more integrated financial operations.

  • 01Airwallex raised $320 million in Series H funding.
  • 02Finance and IT teams are encouraged to integrate clearer controls in payment stacks.
  • 03The concept of 'autonomous finance' is driving changes in financial operations.

Aug 21, 2026

Financial services will outspend most U.S. industries in 2026, and H1 B2B tech buying shows where the contracts are moving

Financial services will outspend most U.S. industries in 2026, and H1 B2B tech buying shows where the contracts are moving

The U.S. financial services industry is projected to have a tech budget of $495 billion by 2026. Recent tracking of B2B purchases indicates an acceleration in technology adoption in areas such as security and AI foundations. The financial sector is expected to outspend most other U.S. industries on technology.

  • 01U.S. financial services tech budgets are forecasted to reach $495 billion in 2026.
  • 02B2B purchases in H1 show rapid cycles in security and AI foundations.
  • 03The financial sector is set to outspend most U.S. industries on technology by 2026.

Aug 20, 2026

Explore More Software & Technology Insights

Read more expert perspectives from across Software & Technology.

Browse Software & Technology Hub

About the Expert

MarketScale Newsroom
MarketScale Newsroom

Editorial Team

MarketScale

The MarketScale Newsroom reports on the companies, technologies, and trends shaping 16 B2B industries. It turns primary sources and expert commentary into clear, useful coverage for the people doing the work.

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Software & Technology and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512