Desk live·
ForensicPost
AI/AI agents/File 26-0523

Eighty-eight per Cent of Enterprises Running Agents Had an Incident

Among organisations that have deployed AI agents, 88% report at least one security incident tied to them, at an average cost reported near $4.7 million. Deployment has outrun the controls by roughly a year.

Constructed geometry · not a chart of case data
TargetEnterprise AI agent deployments
ActorMultiple
S. Rosler11 min readConfidence: medium2 sources reviewed

Among enterprises that have deployed AI agents, 88% report at least one security incident connected to them, with average agent-related breach costs reported around $4.7 million.

These are survey and vendor figures and we treat them as directional. A rate that high nonetheless says something specific: incidents are not an unlucky outcome for badly run programmes, they are the normal outcome of deploying the technology as currently packaged.

The Pattern Is Familiar, And Previously Survivable

Every significant platform shift has run ahead of its controls. Web applications, mobile, and cloud each produced a period where capability was widely deployed and the security model was still being worked out.

Two things are different here. The gap is compressing — enterprise agent deployment has moved faster than cloud adoption did — and the failure mode is not a misconfiguration sitting still. An agent takes actions.

What "Incident" Is Doing In That Statistic

A category that spans a chatbot disclosing an internal price, an agent deleting data, and an agent used as a route into a connected system is broad enough to be doing real work in the number.

We would rather see it decomposed, and until it is, the honest reading is that most organisations deploying agents have encountered something they classified as a security problem — not that most have suffered a $4.7 million breach.

The Governance Question Nobody Has Answered

An agent is not a user and not quite a service account. It acts with delegated authority, at machine speed, on interpretation. Existing frameworks have no category for it, which means access reviews, joiners-movers-leavers processes and privilege audits mostly do not see them.

The practical first step is unglamorous and rarely done: enumerate the agents already operating in the organisation and what each is permitted to do. Most security teams cannot currently produce that list.

How we reported this

This is an analysis file built on published survey and vendor research, listed below. Figures are self-reported by respondents with varying definitions of "incident". Corrections: corrections@forensicpost.com.

Sources
  1. Agentic AI security: $4.7M breaches, 92% alarmedShattered
  2. Prompt injection still drives most agentic AI security failures in productionHelp Net Security
S. Rosler
Covers extortion groups and leak-site economics. Verifies our sample sets.
// the chain of custody — tuesdays

Get the next file first.

One incident a week, taken apart properly. Logs, timelines, and what the filing left out.

PGP-signed edition · no tracking pixels · one-click unsubscribe
© 2026 ForensicPost Media · the desk · newsletter · searchGlossary