Enterprise AI Agents Surge Amid Growing Security Blind Spots

AI agents inside companies have doubled in just four months. This fast growth shows how much businesses rely on AI today. Yet, most organizations still struggle to watch and control these agents.
On average, each environment hosts about 1.17 AI agents. But some have many more. One company had 96 AI agents running at the same time. The most common range of deployed agents jumped from 26-50 to 76-100 in just one quarter.
Despite this growth, security teams barely improved monitoring. Confidence in seeing AI agents rose from 82.6% to 91.8% over a few months. Still, only 9.5% of companies secure more than 80% of their AI agents. Over half—54%—have faced or suspect a security or privacy incident linked to AI agents in the past year.
Accountability remains a big issue. Only 7.2% of companies can name a person responsible when an AI agent misbehaves. A huge 85% have no formal system to manage AI agent conduct. Few organizations—just 19.7%—say all their AI agents are fully secured and governed before launch.
Security Gaps in AI and Cloud Environments
Security teams are discovering serious vulnerabilities outside their planned tests. Around 95% found high or critical flaws in the last year. Nearly half of companies (42%) find new weaknesses every month or more. Many report that at least a quarter of their critical attack surfaces went untested in the past 90 days.
Only 15% of organizations run continuous security testing. The rest rely on point-in-time checks that can’t keep up. One security leader put it plainly: new code changes run in production for days or weeks before anyone validates them. This lag creates blind spots attackers can exploit.
The cloud adds complexity. Many environments expose risks like expired certificates and outdated protocols. For example, 91% of environments had expired certificates, and 96 deprecated TLS clients were observed. Other common issues include plaintext passwords (85%) and NetBIOS exposure (86%). These gaps multiply attack chances.
AI Expansion Outpaces Regulation and Preparedness
Most organizations plan to add even more AI agents soon. Over 80% expect to deploy many more in the next year. Yet, confidence in managing these agents as distinct, authenticated actors is low. Only 60% feel somewhat prepared, and 8% say they are not prepared at all.
Regulation is lagging behind too. Less than 40% believe current rules cover AI agent risks well. Almost half say regulations only cover some risks. This patchy oversight adds to the challenge of keeping AI safe and accountable.
Industry voices highlight the need to evolve security. One expert said, “AI is fundamentally changing enterprise environments, and exposure management must evolve alongside it.” Another noted that automation can raise many alerts, but teams need clear evidence, not noise.
Continuous security validation is key. As one cybersecurity leader said, point-in-time testing fails because environments change faster than tests can catch up. The market shows a clear trend: AI expands coverage, humans prove exploitability, and security validation must run nonstop.
Looking Ahead: Closing the Remediation Gap
A new report called “Closing the Cloud Remediation Gap” will explore how organizations can better turn AI and cloud detections into safe fixes. The report will drop at the RSAC 2027 Conference in San Francisco. It aims to help companies keep pace with AI-driven cloud changes.
Cloud security platform Tamnoon offers tools for this challenge. Its AI engine, Tami, works across multiple cloud systems to guide remediation based on millions of real fixes. This kind of automation could help close the gap between spotting issues and fixing them fast.
As AI agents become central to enterprise systems, companies must improve their oversight and security. Otherwise, the rapid AI surge will deepen blind spots and risks. Growing AI use means growing responsibility to keep systems safe and accountable.
Based on
- Vectra AI Research Reveals New Attack Exposure Reality — ai-techpark.com
- Synack Research Finds 95% of Enterprise Security Teams Discover High or Critical Vulnerabilities Outside Scheduled Tests | Markets Insider — markets.businessinsider.com
- Tamnoon Announces “Closing the Cloud Remediation Gap,” Featuring Perspectives From 50 Security Leaders | Markets Insider — markets.businessinsider.com
- AI agents just doubled inside the enterprise. Confidence rose faster than control did | TechCrunch — techcrunch.com
- SandboxAQ CEO weighs in on security incidents involving OpenAI and Hugging Face — cnbc.com



