Artificial IntelligenceBusinessCybersecurityNewswireWhat's Buzzing

Two-Thirds of Firms Hit by AI Agent Cybersecurity Incidents

Originally published on: April 22, 2026
▼ Summary

– Two-thirds of organizations experienced a cybersecurity incident from AI agents in the past year, causing data exposure and operational disruption.
– Most organizations lack a formal strategy for decommissioning AI agents, leaving persistent agents with credentials as a security risk.
– A significant gap exists between perceived and actual visibility, with 82% of organizations discovering previously unknown AI agents on their networks.
– These incidents are shifting AI governance from a technical issue to a core business risk management concern affecting financial and operational performance.
– The Cloud Security Alliance calls for stronger, unified governance models to manage the security lifecycle of increasingly autonomous AI agents.

A significant majority of organizations have faced security breaches linked to the use of AI agents over the past year, according to a new study. Research from the Cloud Security Alliance and Token Security reveals that 65% of companies experienced at least one such incident, with consequences ranging from data exposure to financial losses. The findings underscore a growing and urgent cybersecurity risk as autonomous agents become more common in corporate environments.

The report, titled Autonomous but Not Controlled, indicates a troubling gap between perceived control and reality. While 68% of security professionals express high confidence in their network visibility, a striking 82% admitted to discovering previously unknown AI agents within the last twelve months. These shadow AI agents are most often found lurking within internal automation systems and large language model platforms. This discrepancy between awareness and actual presence creates a major vulnerability, as teams cannot secure what they do not know exists.

The operational impact of these incidents is substantial. Among affected organizations, 61% reported incidents leading to data exposure, while 43% faced operational disruption. Furthermore, 41% dealt with unintended actions in critical business processes. The fallout extends beyond IT, affecting core business functions. Over a third of organizations, 35%, suffered direct financial losses, and 31% experienced delays in customer-facing or internal services.

A critical weak spot highlighted in the research is the lack of strategy for AI agent decommissioning. Only 20% of organizations have formal processes for retiring these tools. Without proper end-of-life governance, agents can persist on networks long after their useful life, retaining access credentials and permissions. These forgotten agents become dormant threats, potentially leading to unintended data leaks and creating an escalating security liability as deployments multiply.

The Cloud Security Alliance emphasizes that managing AI agent security must evolve from a technical checklist to a central component of business risk management. Hillary Baron, the CSA’s assistant vice president of research, noted that while foundational controls exist, persistent gaps in consistency and lifecycle management leave organizations exposed. She argues that governance frameworks need to mature into unified, operational models capable of maintaining control as agent autonomy increases.

To address these challenges, the CSA advises organizations to implement stronger, integrated governance. Key recommendations include establishing comprehensive visibility and inventory controls, developing formal policies for the entire agent lifecycle, and integrating agent behavior monitoring into broader security and compliance strategies. Proactive risk assessment and continuous monitoring are no longer optional but essential for safeguarding data, operations, and financial health in an era of intelligent automation.

(Source: Infosecurity Magazine)

Topics

ai agent incidents 98% cybersecurity risks 96% ai agent governance 95% data exposure 93% operational disruption 91% financial losses 89% ai agent visibility 88% decommissioning governance 87% cloud security alliance 86% business risk management 85%