9/30/2026
Startup Signal · ai-startups
22 of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials
Filed by Nova Kicker
Hold onto your keyboards, folksâthis one's a wake-up call. A fresh VentureBeat survey just dropped a stat that should make every AI-forward enterprise sweat: 22 out of 37 companies that claim to enforce AI agent permissions are still letting their agents share credentials. That's nearly 60% of "compliant" shops running on a wing and a prayer. The kicker? Enforcing permissions isn't the problemâknowing which agent did what is. When credentials are shared, audit trails go blurry, and accountability goes out the window. If you're building or buying AI agent tooling right now, identity management isn't a nice-to-have; it's the moat. Read on for the full breakdown.
N
Nova Kicker
Magazine AI commentary
Let's talk about the elephant in the server room: 22 out of 37 surveyed companies that enforce AI agent permissions still have agents sharing credentials. That's not a rounding errorâthat's a systemic blind spot. The rush to deploy AI agents is moving faster than our ability to govern them, and this data proves it. Enterprises are slapping on permission frameworks like a band-aid, but underneath, the plumbing is still a chaotic mess of shared logins and inherited access.
The real problem here is auditability. If Agent A and Agent B both use the same credential, and a rogue action happens, who do you blame? The machine? The vendor? The intern who set up the integration? In a world where AI agents are increasingly making high-stakes decisionsâprocessing payments, modifying code, responding to customersâthe ability to trace an action to a specific agent isn't just good hygiene. It's a compliance requirement waiting to happen. Regulators are circling, boards are nervous, and this survey is a flashing red warning light.
This is also a massive market signal for founders. We're witnessing the birth of a whole new category: AI-native identity and access management, or what some are calling "agent IAM." The big legacy players are trying to bolt on AI features, but they're built for a human-centric world. Startups that can offer granular, agent-specific identity, real-time telemetry, and immutable audit trails are going to eat this market alive. If you can tell a Fortune 500 CFO exactly which agent touched what, when, and with which permissionsâyou win.
The deeper lesson? Every platform shift in tech history has spawned a new security layer. Mainframes brought antivirus. Cloud brought CASB and zero-trust. The AI agent era will bring agent governance and observability. Companies that treat AI agents as untrusted, monitored, and individually identifiable entities will thrive; those that treat them as magic black boxes with shared keys will get burned. This survey is the canary in the coal mine.
For more context, check out the original reporting at https://venturebeat.com/security/22-of-37-surveyed-companies-that-enforce-ai-agent-permissions-still-have-agents
đ Read the real article âvia VentureBeat · VentureBeat
