O
OOMeta
← Back to Insights

July 2026 · 7 min read · Research

92% of Security Pros Are Worried About AI Agents
Darktrace's 2026 Report Reveals the New Normal

AI agents are reshaping the enterprise security landscape, but most security teams are not ready for the change. Darktrace's March 2026 State of AI Cybersecurity report reveals an uncomfortable reality: 92% of security professionals are concerned about the impact of AI agents on enterprise security, and the majority of enterprises lack both the monitoring tools and the defensive mechanisms to address the threat.

92% security professionals concerned about AI agents impact, dark tech background

Key Definitions

of Security Pros Are Worried About AI Agents AI agents are reshaping the enterprise security landscape, but most security teams are not ready for the change. Darktrace's March 2026 State of AI Cybersecurity report reveals an uncomfortable reality: 92% of security professionals are concerned about the impact of AI agents on enterprise security, and the majority of enterprises lack both the monitoring tools and the defensive mechanisms to address the threat.

92% Concerned, 80.9% Already Deployed: Security Lags Behind Speed

Darktrace's survey of over 900 global security executives and practitioners reveals a fundamental misalignment: enterprise enthusiasm for AI agent deployment is far outpacing security readiness. 80.9% of technical teams have already moved past planning into active testing or full deployment of AI agents. Yet among those organizations, more than half of all AI agents operate without any runtime security monitoring or logging.

This means a large number of AI agents are running "invisibly" inside enterprise networks — accessing data, calling APIs, executing actions — while security teams remain completely unaware. When an agent is compromised or begins exhibiting anomalous behavior, there are no logs to trace what happened.

The direct consequence of this monitoring gap: a separate Gravitee survey found that only 24.4% of organizations have full visibility into agent-to-agent communication. In environments where AI agents can autonomously invoke other agents, monitoring blind spots compound rapidly — a compromised agent can silently call other agents to execute malicious actions, and the entire sequence unfolds outside the security team's field of view.

Ransomware Up 48% YoY: Agents Are Reshaping the Attack Surface

Darktrace's report also provides quantitative evidence of ransomware evolution. In May 2026, 698 ransomware attacks were reported globally, a 48% increase compared to 472 in May 2025. This is not an isolated spike — it reflects the systematic expansion of the attack surface in the age of AI agents.

As major ransomware groups (such as LockBit) are disrupted by international law enforcement actions, the ransomware ecosystem is shifting from a small number of dominant actors to a more distributed landscape of smaller groups. The proliferation of AI agents accelerates this trend: attackers can now use agents to automate reconnaissance, vulnerability scanning, and social engineering attacks with lower costs and higher efficiency.

For enterprise security teams, this means traditional defense strategies — focused on known large threat actors — are no longer sufficient. AI agents have democratized attack capability, enabling small threat groups to launch attacks at the same scale as major organizations.

The Visibility Gap: You Can't Secure What You Can't See

The core finding of Darktrace's report can be summarized in one word: visibility. The biggest problem facing enterprise AI agent security today is not insufficient defense technology — it is the inability to see what agents are doing.

More than half of agents operate without monitoring, meaning enterprises have virtually no awareness of their actual AI agent ecosystem — how many agents are running, what data they access, which systems they interact with, whether they communicate with other agents. In this state, any security defense is blind.

"You can't secure what you can't see" — this is the first principle of enterprise AI agent security. Before deploying any security controls, enterprises must first achieve comprehensive visibility into their AI agent ecosystem: agent discovery, behavioral baselining, communication topology mapping, and real-time behavioral monitoring.

What Security Teams Need to Do Now

Facing the security challenges posed by AI agents, enterprise security teams need to take three immediate actions:

First, establish agent discovery. Understand how many agents are running in the enterprise, where they operate, and who deployed them. Shadow agent discovery is the first line of defense.

Second, enforce mandatory monitoring. All agents must have complete logging and behavioral monitoring. No agent should be allowed to run without being recorded.

Third, build agent-to-agent communication visibility. The agent call chain must be traceable so that when an attack occurs, security teams can quickly identify the propagation path and affected scope.

92% of security professionals are concerned about the impact of AI agents — that number speaks for itself. The concern is justified, but staying at the concern stage is not enough. Gaining visibility is the prerequisite for solving every AI agent security problem.

References

FAQ

92% Concerned, 80.9% Already Deployed: Security Lags Behind Speed+

Darktrace's survey of over 900 global security executives and practitioners reveals a fundamental misalignment: enterprise enthusiasm for AI agent deployment is far outpacing security readiness. 80.9% of technical teams have already moved past planning into active testing or full deployment of AI agents. Yet among those organizations, more than half of all AI agents operate without any runtime security monitoring or logging.

Ransomware Up 48% YoY: Agents Are Reshaping the Attack Surface+

Darktrace's report also provides quantitative evidence of ransomware evolution. In May 2026, 698 ransomware attacks were reported globally, a 48% increase compared to 472 in May 2025. This is not an isolated spike — it reflects the systematic expansion of the attack surface in the age of AI agents.

The Visibility Gap: You Can't Secure What You Can't See+

The core finding of Darktrace's report can be summarized in one word: visibility. The biggest problem facing enterprise AI agent security today is not insufficient defense technology — it is the inability to see what agents are doing.

What Security Teams Need to Do Now+

Facing the security challenges posed by AI agents, enterprise security teams need to take three immediate actions: