July 2026 · 7 min read · Research
92% of Security Pros Are Worried About AI Agents
Darktrace's 2026 Report Reveals the New Normal
AI agents are reshaping the enterprise security landscape, but most security teams are not ready for the change. Darktrace's March 2026 State of AI Cybersecurity report reveals an uncomfortable reality: 92% of security professionals are concerned about the impact of AI agents on enterprise security, and the majority of enterprises lack both the monitoring tools and the defensive mechanisms to address the threat.

Key Definitions
of Security Pros Are Worried About AI Agents AI agents are reshaping the enterprise security landscape, but most security teams are not ready for the change. Darktrace's March 2026 State of AI Cybersecurity report reveals an uncomfortable reality: 92% of security professionals are concerned about the impact of AI agents on enterprise security, and the majority of enterprises lack both the monitoring tools and the defensive mechanisms to address the threat.
92% Concerned, 80.9% Already Deployed: Security Lags Behind Speed
Darktrace's survey of over 900 global security executives and practitioners reveals a fundamental misalignment: enterprise enthusiasm for AI agent deployment is far outpacing security readiness. 80.9% of technical teams have already moved past planning into active testing or full deployment of AI agents. Yet among those organizations, more than half of all AI agents operate without any runtime security monitoring or logging.
This means a large number of AI agents are running "invisibly" inside enterprise networks — accessing data, calling APIs, executing actions — while security teams remain completely unaware. When an agent is compromised or begins exhibiting anomalous behavior, there are no logs to trace what happened.
The direct consequence of this monitoring gap: a separate Gravitee survey found that only 24.4% of organizations have full visibility into agent-to-agent communication. In environments where AI agents can autonomously invoke other agents, monitoring blind spots compound rapidly — a compromised agent can silently call other agents to execute malicious actions, and the entire sequence unfolds outside the security team's field of view.
Ransomware Up 48% YoY: Agents Are Reshaping the Attack Surface
Darktrace's report also provides quantitative evidence of ransomware evolution. In May 2026, 698 ransomware attacks were reported globally, a 48% increase compared to 472 in May 2025. This is not an isolated spike — it reflects the systematic expansion of the attack surface in the age of AI agents.
As major ransomware groups (such as LockBit) are disrupted by international law enforcement actions, the ransomware ecosystem is shifting from a small number of dominant actors to a more distributed landscape of smaller groups. The proliferation of AI agents accelerates this trend: attackers can now use agents to automate reconnaissance, vulnerability scanning, and social engineering attacks with lower costs and higher efficiency.
For enterprise security teams, this means traditional defense strategies — focused on known large threat actors — are no longer sufficient. AI agents have democratized attack capability, enabling small threat groups to launch attacks at the same scale as major organizations.
The Visibility Gap: You Can't Secure What You Can't See
The core finding of Darktrace's report can be summarized in one word: visibility. The biggest problem facing enterprise AI agent security today is not insufficient defense technology — it is the inability to see what agents are doing.
More than half of agents operate without monitoring, meaning enterprises have virtually no awareness of their actual AI agent ecosystem — how many agents are running, what data they access, which systems they interact with, whether they communicate with other agents. In this state, any security defense is blind.
"You can't secure what you can't see" — this is the first principle of enterprise AI agent security. Before deploying any security controls, enterprises must first achieve comprehensive visibility into their AI agent ecosystem: agent discovery, behavioral baselining, communication topology mapping, and real-time behavioral monitoring.
What Security Teams Need to Do Now
Facing the security challenges posed by AI agents, enterprise security teams need to take three immediate actions:
First, establish agent discovery. Understand how many agents are running in the enterprise, where they operate, and who deployed them. Shadow agent discovery is the first line of defense.
Second, enforce mandatory monitoring. All agents must have complete logging and behavioral monitoring. No agent should be allowed to run without being recorded.
Third, build agent-to-agent communication visibility. The agent call chain must be traceable so that when an attack occurs, security teams can quickly identify the propagation path and affected scope.
92% of security professionals are concerned about the impact of AI agents — that number speaks for itself. The concern is justified, but staying at the concern stage is not enough. Gaining visibility is the prerequisite for solving every AI agent security problem.
References
- Darktrace: "State of AI Cybersecurity 2026: 92% of Security Professionals Concerned About AI Agents"
- miniOrange: "AI Agent Security Risks: What Enterprises Need to Know in 2026"
- AGAT Software: "AI Agent Security in 2026: What Enterprises Are Getting Wrong"
FAQ
92% Concerned, 80.9% Already Deployed: Security Lags Behind Speed+
Darktrace's survey of over 900 global security executives and practitioners reveals a fundamental misalignment: enterprise enthusiasm for AI agent deployment is far outpacing security readiness. 80.9% of technical teams have already moved past planning into active testing or full deployment of AI agents. Yet among those organizations, more than half of all AI agents operate without any runtime security monitoring or logging.
Ransomware Up 48% YoY: Agents Are Reshaping the Attack Surface+
Darktrace's report also provides quantitative evidence of ransomware evolution. In May 2026, 698 ransomware attacks were reported globally, a 48% increase compared to 472 in May 2025. This is not an isolated spike — it reflects the systematic expansion of the attack surface in the age of AI agents.
The Visibility Gap: You Can't Secure What You Can't See+
The core finding of Darktrace's report can be summarized in one word: visibility. The biggest problem facing enterprise AI agent security today is not insufficient defense technology — it is the inability to see what agents are doing.
What Security Teams Need to Do Now+
Facing the security challenges posed by AI agents, enterprise security teams need to take three immediate actions:
Related Articles
IBM: 97% of AI Incidents Cause Data Breaches
IBM Cost of a Data Breach 2026: 97% of AI security incidents lead to data breaches, shadow AI doubled year-over-year, average cost reaches $6 million.
AI Agent NHI Crisis: Machine Identities Outpace Human IAM
Every AI agent creates a non-human identity. NHIs outpace human identities. MCP auth gaps, CVE-2026-32211 (CVSS 9.1), and ClawHavoc reveal IAM failures.
88% of Firms Hit by AI Agent Security Incidents
Gravitee: 88% of orgs hit by AI agent incidents. Over 50% of agents run with zero oversight. NIST CAISI targets prompt injection and accountability gaps.
JADEPUFFER Ransomware and Sol Database Deletion
In July 2026, three independent security incidents form a crisis of trust: JADEPUFFER, the first fully autonomous AI ransomware; GPT-5.6 Sol autonomously.