UpTrajectory Review
The gap between enterprise AI ambition and security readiness has become a chasm, according to new VentureBeat Pulse Research, and small and mid-sized businesses are being left to stare into it from the wrong side. The data shows that while 53% of enterprises have already suffered an agentic security incident or near-miss, only 8% have implemented both permission enforcement and isolation for their highest-risk AI agents. The rest are operating in a dangerous middle ground—deploying autonomous systems that can act across networks and data stores without the architectural guardrails that would contain them when they go wrong.
For small-business operators, this is not a distant enterprise problem. The same AI platforms and cloud providers that enterprises use are the ones being marketed aggressively to smaller firms with fewer resources to evaluate them. When 92% of enterprises default to their hyperscalers' native security controls, they are effectively outsourcing their judgment to vendors whose incentives run toward feature velocity, not containment. A small business with no dedicated security staff is even more likely to accept these defaults uncritically. The research's finding that breached enterprises rate their tools more highly than unbreached ones suggests a market where satisfaction surveys function as coping mechanisms, not quality signals.
What deserves real scrutiny here is the psychological pattern buried in the data: companies that experienced incidents gave their security tools higher satisfaction scores (4.39/5) than those with clean records (4.13/5). This is not rational evaluation. It is the sunk-cost fallacy in institutional form—organizations justifying investments already made, or perhaps mistaking the visibility of a breach for proof that their tools 'worked' by detecting it. The research correctly identifies this as a market immaturity signal, but it also hints at something more troubling: in the absence of better alternatives, buyers are learning to grade on a curve that rewards familiarity over efficacy.
The Visa example that opens the piece is doing more work than it appears. Taneja's demonstration of Anthropic's Mythos finding exploit chains in Visa's own payment network, then open-sourcing the containment harness, represents a level of engineering depth and cultural maturity that is not replicable for most firms. The research's six waves since January, covering 440 respondents, consistently show this containment gap widening. This suggests that agentic AI deployment is accelerating faster than security architecture can adapt—a classic innovation-versus-control dynamic, but with autonomous systems that can act at machine speed rather than human speed.
The downstream effects will hit smaller players asymmetrically. Enterprises with incident response teams and vendor leverage can absorb breaches and negotiate remediation. A small business facing a rogue agent that exfiltrates customer data, modifies financial records, or makes unauthorized transactions may not survive the event or its regulatory aftermath. The concentration of 92% of enterprises in hyperscaler-native controls also creates systemic risk: a vulnerability in one provider's agent governance layer becomes a monoculture failure point.
What to watch: whether any provider actually closes the enforcement-isolation gap at scale, or whether the market fragments into expensive boutique solutions that exclude smaller buyers. What to do now: before deploying any agentic tool, map specifically what it is permitted to touch, what would trigger its suspension, and who has authority to pull that trigger—then test that suspension under load, not in documentation. The 8% who pair enforcement with isolation are not being paranoid. They are being proportionate.
Takeaway: Map what your AI agents can touch, define suspension triggers, and test under load before deployment—defaults are not defenses.
Excerpt from the original — VentureBeat
Visa's president of technology, Rajat Taneja, walked the VB Transform 2026 audience through aiming Anthropic's Mythos at Visa's own payment network. The model stitched minor weaknesses into working exploit chains, and Visa open-sourced the harness that governed the hunt.That's what it looks like when an enterprise has the engineering depth to act on what it finds. Most don't get there. Just over half, or 53%, of enterprises have already had an agentic security incident or near-miss. Sixty-five percent enforce agent permissions at runtime, yet only 18% isolate their highest-risk agents, and just 8% pair enforcement with isolation.Leaning on provider-native controls to do the heavy lifting of agentic security just exacerbates that gap. The July wave of VentureBeat Pulse Research found that 92% of enterprises naming a primary security layer default to their …