Qualis Lab
Qualis Lab
ARTICLE · AI
#ai#security#governance

54% have already had a security incident with AI agents

More than half of companies already had an incident or near-miss with agents in production. Even so, most still let them share credentials.

Qualis Team
Editorial team
1 min read

The number

A survey of 107 organizations with more than 100 employees reveals that more than half already had a confirmed incident or a detected risk with AI agents in production: 18% with real damage and 36% with a critical situation caught in time.

Despite that, most still let agents share credentials with each other, and only 32% give each agent its own identity with scoped permissions. The gap between adoption pace and real protection widens week by week.

Why it matters

For any organization deploying AI automation, the message is blunt: adoption speed must come with governance from the start.

When an agent has access to critical systems, sensitive data, and key business processes, the absence of controls isn't a technical risk — it's an operational, reputational, and regulatory risk that business leaders can't delegate to IT alone.

The Qualis view

An agent with access to production is, in practice, just another user — and should be treated as one: its own identity, least privilege, and traceability of what it does. The "let them share a credential to make it easier" pattern is exactly what turns a small incident into a serious one. Testing agents the way you test any release —focused on permissions, limits, and behavior around sensitive data— is part of quality assurance, not an optional extra.

Ready to start?

Want to bring this to your team?