
VTechFusion Team
VTechFusion Technologies
A VentureBeat Research study spanning five surveys of 573 enterprise leaders finds that companies have deployed AI agents faster than they've built the controls to manage them. Twenty-one percent of enterprises still cannot stop a runaway agent's spending in real time despite running multiple AI orchestration platforms; 27% exercise only reactive control, learning what an agent cost when the invoice arrives rather than enforcing a budget ceiling as it runs. Separately, 54% of companies report an agent security incident or a caught-in-time near-miss in the past 12 months, and only about a third give every agent its own scoped identity — most agents still share credentials.
The Gap Between Deployment Speed and Control Maturity
This research crystallizes a pattern that's been building across every enterprise AI governance survey this year: organizations are treating agent rollout as a capability question (can it do the task?) faster than they're treating it as a control question (can we stop it, audit it, or bound its cost if it misbehaves?). That ordering is understandable — agent capability demos are what get budget approved — but it produces exactly the gap this research quantifies. An agent that can autonomously call external APIs, provision cloud resources, or place orders is also an agent that can autonomously run up costs or take actions nobody intended, and "we'll add guardrails later" is a materially riskier sequencing than it sounds when the agent is already in production.
Where the Security Stack Is Actually Falling Short
- Most agent security tooling is borrowed from model providers and hyperscalers rather than purpose-built for the agent-specific failure modes (credential sharing, unscoped permissions, cascading tool-call loops)
- Only about three in ten enterprises isolate their highest-risk agents from the rest of the environment, meaning a single compromised or misbehaving agent can potentially reach far more than its intended task scope
- Security spend on agents remains a thin slice of the overall security budget relative to how much operational authority agents have already been granted
Real-Time Spend Control Is a Specific, Solvable Problem
Unlike some AI governance challenges that require genuinely novel tooling, real-time agent spend control is architecturally closer to a solved problem borrowed from adjacent domains: cloud cost management already has mature patterns for per-resource budget ceilings, anomaly alerting, and automatic throttling when a spend rate crosses a threshold. The gap isn't that the pattern doesn't exist — it's that most agent orchestration platforms weren't built with a metering layer as a first-class concern, and retrofitting one after agents are already live in production is a harder, more disruptive project than building it in from day one of a new agent deployment.
A Practical Starting Checklist
- Every production agent should have its own scoped identity and credentials — never a shared service account — so a single compromised agent's blast radius is contained and its actions are individually auditable
- Set a hard per-agent spend ceiling enforced at the orchestration layer, not just monitored after the fact in a billing dashboard, with automatic suspension (not just an alert) when the ceiling is reached
- Isolate your highest-risk agents — the ones with the broadest tool access or the ability to take real-world actions like placing orders or modifying records — from lower-risk agents, so a failure in one doesn't cascade
- Treat agent security budget as a distinct line item, not an assumed subset of existing AI infrastructure spend, since the research shows it's currently underfunded relative to the operational authority agents hold
Frequently Asked Questions
What percentage of enterprises can't control AI agent spending in real time?
21% cannot stop a runaway agent's spending in real time despite running multiple AI orchestration platforms, and a further 27% only learn an agent's cost reactively, after the invoice arrives, per VentureBeat Research's survey of 573 enterprise leaders.
How common are AI agent security incidents?
54% of surveyed companies report an agent security incident or a near-miss caught before harm within the past 12 months — more than half, despite agent deployment still being relatively early-stage at most organizations.
What's the single highest-priority fix for agent spend governance?
Enforcing a hard per-agent spend ceiling at the orchestration layer with automatic suspension, rather than monitoring spend after the fact in a billing dashboard — the difference between reactive and real-time control is exactly what this research identifies as the gap.
Media & Press Enquiries
For editorial enquiries, expert commentary, or case study access.
Ready to Build Something Great?
Let's turn your idea into a product. Book a free 30-minute discovery call with our team — no commitment, just clarity.
