Many organisations that restrict what AI agents can do still let multiple agents use the same credentials, a VentureBeat survey finds. The gap matters: permission limits can curb access, but shared keys make it harder to identify which agent acted or revoke one without disrupting others.
Watch Desk analysis
What happened
VentureBeat reports that 22 of 37 surveyed organisations enforcing scoped permissions at runtime, while also running agents in production, said some or most of those agents still shared credentials. Only 15 said every agent had its own scoped, managed identity.
Across 68 respondents with agents in production, 42 said some or most agents shared credentials. The August survey had 137 respondents at organisations with at least 100 employees; VentureBeat says the sample was self-selected and should not be treated as representative of all enterprises. Read VentureBeat’s report.
Why it matters
A shared service account or API key can leave a team knowing what a credential was allowed to do without knowing which agent used it. That complicates audits, incident response and the basic task of shutting down one misbehaving agent without taking others offline.
The survey also points to a separate containment gap: only 12 of 137 respondents said high-risk agents ran in isolation with a bounded blast radius. VentureBeat reports that 64 of 109 organisations with agents in production or a pilot had experienced an agent-caused security incident or near-miss in the previous 12 months. The survey does not establish that limited isolation caused those incidents.
Our read
Agent permissions and agent identity are related, but they are not the same control. The figures make a useful case for asking both what an agent may access and whether its actions can be traced and revoked individually. These are survey responses, not a census of enterprise practice, but the distinction is worth carrying into any deployment review.
What to watch
- Whether organisations move from shared keys to individually managed agent identities.
- Whether high-risk agents are isolated with clear limits on what they can affect.
- How future survey waves compare, given that each wave uses a separate self-selected sample.
Discussion spark: If an agent has tightly scoped permissions, is sharing credentials an acceptable trade-off, or should every production agent have its own identity for accountability and revocation?
Sources and evidence
- AI agent permissions still use shared keys – VentureBeat (30 September 2026, 20:27 UTC)
Watch Desk is operated by WittyWires as an independent cross-cutting AI news tracker. It does not speak for the organisations or people it covers.