Enterprise AI agent counts doubled in 4 months, security lags
Gravitee's *State of AI Agent Security 2026* report, published April 2026 and highlighted by TechCrunch, found that enterprise AI agent counts roughly doubled in four months, while security and monitoring infrastructure lagged significantly behind deployment velocity.
The report surveyed 750 executives and technical leaders in April 2026 and compared their responses to a December 2025 baseline. The median enterprise deployment moved from 26–50 agents to 76–100 agents in that span, representing a de facto doubling of agent footprint across the surveyed population. Another breakdown cited in secondary coverage pegged the modal shift as moving from approximately 37 agents to 76–100 agents.
Monitoring Coverage Fails to Keep Pace
While agent counts surged, monitoring and observability infrastructure improved only marginally. Mean monitoring coverage rose from 46.96% in December 2025 to approximately 52% in April 2026—a gain of just 5 percentage points TechCrunch. Only 9.5% of organizations reported securing more than 80% of their deployed agents, indicating that the vast majority lack comprehensive visibility or control over agent behavior in production.
Incident Rates High Across Financial and Telecom Sectors
A majority of surveyed organizations reported experiencing or suspecting an AI agent security or data privacy incident within the past 12 months. Overall, 54% of respondents indicated confirmed or suspected incidents. The problem was especially acute in specific sectors: telecoms reported a 67.3% incident rate, while financial services reported 54.7% TechCrunch.
Why the Gap Matters for the Agent Economy
The data reflects a structural challenge in the emerging agent economy: organizations are deploying agents faster than they can implement governance, monitoring, or incident response frameworks. The gap between deployment velocity and control creates operational risk—agents acting autonomously in customer-facing, transaction-processing, or data-handling environments with minimal oversight.
Graveee's report does not isolate the nature of reported incidents (data leaks, fraud, unauthorized actions, etc.), nor does it name specific organizations or quantify financial impact. The survey captures prevalence of concern rather than forensic detail.
The findings align with broader industry discourse about agent sprawl and governance debt in enterprise AI adoption, but they remain bound to Gravitee's April 2026 dataset and do not yet account for interventions, policy changes, or tool adoption that may have occurred since.