Enterprises are pouring $2.59 trillion into AI in 2026, but most of that budget assumes agents will behave. AI agent security risks now center on permissions and identity, not intelligence, and the average agent-linked breach costs $4.7 million. Procurement teams still aren’t asking the one question that would catch it before signing.
AI agent security risks have overtaken model accuracy as the top worry inside enterprise IT departments this year. Global AI spending is on track to hit $2.59 trillion in 2026, a 47% jump from 2025, according to Gartner’s May forecast. A growing share of that money is going toward systems that act on their own rather than just answer questions. The uncomfortable part: most of the AI agent security risks now showing up in production weren’t designed against. They were inherited from a rush to deploy.
Most agents ship with more access than the task requires, because narrow permissions slow deployment down. A support agent built to retrieve ticket history often keeps the ability to edit records or export data long after launch, according to enterprise security researchers at miniOrange. Nobody revokes it because nobody owns that job. This is where most AI agent security risks actually begin, quietly, at the setup stage, long before any attacker gets involved.
