Home/ Incident database/stat-neuraltrust-2026
Financial loss Prompt injection verified aggregate statistic

NeuralTrust: 34.9% of enterprises report confirmed AI agent security incidents

NeuralTrust · Jun 1, 2026 · General agent

What happened

A global survey of 160+ CISOs found that 34.9% of organizations had experienced confirmed AI-agent security incidents, 73% of CISOs were 'very/critically concerned' about agent risks, yet only 30% reported mature security readiness. Telecoms (67.3%) and Financial Services (54.7%) led in incidents.

Loss / impact
Jun 1
2026
Prompt
Failure mode
General
Agent type

Causal vector

Aggregate finding across enterprise AI agent deployments

Source

Reported by NeuralTrust - State of AI Agent Security 2026. Verified against the primary report.

Read the original report ↗

How a spend firewall would have helped

An external spend + action firewall is the single highest-leverage control in the 'readiness' gap: it converts an unbounded agent into a policy-bound one without requiring model-side changes.

The six rule types that contain this class of failure

Per-transaction cap

Any single spend above your ceiling is BLOCKED before it moves.

Daily total

Cumulative spend across all agent calls, bounded per day.

Velocity limit

Stops runaway retry loops — the #1 cause of overnight losses.

Merchant allowlist

Only approved destinations can ever receive funds.

Category rules

Flag high-risk classes (crypto, infra, refunds) for review.

Approval threshold

Above a value, the action waits for a human.

Related incidents

Darktrace/CSA: 92% of security pros concerned about AI agent impact

Darktrace / Cloud Security Alliance · Jan 1, 2026

Don't be the next entry

Every incident in this database is the result of trusting a prompt, a provider cap, or a human review cycle. sipi.bot replaces all three with one deterministic call. 27 documented failures, one control.