NeuralTrust: 34.9% of enterprises report confirmed AI agent security incidents
NeuralTrust · Jun 1, 2026 · General agent
What happened
A global survey of 160+ CISOs found that 34.9% of organizations had experienced confirmed AI-agent security incidents, 73% of CISOs were 'very/critically concerned' about agent risks, yet only 30% reported mature security readiness. Telecoms (67.3%) and Financial Services (54.7%) led in incidents.
Causal vector
Aggregate finding across enterprise AI agent deployments
Source
Reported by NeuralTrust - State of AI Agent Security 2026. Verified against the primary report.
An external spend + action firewall is the single highest-leverage control in the 'readiness' gap: it converts an unbounded agent into a policy-bound one without requiring model-side changes.
The six rule types that contain this class of failure
Per-transaction cap
Any single spend above your ceiling is BLOCKED before it moves.
Daily total
Cumulative spend across all agent calls, bounded per day.
Velocity limit
Stops runaway retry loops — the #1 cause of overnight losses.
Merchant allowlist
Only approved destinations can ever receive funds.
Category rules
Flag high-risk classes (crypto, infra, refunds) for review.
Approval threshold
Above a value, the action waits for a human.
Related incidents
HUMAN Security: AI agent traffic grew 7,851%, 8x faster than human traffic
HUMAN Security · Jan 1, 2026
AvePoint: 88.4% of organizations hit by at least one AI agent security breach in 12 months
AvePoint · Jan 1, 2026
Darktrace/CSA: 92% of security pros concerned about AI agent impact
Darktrace / Cloud Security Alliance · Jan 1, 2026
Don't be the next entry
Every incident in this database is the result of trusting a prompt, a provider cap, or a human review cycle. sipi.bot replaces all three with one deterministic call. 27 documented failures, one control.