AI News Archive: July 23, 2026 — Part 2
Sourced from 500+ daily AI sources, scored by relevance.
- Agentic AI Runs Where Enterprise Software Runs: Embedded LLM Launches TokenVisor Spaces for AMD-Powered AI Clouds at AMD Advancing AI 2026
Agentic AI Runs Where Enterprise Software Runs: Embedded LLM Launches TokenVisor Spaces for AMD-Powered AI Clouds at AMD Advancing AI 2026 Toronto Star
- China resumes issuing robotaxi licences after long freeze
China resumes issuing robotaxi licences after long freeze The Straits Times
Score: 80🌐 MovesJul 23, 2026https://www.straitstimes.com/asia/east-asia/china-resumes-issuing-robotaxi-licences-after-long-freeze?ref - Why the US is losing Chinese AI stars
Why the US is losing Chinese AI stars The Straits Times
Score: 80🌐 MovesJul 23, 2026https://www.straitstimes.com/opinion/why-the-us-is-losing-chinese-ai-stars - Forum: Xi Jinping Headlines World AI Conference
China’s ninth annual World AI Conference (WAIC) was held from July 17–20 in Shanghai. Escalating points of tension in the U.S.-China AI competition, including tit-for-tat cybersecurity measures aimed at frontier models and U.S. labs’ reiterated emphasis of the risks posed by China’s AI ascendancy, m
Score: 80🌐 MovesJul 23, 2026https://digichina.stanford.edu/work/forum-xi-jinping-headlines-world-ai-conference/ - NVIDIA and KAIST Launch Joint AI Research Lab to Accelerate AI Innovation in Korea
NVIDIA and the Korea Advanced Institute of Science and Technology (KAIST) today announced the launch of a joint AI research laboratory at the KAIST Kim Jaechul Graduate School of AI in Seoul, dedicated to advancing agentic AI for South Korea.
- How AI helps scientists design the next generation of medicines
Designing and developing a new medicine is an expensive, failure-prone scientific challenge. A new drug can take many years to develop, at the cost of a significant investment. And even then, most possible candidates never reach the patient. For biologic medicines, therapies made from engineered proteins rather than synthetic chemistry (which are often used to…
- Blackstone beats profit estimates with AI gains as assets hit $1.35 trillion
Blackstone beats profit estimates with AI gains as assets hit $1.35 trillion Reuters
- Alphabet borrows $100bn to pay for AI investments
Alphabet , the parent company of Google, has reported revenue for the second quarter of 2026 of £120bn, an increase of 24%, with Google Cloud experiencing “accelerated” growth. The Google Cloud Platform posted revenue of almost $25bn, an 82% increase from the previous year, driven by demand for artificial intelligence (AI). But the company’s capital expenditure (CapEx) during the quarter was $44.bn, with the vast majority of that being spent on technical infrastructure to support the company’s investments in AI. Of the $45.9bn in costs incurred during the quarter, it spent $18.2bn on research and development. CEO Sundar Pichai said: “One of the strongest parts of our growth comes from the rapid adoption of our Gemini Enterprise platform. It is differentiated with easy-to-use tools to build agents and automate processes, connectivity to enterprise systems, cost management and governance tools. “Gemini is transforming how millions of businesses use AI to build custom agents, automate processes, improve cyber security, manage customer relationships, streamline data analytics, collaborate effectively and more,” he said. “All of this momentum is driving growth in our paid token usage.” Chief financial officer Anat Ashkenazi said: “Approximately 60% of our investment in technical infrastructure this quarter was in servers, and 40% was in datacentres and networking equipment.” She said the company has revised its full-year 2026 CapEx guidance range to $195-205bn, up from its previous estimate of $180-190bn. “The increase in the range is primarily due to an acceleration in the delivery of capacity to meet growing demand,” said Ashkenazi. “As we previously shared, we continue to expect our CapEx to increase significantly in 2027.” She said the increase in spending would put pressure on Alphabet’s profit and loss account in the form of higher depreciation expense and related datacentre operations costs. When questioned about the rise in CapEx, Ashkenazi said: “We take a multi-year view at what the needs are, as well as focus on next year in the near term and build aggressively to meet those demands.” She said the company has also expanded its debt portfolio “quite significantly over the past 12 months”. This has grown from $16bn to $100bn. Along with running AI inference and machine learning workloads for its cloud customers, agentic AI is one of the areas the company has begun expanding into. Speaking about agentic AI in e-commerce, Philipp Schindler, chief business officer, used his prepared remarks during the earnings call to talk about agent-to-agent e-commerce. He said Alphabet has been running with a number of retailers, including Target, and described the open-source Universal Commerce Protocol (UCP) as “the new standard for agentic commerce”. “Merchants are rapidly adopting UCP,” said Schindler. “We also announced Universal Cart, allowing shoppers to add to items from different retailers across Google surfaces and buy in a single checkout.” Commenting on the Alphabet results, Forrester vice-president and research director Emily Collins said: “The results suggest Google is successfully using AI to deepen engagement while expanding its role across product discovery, shopping and commerce. As AI reshapes digital experiences, Google is positioning itself to monetise consumer intent across the entire customer journey.” Read more about AI investment AI inference cost optimisation : An enterprise guide: Inference is the largest long-term expense in enterprise AI deployments. Businesses can keep AI inference costs in check with these seven optimisation strategies. How the AI boom is reshaping tech cost management:FinOps practitioners are stepping up to manage AI expenses, optimise token usage and align cost-saving measures with sustainability goals to improve returns from AI investments.
Score: 80💰 MoneyJul 23, 2026https://www.computerweekly.com/news/366646235/Alphabet-borrows-100bn-to-pay-for-AI-investments - Alphabet's cash burn raises alarm for Big Tech as AI spending climbs
Alphabet's cash burn raises alarm for Big Tech as AI spending climbs Reuters
- Intel forecast crushes estimates as AI boom boosts chip demand; shares jump
Intel forecast crushes estimates as AI boom boosts chip demand; shares jump Reuters
- 142 AI data center protests staged in 42 states as public opposition increases — organizers brand 'unaccountable' buildouts as an 'unacceptable infringement on our liberty'
Data center projects are facing increasing opposition from surrounding communities, making consent even far scarcer than the chips and power needed to run these facilities. Any developer planning to construct one must now consider the people living around the proposed site and take account for the months or years needed to approve it, if it even gets the green light.
- AI infrastructure demand is outrunning even the boldest supply chain strategies
AI infrastructure buildouts are moving so fast that plans made just months ago are already obsolete, forcing hardware makers to rewrite how they design, source and ship the systems powering the next generation of AI factories. The shift from single-shot retrieval-augmented generation, or RAG, toward agentic AI has reshaped what enterprises need from their compute […] The post AI infrastructure demand is outrunning even the boldest supply chain strategies appeared first on SiliconANGLE .
Score: 78🌐 MovesJul 23, 2026https://siliconangle.com/2026/07/22/ai-infrastructure-demands-configurable-rack-scale-compute-amdadvancingai/ - Trump expands a voluntary pledge to protect consumers from high utility bills from AI data centers
Trump expands a voluntary pledge to protect consumers from high utility bills from AI data centers Toronto Star
- 23 governors sign Trump's cost pledge for data centers, backbone of AI
23 governors sign Trump's cost pledge for data centers, backbone of AI USA Today
- AlphaSense Tops $700 Million in Annual Recurring Revenue, Takes IPO Steps
AlphaSense Tops $700 Million in Annual Recurring Revenue, Takes IPO Steps The Information
Score: 78💰 MoneyJul 23, 2026https://www.theinformation.com/articles/alphasense-tops-700-million-annual-recurring-revenue-takes-ipo-steps - Teladoc launches AI-driven platform for 'new era of connected care'
Teladoc launches AI-driven platform for 'new era of connected care' Healthcare IT News
Score: 78🌐 MovesJul 23, 2026https://www.healthcareitnews.com/news/teladoc-launches-ai-driven-platform-new-era-connected-care - AI arms race in line for a reckoning after OpenAI hacking incident
Aggressive training techniques sharpens threat of bad behavior by leading models.
Score: 78🌐 MovesJul 23, 2026https://arstechnica.com/ai/2026/07/ai-arms-race-in-line-for-a-reckoning-after-openai-hacking-incident/ - AI memory shortage is now increasing the price of cars — GM warns of vast cost increases, BYD hikes driver assistance prices 20%
GM CFO Paul Jacobson says that the company's costs are expected to increase by $1.5 to $2 billion, primarily due to increasing memory chip costs. The move comes as the RAM shortage is affecting the automotive industry, right as cars are requiring more memory and storage due to infotainment and ADAS features.
- Medidata Launches Medidata Plus, an AI-Native Foundation Built to Scale Clinical Portfolios
Medidata Launches Medidata Plus, an AI-Native Foundation Built to Scale Clinical Portfolios Toronto Star
- SK Telecom Leads Global Technical Standardization for Physical AI
SKT’s robot data factory standard adopted by ITU-T to support AI training for intelligent robots.
Score: 78🌐 MovesJul 23, 2026https://www.sktelecom.com/en/press/press_detail.do?idx=1672¤tPage=1&type=all&keyword= - AI image fraud will cost $40 billion next year - can these international standards help?
Until now, efforts to identify and combat deepfakes and AI scams have been scattered. Which proposed standard will dominate?
- US Senator Warren accuses AI firms of trying to curb oversight in trade accord
US Senator Warren accuses AI firms of trying to curb oversight in trade accord Reuters
Score: 78🌐 MovesJul 23, 2026https://www.reuters.com/legal/litigation/warren-accuses-ai-firms-trying-curb-oversight-trade-accord-2026-07-23/ - Intel’s AI-Fueled Forecast Shows Comeback Is Gaining Steam
Intel Corp. delivered a revenue forecast that shattered Wall Street estimates as booming data center spending fuels a long-awaited turnaround.
- Ford Will Use Apple Maps in New Self-Driving System
In a first, Apple software will influence the way a new line of electric vehicles made by Ford Motor operates, and other automakers may follow.
Score: 77🌐 MovesJul 23, 2026https://www.nytimes.com/2026/07/23/business/ford-apple-software-self-driving.html - Utho Cloud to deploy 10,000 GPUs over two years to expand AI infrastructure in India
The deployment will include Nvidia H200, H100 and Blackwell GPUs, with the company promising sovereign AI infrastructure and up to 60% lower pricing than hyperscalers.
- US tech firms debate curbs on Chinese AI
For some execs, the rise of open-source AI from China marks a “dystopian hellscape,” while others are complimenting the “excellent” models.
Score: 77🌐 MovesJul 23, 2026https://www.semafor.com/article/07/23/2026/us-tech-firms-debate-curbs-on-chinese-ai - Google Cloud’s Revenue Is Rocketing—but Costs of AI Expansion Are as Well
Google Cloud’s Revenue Is Rocketing—but Costs of AI Expansion Are as Well The Information
Score: 77🌐 MovesJul 23, 2026https://www.theinformation.com/newsletters/the-briefing/google-clouds-revenue-rocketing-costs-ai-expansion-well - Trump Expands AI Data Center Pledge in Bid to Ease Power Costs
President Donald Trump on Thursday welcomed fresh commitments from power utilities and data center developers to put technology companies on the hook to pay for the electricity they need to drive energy-hungry artificial-intelligence systems.
- Tech Bonds Hit by Selloff as AI Debt Fears Race Through Markets
The bonds of some of the biggest US tech companies slid Thursday amid renewed worries about the scale of the debt-fueled artificial-intelligence boom and escalating conflict in the Middle East.
- NVIDIA AI Supercomputer Comes Online at Naval Postgraduate School
NVIDIA founder and CEO Jensen Huang today visited the Naval Postgraduate School in Monterey, California, to commission an NVIDIA DGX GB300 system — bringing one of the world’s most powerful AI platforms fully online for the students, researchers and faculty at the U.S. military’s flagship graduate university. “Our nation depends on our men and women […]
Score: 76🌐 MovesJul 23, 2026https://blogs.nvidia.com/blog/naval-postgraduate-school-dgx-ai-supercomputer/ - Google transforms its data center architecture for agent era
Google’s data center team is racing to turn its infrastructure into a well-oiled machine for AI and the onslaught of agents . At this year’s Google I/O, CEO Sundar Pichai shared startling numbers: Google’s data centers processed about 3.2 quadrillion tokens a month, roughly seven times more than the 480 trillion processed in May 2025. “Multiple agents work together, and now you’ve got millions, billions of users around the world potentially spinning off agents to help them do things,” said Mark Lohmeyer , vice president and general manager for AI and computing infrastructure at Google. Google’s new data-center blueprint includes updated hardware, software, and orchestration layers to keep always-running agents operational. In the LLM era, users sent prompts and received responses, and Google’s infrastructure was designed for latency and throughput. But agents could increase inference transactions by up to 100 times non-agentic workloads, Lohmeyer said. Google’s redesigned AI data-center stack has the elasticity for agents to be widely distributed, run for long periods, and make decisions independently. “We’re delivering new platforms every year, each one optimized for what we think the world is going to need for the age of agents going forward,” Lohmeyer said. Efficient data flow is key so agents can act, reason, and decide faster. Google adjusted the Google Kubernetes Engine into an agent-native environment, where agents could be quickly spun up in sandboxes and containers. “From an infrastructure perspective, you need to spin up a bunch of TPUs or GPUs very rapidly. Then you need to be able to run them and spin them back down,” Lohmeyer said. Google also made drastic improvements to its silicon to support its middleware changes. It recently introduced new AI chips , with the TPU-8t for training, and TPU-8i for inference. The 8t chip has three times more computing power than the previous-generation Ironwood chip. The 8i chip has 384 megabytes of SRAM and 288GB of HBM3e memory, which is 50% more than the previous-generation chip. The platform is optimized for KV cache (key-value cache), which stores important contextual information needed by agents to make decisions, which reduces the round trips to other memory and storage systems. “Being able to store more of the KV cache directly on the chip allows you to respond much more rapidly and cost-effectively,” Lohmeyer said. A new CPU called Axion N4A is more power efficient at agentic workloads such as orchestration and tool calling, Lohmeyer said. Google also made many network and storage improvements to cut training and inference time. A new technology called TPUDirect can move data from storage directly into the memory of the TPU quickly by bypassing any orchestration overhead, Lohmeyer said. A networking technology called Virgo can coordinate 1 million TPUs across a widely distributed network. It can also link up GPUs such as Nvidia’s latest CPU-GPU package called Vera Rubin. “In the case of Vera Rubin, we’ll be able to connect up to 960,000 GPUs leveraging Virgo,” Lohmeyer said. A new technology called Pathways is a distributed training framework that efficiently scales machine learning across millions of TPUs and GPUs. Pathways solves bottleneck issues typically associated with JAX, and both help coordinate across wide networks. “The software to orchestrate these large-scale distributed training jobs is also just as important as the hardware that it runs on top of,” Lohmeyer said. Weighing Google’s AI data-center stack Google is the only provider with its own data centers, software, hardware and models, said Jack Gold , principal analyst at J. Gold Associates. Google can optimize each on a regular cadence, which “many data centers can’t easily afford given the high cost of new chips,” Gold said. Google’s stack may not be best for every data center need compared to Nvidia’s general-purpose GPUs, CPUs, and networking. AWS and Microsoft are also creating their chips. “There is no real risk of Nvidia being replaced by Google in a big way. But with an ever-expanding market, there is plenty of room for all players,” Gold said. But Logan Wolfe , partner at Kyndryl’s global AI strategy and sovereign transformation, advised enterprises to adopt a multi-cloud strategy to reduce risk from system failures, however superior an infrastructure may be. “I think that kind of hybrid and liquid infrastructure, we’re definitely getting there,” Wolfe said. The cost per token varies depending on the provider of inference, whether that’s Microsoft, Google, OpenAI or Anthropic. That will matter as AI moves from experimentation to a powerful tool that drives business changes. “Ultimately it really comes down to how much money are we spending on AI to move a certain business outcome,” Wolfe said.
Score: 76🌐 MovesJul 23, 2026https://www.networkworld.com/article/4200581/google-transforms-its-data-center-architecture-for-agent-era.html - Why OpenAI’s Hugging Face AI Hack Spooked Employees
Why OpenAI’s Hugging Face AI Hack Spooked Employees The Information
Score: 76🌐 MovesJul 23, 2026https://www.theinformation.com/newsletters/applied-ai/openais-hugging-face-ai-hack-spooked-employees - Ajman launches UAE's first Agentic AI service to renew trade licences
Ajman launches UAE's first Agentic AI service to renew trade licences Gulf News
- German DeepTech startup kausable raises €12 million to develop reasoning-first AI that adapts without retraining
kausable, a German DeepTech AI startup, has raised €12 million in a Seed funding round to develop reasoning-first frontier AI that adapts on its own efficiently to changing context without further retraining. The round was led UVC Partners and Entourage, with follow-on from the German investors HTGF and Mätch VC. kausable is also backed by […] The post German DeepTech startup kausable raises €12 million to develop reasoning-first AI that adapts without retraining appeared first on EU-Startups .
- Democrats seize on AI data center backlash that's dividing rural Republicans in places like Texas
Democrats seize on AI data center backlash that's dividing rural Republicans in places like Texas Toronto Star
- Four former DOGE staffers raised $160 million at a $1.4 billion valuation for an AI military cyber startup
Cathedral, a stealth military cybersecurity startup founded by four former Department of Government Efficiency staffers, has raised $160 million at a $1.4 billion valuation. Andreessen Horowitz and Sequoia Capital led the round and both took board seats. The company plans to secure US government contracts for AI-driven offensive and defensive cyber operations against adversaries including […] This story continues at The Next Web
Score: 75💰 MoneyJul 23, 2026https://thenextweb.com/news/cathedral-doge-alumni-military-cyber-startup-1-4-billion - Samsung Reportedly Weighs €1B Mistral AI Investment
Samsung is reportedly weighing a €1 billion investment in Mistral, giving the French AI lab a possible €20 billion valuation as Europe pushes sovereign AI. The post Samsung Reportedly Weighs €1B Mistral AI Investment appeared first on TechRepublic .
Score: 75💰 MoneyJul 23, 2026https://www.techrepublic.com/article/news-samsung-mistral-ai-investment-emea/ - Robotics Startup Genesis in Talks to Raise About $500 Million
AI robotics startup Genesis AI is in talks with investors to raise around $500 million in a new funding round, according to people familiar with the efforts.
Score: 75💰 MoneyJul 23, 2026https://www.bloomberg.com/news/articles/2026-07-23/robotics-startup-genesis-in-talks-to-raise-about-500-million - PODCAST: Alphabet's AI bill
PODCAST: Alphabet's AI bill Reuters
Score: 75🌐 MovesJul 23, 2026https://www.reuters.com/podcasts/reuters-morning-bid/morning-bid-2026-07-23/ - Apple’s OpenAI lawsuit is about who gets to define the post-smartphone era
Today on Decoder, I’m talking with Hayden Field, The Verge’s senior AI reporter, about the major trade secrets lawsuit between Apple and OpenAI and what this tells us about OpenAI’s future. By now I’m sure most Decoder listeners are familiar with Apple’s allegations in this case. The company says a number of ex-Apple employees at […]
Score: 75🌐 MovesJul 23, 2026https://www.theverge.com/podcast/968787/apple-openai-trade-secrets-lawsuit-ai-hardware-smartphone-jony-ive - Anthropic calls for industry-wide AI safety standards to keep models from wreaking havoc
Anthropic's red team leader, Logan Graham, reveals AI models can now hack devices and steal money, prompting the launch of Project Glasswing.
- Google Cloud tops $24.8bn as AI drives growth
Alphabet’s cloud business emerges as its fastest-growing segment, as enterprises ramp up spending on AI infrastructure and services.
Score: 75🌐 MovesJul 23, 2026https://www.itweb.co.za/article/google-cloud-tops-248bn-as-ai-drives-growth/LPp6V7rBONz7DKQz - UAE ranks 17th globally, leads Middle East for AI readiness and future skills
UAE ranks 17th globally, leads Middle East for AI readiness and future skills
Score: 75🌐 MovesJul 23, 2026https://www.khaleejtimes.com/uae/uae-ai-readiness-global-top-20-qs-index - AI-Powered Ransomware Threatens India: 62% of Hit Firms Report Higher Attack Impact
Proofpoint, Inc. today released its 2026 AI-Era Ransomware Report, revealing that artificial intelligence is making ransomware significantly more successful by helping attackers create more convincing phishing, impersonation and credential theft campaigns. The study found that nearly 62% of Indian organizations affected by ransomware said AI increased the effectiveness of the attack, reinforcing a broader shift […] The post AI-Powered Ransomware Threatens India: 62% of Hit Firms Report Higher Attack Impact appeared first on CXOToday.com .
- The 3 biggest takeaways from Google's Q2 earnings, from AI spending to a milestone for Gemini
The 3 biggest takeaways from Google's Q2 earnings, from AI spending to a milestone for Gemini Business Insider
Score: 75🌐 MovesJul 23, 2026https://www.businessinsider.com/3-biggest-takeaways-from-google-second-quarter-earnings-ai-spending-2026-7 - Studios Are Cutting Staff. Freelancers Will Pay The AI Bill
Hollywood faces a crisis, with production down 30% and many creatives struggling. Studios are pushing AI costs onto freelancers, but this strategy may not yield savings.
- JPMorgan report finds dramatic jump in AI-themed ETFs — despite rough quarter
Wall Street is banking heavily on exchange-traded funds that give investors artificial intelligence exposure, according to JPMorgan Asset Management.
Score: 75🌐 MovesJul 23, 2026https://www.cnbc.com/2026/07/23/jpmorgan-dramatic-jump-in-ai-etfs-despite-rough-quarter.html - Musk proposes peer review for frontier AI models in Economist interview
Musk proposes peer review for frontier AI models in Economist interview Reuters
- Databricks expands Microsoft Azure partnership, to use more custom chips
Databricks expands Microsoft Azure partnership, to use more custom chips Reuters
- The agent security gap: 54% of enterprises have already had an AI agent incident, and most still let agents share credentials
Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents still share credentials; and only three in ten isolate their highest-risk agents. The security stack is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents, spending remains a thin slice of the security budget, and enterprises are evenly split on whether their defenses are keeping pace with AI-enabled attackers. The result is an agent security gap — autonomous agents proliferating faster than the identity, isolation, and enforcement controls needed to hold them. This wave of VentureBeat Pulse Research examines how enterprises secure their AI agents: what tooling they run, how they manage agent identity and isolation, what has already gone wrong, how much they spend, and whether they believe their defenses are keeping pace with AI-enabled attackers. The central finding is an agent security gap — the distance between the autonomy enterprises are granting their agents and the controls in place to contain them. More than half of organizations (54%) have already experienced a confirmed agent security incident (18%) or a near-miss caught before harm (36%). The structural weakness beneath those numbers is identity: only about a third (32%) give every agent its own scoped, managed identity, while the rest report that some agents share credentials or that agents mostly run on shared API keys and human or service-account credentials. When agents share credentials, a single compromised or over-permissioned agent carries a wide blast radius — and only three in ten enterprises (30%) isolate their highest-risk agents in sandboxes to bound that radius. What makes the gap notable is how comfortable enterprises are inside it. The security stack is overwhelmingly provider-native — OpenAI’s guardrails (51%), Google’s and Microsoft’s cloud controls, and Anthropic’s managed-agent controls dominate, while the dedicated agent-security specialists barely register — and satisfaction with that borrowed stack is high, averaging 4.2 out of 5. Yet spending remains a thin slice of the security budget, only a third of enterprises believe their AI defenses are ahead of AI-enabled attackers, and a clear majority plan to change tooling within the year. Enterprises are satisfied with controls they are simultaneously preparing to replace. Methodology VentureBeat fielded this survey as part of its ongoing Pulse Research series, this instrument focused on enterprise agent security — the tooling, identity, isolation, and enforcement controls organizations use to secure autonomous AI agents. Responses are filtered to organizations with more than 100 employees (n=107; the survey’s smallest size band, 1–100 employees, is excluded), drawn from a single June 2026 wave. Because this is one wave rather than a pooled multi-month sample, the report reads cross-sectionally and does not infer month-over-month trends. Several questions were multiple-select, so those shares can sum to more than 100%. By role the sample is senior and buyer-credible: 45% are final decision-makers for AI purchases and another 30% recommenders or influencers. Managers (43%), individual contributors (24%), VPs and directors (15%), and the C-suite (11%) make up the seniority mix. By organization size the sample is mid-market-weighted: 251–1,000 (42%) and 101–250 (25%) employees lead, with 1,001–5,000 (19%), 5,001–10,000 (8%), and 10,001+ (7%) above them. Technology/Software is the largest industry at 23%, followed by Manufacturing (15%), Retail/E-commerce (14%), and Healthcare/Life Sciences (13%). At 107 respondents the sample is large enough to read directionally but should be treated as a directional signal rather than a precise measurement; it is self-selected and is not a probability sample. It skews toward the mid-market, so it is best read as the view from organizations actively standing up agent security rather than from the largest operators. Satisfaction ratings are computed on the respondents who answered each rating question; the overall satisfaction score reflects 82 of the 107 qualified respondents. Finding 1: The incidents are already here More than half have had an agent security incident or near-miss We asked whether organizations had experienced an agent security incident — a confirmed breach, or a near-miss caught before harm. Most that run agents in production had. This is the report’s defining number. More than half of organizations (54%) have already had an agent security event — 18% a confirmed incident and 36% a near-miss caught before it caused harm. Only 42% report nothing, and a small remainder either run no agents in production or don’t track such events. That so many report near-misses rather than only confirmed incidents is telling: enterprises are catching problems, but they are catching them close to the edge. The controls examined in the rest of this report — identity, isolation, enforcement — are what determine whether the next near-miss stays a near-miss. Exposure scales with company size, but containment does not. The incident-or-near-miss rate rises from 49% in the mid-market (companies with 101-1,000 employees) to 63% at larger enterprises (above 1,000 employees), while sandbox isolation of high-risk agents falls from 35% to 20%, and satisfaction with security tooling drops from 4.36 to 3.97. The organizations running the most agents across the most systems carry the most incidents and the least of the one control that bounds an incident's blast radius. Finding 2: The identity gap Only a third give every agent its own scoped identity We asked how enterprises manage the identity of their AI agents — whether each agent has its own credentials, or agents share them. Full per-agent identity is the exception. Rolled together, the overlapping answers show 69% of enterprises (74 of 107) with credential sharing somewhere in the agent fleet. Identity is the structural weakness beneath the incidents. Only about a third of enterprises (32%) give every agent its own scoped, managed identity — the precondition for least-privilege access and clean attribution. Nearly half (48%) say some agents have scoped identities but many still share credentials, and another 32% say agents mostly run on shared API keys or borrowed human and service-account credentials. (Respondents could describe more than one pattern across their agent fleet, so these overlap.) The consequence is direct: when agents share credentials, an over-permissioned or compromised agent can act with far more reach than intended, and forensics after an incident cannot cleanly tell which agent did what. The non-human identity problem — giving every agent its own governed identity — is the single largest unfinished piece of enterprise agent security. Moreover, a company’s agent credential posture is correlated with incidents. Organizations with credential sharing anywhere in the fleet were hit — with an incident or a near-miss in the past twelve months — at 63.5% (47 of 74). Organizations where every agent carries its own scoped identity were hit at 40.9% (9 of 22). The fully-scoped group is small, so for now the relationship is an association rather than proven causation, and the gap is concentrated in the mid-market — but within a single survey, a twenty-three point difference in incident rate suggests significance. Finding 3: Observe and enforce, but rarely isolate Only three in 10 sandbox their highest-risk agents We asked what an organization’s agent security posture looks like in practice — whether they observe, enforce, isolate, or some combination. The control that bounds damage is the least common. Monitoring and enforcement are reasonably common; containment is not. Roughly half of enterprises observe agent activity (47%) or enforce scoped permissions at runtime (49%), but only 30% isolate their highest-risk agents in sandboxes that bound the blast radius when the other controls fail. That ordering is backwards from a defense-in-depth standpoint: observation tells you what happened, enforcement tries to prevent it, but isolation is what limits the damage when prevention fails — and it is the control enterprises have adopted least. Combined with the identity gap in Finding 2, the picture is of agents that are watched and permissioned but rarely boxed in, which is precisely the configuration in which a single failure propagates. Finding 4: Security runs on borrowed, provider-native controls Guardrails from OpenAI, Google and Microsoft dominate; specialists barely register We asked which agent security tooling enterprises use, and which is their primary layer. The answer favors the model providers and hyperscalers over the dedicated security vendors. Enterprises are securing agents with tools that came bundled with their models and clouds. OpenAI’s guardrails lead at 51%, followed by Google’s and Microsoft’s cloud-native controls and Anthropic’s managed-agent controls — and when asked to name their single primary security layer, 82% name one of these provider-native offerings. The purpose-built agent-security category — Palo Alto’s Prisma AIRS, CrowdStrike, Cisco AI Defense, Zenity, HiddenLayer, Check Point’s Lakera, Okta for AI Agents, non-human identity platforms — barely registers, each in the low single digits, and only 5% run no dedicated tooling at all. As with retrieval and evaluation elsewhere in this series, the provider bundle is winning the default: enterprises reach first for the guardrails their platform ships, and the independent security layer that would address the identity and isolation gaps has not yet been adopted at scale. The provider-default pattern is consistent across both Q2 survey waves. In April–May (n=110), usage was led by the same names — OpenAI's controls at 26%, Azure at 15%, AWS at 14%, Google at 12% — with every dedicated agent-security specialist at 3% or below and one in ten using no dedicated tooling at all. The common finding from the two surveys: Enterprises are defaulting to the solutions provided by the platform they’re using, and the specialist category vendors have yet to become big players here. ( A note on reading these shares. As described in the methodology section, the respondent sample is self-selected and skews mid-market, and the usage question counted every vendor or approach a respondent has in place — so the figures measure presence in the security stack rather than spending or exclusivity. Individual vendor percentages therefore carry all the usual sample caveats. The structural pattern, however, held across both Q2 waves on two differently worded questions: provider-native and hyperscaler controls lead, and dedicated agent-security specialists remain in low single digits. Read the individual shares loosely and the pattern with confidence.) Finding 5: And enterprises are comfortable with it Satisfaction is high, even as incidents mount and identity lags We asked how satisfied enterprises are with their current agent security tooling. The comfort is notably out of step with the exposure documented above. Satisfaction with agent security tooling is high — 4.2 out of 5 overall, and 4.1 for value for money — among the most positive readings in this series. That is the striking part: enterprises are highly satisfied with a stack that is mostly borrowed provider guardrails, even though more than half have already had an incident or near-miss and only a third give their agents scoped identities. The comfort appears to rest on the convenience and low friction of provider-native controls rather than on demonstrated containment. It is a false comfort in the making — the same enterprises expressing satisfaction are, as Finding 8 shows, a clear majority planning to change tooling within the year, which suggests the confidence is thinner than the score implies. Finding 6: Budgets haven’t caught up Most spend under a tenth of the security budget on agents We asked what share of the security budget enterprises allocate to securing AI agents. For a fast-emerging risk, the allocation is modest. Spending on agent security is still a thin slice. The most common allocation is 6–10% of the security budget (46%), and a third of enterprises (34%) spend 5% or less; only a quarter (24%) devote more than a tenth. Given the incident rate in Finding 1 and the identity and isolation gaps in Findings 2 and 3, the budget looks like a lagging indicator — the risk has arrived faster than the funding to address it. The enterprises spending more than a tenth of their security budget on agents are a distinct minority, and they are likely the ones building the scoped-identity and isolation controls the rest have not. Finding 7: The arms race is even, at best Only a third think their AI defenses are ahead of AI-enabled attackers We asked how enterprises assess the balance between their AI-enabled defenses and AI-enabled attackers. Confidence is far from settled. Enterprises are split on whether they are winning. Only about a third (35%) believe their AI-enabled defenses are ahead of AI-enabled attackers; the rest are less sure — 32% call it roughly even, 21% think attackers are ahead, and another 21% say it is too early to tell. Taken together, a clear majority (53%) rate the balance as even or tilted toward the attacker. That uncertainty sits uneasily beside the high satisfaction of Finding 5: enterprises are content with their tooling yet unconvinced it is winning the contest it exists to win. In a domain where the offense is also compounding with AI, an even race is not a comfortable place to be. Finding 8: A security reshuffle is coming Nearly six in 10 plan to adopt or switch tooling within a year We asked whether enterprises plan to adopt a new, additional, or replacement agent security solution, and which they are considering. Few intend to stand pat. The security stack is not settled. While 41% have no plans to change, a clear majority (59%) intend to adopt a new, additional, or replacement agent security solution within twelve months, and 29% within the next quarter — a strong signal that, high satisfaction notwithstanding, enterprises know the current stack is provisional. Incidents are what start the buying cycle. Among organizations that have been hit, 42.1% plan to adopt, add, or replace agent security tooling within the next ninety days, against 14.0% of organizations with no incident — and after a confirmed incident it becomes majority behavior, at 52.6%. Getting hit also changes the threat assessment: 33.3% of hit organizations say AI-armed attackers are ahead of their defenses, against 8.0% of the unhit. Experience, in this data, is the strongest predictor of both urgency and pessimism. The consideration set still leans provider-native (OpenAI 34%, Google 30%, Anthropic 29%, Azure 25%), but the dedicated security vendors — Cloudflare, Cisco, Palo Alto, Okta, Check Point’s Lakera — draw early interest in the mid-to-high single digits, more than their current footprint. What the shopping does not yet include is the identity layer specifically. Twelve percent of the respondents include an agent-identity product — Okta for AI Agents, Microsoft Entra Agent ID, or a non-human identity platform — anywhere in their consideration set, and among the credential-sharing organizations that have already had an incident, identity consideration is essentially unchanged, at roughly one in ten. The control most directly implicated by the incident data is the one largely missing from the purchase plans. Whether this wave hardens the provider-native default or finally opens the door to purpose-built agent security — the identity and isolation controls the incidents call for — is the question this series will keep tracking. The bottom line: A security gap that autonomy will test first Organizations with more than 100 employees are giving AI agents real reach into systems and data while securing them with controls built for something else. More than half have already had an incident or near-miss; only a third give every agent its own scoped identity, and most still share credentials; only three in ten isolate their highest-risk agents; and the stack doing this work is overwhelmingly borrowed from the model providers and hyperscalers rather than purpose-built for agents. The uncomfortable pairing is confidence with exposure: satisfaction with the current tooling is among the highest in this series, yet spending is a thin slice of the security budget, only a third believe their defenses are ahead of AI-enabled attackers, and a clear majority are already planning to replace what they have. At 107 respondents in a single wave this is a directional read, skewed toward the mid-market — but the direction is clear: agent adoption is running ahead of agent security, and the controls that matter most when something fails — scoped identity and isolation — are the ones enterprises have built least. The agent security gap is not a coverage problem that a provider guardrail will close on its own; it is a problem of identity, isolation, and enforcement built for autonomous software. The open question for later waves is whether enterprises close it deliberately — or whether a confirmed incident closes it for them. Based on survey responses from 107 qualified enterprise respondents (100+ employees), drawn from a single June 2026 wave. This is a directional read, not a precise measurement — the sample is self-selected and skews mid-market, so it's best read as the view from organizations actively standing up agent security rather than from the largest operators. Respondents are senior and buyer-credible (45% final decision-makers, 30% recommenders/influencers), spanning managers through the C-suite, and drawn primarily from Technology/Software, Manufacturing, Retail/E-commerce, and Healthcare/Life Sciences.