Enterprises Report Widespread AI-Related Security Incidents and Vulnerabilities

DigiCert's AI Trust Outlook survey of 1,001 IT and security leaders in the US, UK, and Australia found 78% of organizations had either experienced AI-related security incidents or identified AI-related vulnerabilities. The underlying DigiCert PDF frames the issue as an identity and governance problem, while The Register reports a company spokesperson's breakdown: 27.7% had one incident, 21.9% had multiple incidents, and 28.4% found vulnerabilities without incidents. For security and data teams, the practical signal is that AI agents are entering production faster than inventories, permissions, and audit trails can keep up. DigiCert also reports 90% of organizations have discussed AI governance at board or executive level, but only 50% have dedicated budgets and formal programs.
AI security is moving from model-risk theory into machine-identity operations: the control plane now has to know which agent acted, under whose authority, and with which data. The safest read of the DigiCert survey is not that every incident was a model flaw, but that enterprises are exposing gaps in identity, configuration, and traceability as AI agents move into live workflows.
What happened
DigiCert's AI Trust Outlook surveyed 1,001 IT and security leaders in the US, UK, and Australia. The PDF says 78% of organizations reported either AI-related security incidents or AI-related vulnerabilities; The Register reports DigiCert's spokesperson broke that into 27.7% with one incident, 21.9% with multiple incidents, and 28.4% with vulnerabilities but no incidents. The Register also reports the incidents were tied to unauthorized or misconfigured AI agents rather than defects in AI-generated code.
Security context
DigiCert's report says nearly 90% of respondents have begun implementing AI identity practices, but governance maturity lags. It says 90% have discussed AI governance at executive or board level, 50% have dedicated budgets and formal programs, and 53% can fully trace AI decisions back to the models and source data that produced them. The gap matters because agent actions may cross credentials, APIs, and machine-to-machine connections that conventional user-centric controls do not inventory well.
For practitioners
Treat the finding as an audit prompt, not a breach forecast. Security teams should first inventory AI agents and AI-enabled automations, bind them to owners and approved scopes, log tool and API calls, and confirm they can revoke access for a compromised or retired agent. The comparable Spacelift infrastructure survey points in the same direction: organizations are using AI-generated or agentic infrastructure workflows faster than review and governance controls mature.
What to watch
Watch whether agent identity schemes become measurable controls in procurement and security reviews rather than vendor positioning. Useful proof points would include agent IDs tied to workload identity, signed model or agent artifacts, traceable decision logs, and budgeted governance programs that reach production teams, not only board-level discussions.
Key Points
- 1DigiCert's survey found 78% of respondents had AI-related incidents or vulnerabilities, making agent governance an operational security issue.
- 2The Register reports the incident breakdown came from unauthorized or misconfigured AI agents, not defects in AI-generated code.
- 3Practitioners should prioritize agent inventory, scoped identities, revocation paths, and traceable logs before expanding autonomous workflows.
Scoring Rationale
The survey is notable for enterprise AI security teams because it ties AI incidents and vulnerabilities to practical gaps in agent identity, configuration, governance budgets, and traceability. The commissioned nature of the research and lack of disclosed incident detail keep it below major-industry-impact territory, but the operational signal is still relevant.
Sources
Public references used for this report.
Practice interview problems based on real data
1,625 SQL & Python problems across 15 industry datasets — the exact type of data you work with.
Try 250 free problems
