Your AI Agent Just Handed Its Credentials to a Stranger.
Venture capital already knows the fix. Most enterprises haven’t shipped it.
DataTribe published its Q2 2026 Insights Report on July 27. Two days later, Help Net Security ran the number that mattered: AI and agent security is now the single largest category of cybersecurity seed-stage investment, close to a quarter of every deal done last quarter. That is not the story. The story is why investors are suddenly this specific about it.
They are not funding “AI security” in the abstract. They are funding one mechanism: an agent that spins up a second agent, mid-task, and hands it live credentials – no verification, no scoping, no log. DataTribe found roughly a quarter of deployed agents can do this today. Read that again. A quarter of the agents already running in production environments can silently create a new, unaccountable identity and give it the keys.
The Number Investors Actually Priced
Here’s the whole game: DataTribe measured every control in its dataset for impact on incident rates, and one control beat all the others by a wide margin. Scoping agent privileges to least-privilege access took incident rates from more than two-thirds of deployments down to below 20%. Not a modest improvement. A collapse.
That is what seed money is chasing – not agent security as a category, but the specific, provable lever inside it. Everything else investors funded this quarter is downstream of that one finding.
The Handoff Nobody Is Watching
Call it silent succession: an agent, mid-task, creates a subordinate agent and passes it working authority without telling anyone. No identity provider checks who the new agent is. No policy engine scopes what it can touch. No log records that the handoff happened at all.
This is not a hypothetical. It is the mechanism DataTribe is describing when it says a quarter of deployed agents can spawn sub-agents and hand off live credentials with no verification, scoping, or audit trail. The sub-agent inherits whatever access its parent happened to be holding, which is almost always broader than the actual sub-task requires. Nobody approved that grant. Nobody is accountable for it. It just happened, in milliseconds, because the architecture allows it.
Kiteworks’ own Data Security and Compliance Risk: 2026 Forecast Report found 60% of organizations cannot terminate a misbehaving AI agent once it is running, and 63% cannot enforce purpose limitations on what an agent is allowed to do in the first place. Those two numbers explain why silent succession works as an attack path. You cannot scope what you cannot see, and you cannot kill what you have no switch for.
Why the Math Got Worse This Quarter
None of this would matter as much if defenders still had time to notice. They don’t. DataTribe cites CrowdStrike’s 2026 Global Threat Report, which puts the fastest observed breakout time this year – initial compromise to lateral movement – at 27 seconds.
Twenty-seven seconds. That is not a detection window. That is barely enough time for a SOC dashboard to refresh. A human analyst cannot triage an alert, rule out a false positive, and contain an incident inside 27 seconds. Nothing built around “detect, then respond” survives contact with that number.
Meanwhile the old front door hasn’t closed. Verizon’s 2025 Data Breach Investigations Report found edge device and VPN exploitation rising sevenfold. So attackers are getting through the perimeter faster than ever, and once inside, they are increasingly finding unscoped, unlogged agent identities waiting for them. Fast entry plus ungoverned agent sprawl plus a 27-second window is not three separate problems. It’s one compounding one.
The Architectural Question
Here’s where it gets uncomfortable for anyone still thinking about this as a detection problem. If breakout happens in 27 seconds and a quarter of your agents can silently mint new identities with inherited access, faster alerting does not save you. The only control that acts inside that window is one that was already in place before the agent asked for anything.
That means the fix has to live at the point of the request, not at the perimeter and not in a SIEM dashboard after the fact. Every time an agent – or a sub-agent it just created – asks to touch a file, a record, or a dataset, something has to evaluate that specific request against policy before access is granted, and log it regardless of the outcome. This is the architectural bet a handful of vendors are making, Kiteworks among them: a unified policy engine that enforces per-request RBAC and ABAC for both human and agent identities under one plane, so a sub-agent inherits governance the moment it’s created instead of inheriting whatever access its parent happened to be holding. It is one example of the pattern, not the only one, and it does nothing for the edge and VPN exploitation Verizon is describing. Perimeter hardening and content-layer governance are two different budget lines that need to move together.
What to Do This Week
1. Inventory which of your deployed agents can spawn sub-agents. Most security teams cannot currently answer this question. That is the actual gap, not a lack of tooling.
2. Require that any sub-agent creation event triggers its own identity verification and scoped credential issuance – never inherited, unscoped access from the parent.
3. Confirm you have a working kill switch. If 60% of organizations can’t terminate a misbehaving agent, assume you’re in that group until you’ve tested it.
4. Push least-privilege scoping to the top of the AI governance roadmap, ahead of general AI policy work. It is the only control DataTribe measured that cut incident rates by two-thirds.
5. Stop treating this as a perimeter problem or a content-governance problem. It is both, funded from the same conversation, on the same timeline.
Venture capital isn’t betting on agentic AI security because it sounds forward-looking. It’s betting on it because DataTribe just showed the industry which control actually works, and most enterprises haven’t installed it yet. That gap is not a research question anymore. It’s a Monday morning task list.



