A majority of enterprises deploying AI agents in customer service have already experienced security incidents, yet most continue operating with inadequate access controls. The research surveyed 107 enterprises and found that 54% have suffered confirmed agent security incidents or near-misses, whilst only approximately one-third implement proper identity scoping—meaning most agents operate with shared credentials rather than individual, limited-scope access. This represents a fundamental gap between deployment velocity and security maturity: organisations are moving agents into production environments with real system and data access before establishing the foundational controls that should precede such integration.
For CX teams already running agent-based automation through platforms like Zendesk or Salesforce, this finding demands immediate audit of current credential architecture. The prevalence of shared credentials creates compounding risk—a single compromised agent or misconfigured workflow can expose customer data across multiple systems simultaneously, and the incident response surface becomes exponentially harder to contain. Teams should be asking whether their current agent deployments operate under individual service accounts with least-privilege access, or whether they've inherited the shared-credential model that now characterises the majority of implementations. The gap is particularly acute for support teams managing high-volume interactions, where the pressure to scale agents quickly often outpaces security governance.
The broader implication is that the agentic AI wave in customer service is outpacing the security infrastructure required to govern it responsibly. Organisations betting on agent-driven efficiency gains—as PwC and OpenAI are doing in customer service—need to recognise that incident response and credential management are not post-deployment considerations but prerequisites. For CX leaders, this means treating agent security architecture as a blocking dependency before scaling, not as a remediation task after incidents occur.
Across 107 enterprises, AI agents are being given real access to systems and data while the controls meant to contain them lag behind. More than half have already had a confirmed agent security incident or a near-miss; only about a third give every agent its own scoped identity, and most agents stil