The security of AI agents is a pressing concern for enterprises, with a majority already experiencing incidents. Despite this, the focus remains on prevention rather than containment. Only 18% of enterprises isolate their highest-risk AI agents, and 8% pair enforcement with isolation, leaving a significant gap in the security stack. This is particularly concerning as 53% of organizations have already had an agent security event, with 19% confirming an incident and 38% having identified a near-miss. The lack of isolation and containment measures means that the blast radius of any security breach is wide, and post-incident forensics are challenging. The reliance on borrowed, provider-native controls from hyperscalers and model providers further exacerbates the issue, with only 10% of enterprises considering dedicated agent-identity products. The arms race between AI-enabled defenses and attackers is tilting, with 30% of enterprises believing attackers are ahead, and 74% planning to replace their current security tooling within 12 months. This highlights the need for a comprehensive approach to agent security, including isolation and governed identity, to address the growing lack of confidence in agentic security.