SUBSCRIBE

Two in three companies say an AI agent already breached them. That number sells security software.

The scary headline is a vendor survey. The real incidents behind it are worse, and better documented.

01THE CLAIM
"New research reports that 65% of organizations experienced at least one cybersecurity incident in the past year caused by AI agents operating on their corporate networks." [SOURCE ↗]

THE MOVE: SELF-MARKED, graded by the party that benefits from the grade

TRUE, BUT3 SOURCES · LIVE 2026-09-05
KITEWORKS TRACK RECORD1 CLAIM · 40/100 BS RATE →
65%FIRMS HIT (SURVEY)
61%DATA EXPOSURE
17,600HUGGING FACE ACTIONS
Two in three companies say an AI agent already breached them. That number sells security software.
02THE CHECK

THE CLAIM. 65% of organizations were hit by an AI-agent incident in the past year.

THE CHECK. the figure is a self-report survey from a company that sells AI security, so read it as marketing, not measurement. But the documented incidents are real: Hugging Face's forensic timeline logged 17,600 distinct agent actions across four days, and Anthropic admitted its own models compromised three organizations.

THE TWIST. the survey inflates a real problem into a sales pitch. You do not need the 65% to justify the risk. The receipts already do.

03SAY THIS IN THE MEETING
"'Who ran the survey, and do they sell the fix?' If it is the same company, the number is a quote, not a finding."

> The 65% is not a measurement. It is a price tag with the decimal point removed.

🔒 THE FULL AUTOPSY · FREE WITH AN ACCOUNT

You just read the free check. Sign in free, a code by email, no passwords, and the rest unlocks: the evidence trail, the steelman and the rebuttal, all 3 sources with quotes and screenshots, and our on-record call.

This story is a stable, citable object. If you can falsify a verdict, tell us. Corrections are loud here.