Fresh enterprise research puts a number on a problem most security teams have been talking around: a majority now enforce agent permissions at runtime, and per-agent identity provisioning is climbing sharply, yet only a sliver isolate their highest-risk agents or pair enforcement with isolation. The result is a containment gap that widens even as every headline control improves.

The strategic misread is treating identity and isolation as substitutes rather than layers. Giving each agent a scoped, managed credential answers 'who is this agent' but says nothing about 'what happens when it goes wrong.' An agent with a clean identity and broad blast radius is still a breach waiting to happen. When 63% of fleets still share credentials somewhere, the identity gains are partly cosmetic. The Visa-Anthropic exercise, where a model chained minor weaknesses into working exploits under a governed harness, is instructive precisely because so few firms have the engineering depth to run it. Leaning on hyperscaler-native controls (which 92% of respondents naming a primary layer do) is the path of least resistance, and it quietly caps how far containment can go.

There is a subtler signal buried in the satisfaction data: the enterprises doing the hardest work, isolating their riskiest agents, rate their tools lower, while firms that got 'rescued' from a near-miss reward the tool with a trust premium. In a young market, the rescue does the marketing. That means buying decisions are being driven by relief, not by architecture, which is exactly how gaps calcify.

For Japanese enterprises, this lands on a familiar structural weakness. Agentic pilots here are overwhelmingly built on the big cloud and AI platforms, and security design is routinely delegated to SIers under fixed-scope contracts. The risk is that 'agent identity provisioned' gets checked off as done in a requirements document, while isolation, which demands ongoing architectural investment, never makes it into the statement of work. SIers that reframe agentic security as a layered platform capability rather than a one-time identity task have a clear differentiation opening, especially for finance and manufacturing clients where blast-radius control is a board-level concern.

The RPA angle is the most immediate. As Japan's large installed base of RPA bots evolves into autonomous agents, the credential-sharing habits baked into legacy automation carry straight over: shared service accounts, hardcoded secrets, no per-task scoping. Development and platform teams should treat the identity-versus-isolation distinction as the design question of 2026, not a later hardening step. The firms that build containment in from the first pilot will avoid retrofitting it after their first agentic incident.