Cisco ran 6,986 multi-turn attacks against 15 flagship AI models and recorded an 88.3% breach rate. Amy Chang, Cisco's head of AI threat intelligence, presented that figure at VB Transform 2026. The comparison stat is the real problem: single-turn and multi-turn testing did not rank the same models in the same vulnerability order, meaning any organization using only one-shot red-teaming has an incomplete picture of its actual exposure.

The enterprise posture behind that number is worse. VentureBeat's June 2026 survey of 107 companies found 54% have already experienced a confirmed agent security incident or a near-miss. Only 32% give each agent its own scoped identity. Only 30% sandbox their highest-risk agents. Meanwhile, 82% still rely on provider-native controls as their primary security layer. Three acquisitions priced the gap directly: Palo Alto Networks closed a $25 billion deal for CyberArk in February, CrowdStrike agreed to pay $740 million for SGNL in January, and Cisco announced a reported $400 million acquisition of Astrix Security, all targeting the identity and isolation layer most enterprises have not finished building.

The defensive argument in the full piece is worth reading because it cuts against the complexity instinct. Chang concluded that after building agentic frameworks where AI systems design, execute, and self-evaluate attacks, the answer is still basic: map your fundamentals, trace real incidents back through Cisco's Integrated AI Security and Safety Framework, and build coverage from there. Box CISO Heather Ceylan adds a concrete three-layer model, and Intuit's VP of AI Rajesh Parekh explains how a central generative AI operating system called GenOS removes the permissioning burden from individual agent developers. The architecture details are specific enough to act on.

[READ ORIGINAL →]