Why AI Agents Are Becoming Your Newest Insider Threat
Blog

Why AI Agents Are Becoming Your Newest Insider Threat

Why AI Agents Are Becoming Your Newest Insider Threat


Somewhere in your business right now, there is very likely an AI agent with more access than most of your employees. It can read customer records, query your CRM, pull financial data, and take action across systems, often without a single human approving each step. Your IT team probably knows it exists. Whether anyone has actually governed what it can touch is a different question entirely.


This isn't a hypothetical. Obsidian Security, a firm that builds tools specifically to monitor AI agents interacting with enterprise data, raised 85 million dollars in August at a valuation of 1.1 billion dollars. The company's own numbers are the interesting part: nearly 70 percent of its clients now allow AI agents to interact with business data. That's not an edge case. That's most of the market, moving faster than most security teams can track.


The Real Shift Nobody Is Talking About


The conversation around AI agents has mostly been about productivity: what they can do, how fast they can do it, what tasks they can take off someone's plate. That framing misses the more consequential shift happening underneath it.


Every AI agent deployed inside a business is a new identity. Not a metaphorical one. A literal, credentialed, permission-bearing identity that authenticates to systems, calls APIs, and takes action, the same way an employee or a service account does. Except most organizations aren't treating it that way.


Machine identities, driven largely by the rise of AI agents, now outnumber human identities in the average enterprise by roughly 45 to 1, according to CyberArk-backed research. That means the vast majority of "identities" operating inside a typical business today aren't people at all. They're software, acting with a scope of access that was often granted quickly, to solve an immediate problem, without much thought given to what happens if that access is ever misused.


Nobody Can Tell the Difference Anymore


Here's the part that should genuinely concern any leadership team paying attention: a recent Cloud Security Alliance survey found that 68 percent of organizations cannot reliably distinguish AI agent activity from human activity in their own logs and monitoring systems.


Think about what that actually means. If an agent starts behaving strangely, querying data it doesn't normally touch, moving faster than any human could, accessing systems outside its usual scope, most security teams have no clean way to notice. The signal is buried inside a stream of activity that looks, on paper, indistinguishable from a person doing their job.


This isn't a small gap. It's the difference between having a security program and having the appearance of one.


Adoption Outpaced Governance, and the Numbers Show It


The State of AI Agent Security 2026 report, which surveyed practitioners directly building and securing these systems, found that only 21.9 percent of teams treat AI agents as independent, identity-bearing entities. The rest either treat them as extensions of a human user or fall back on shortcuts: 45.6 percent still rely on shared API keys for agent-to-agent authentication, and 27.2 percent have reverted to custom, hardcoded authorization logic just to make things work.


Shared credentials and hardcoded logic are exactly the patterns identity security has spent the last decade trying to eliminate from human systems. They're now quietly reappearing in agentic ones, at a pace that outstrips most organizations' ability to notice, let alone fix. A separate analysis found that 71 percent of non-human identities aren't rotated within any recommended timeframe, which means the credentials an agent was issued on day one are often still the credentials it's using months later, unchanged and unreviewed.


The consequences are already visible. Okta's research found that 88 percent of organizations have already experienced an agent-related security incident. Yet only 22 percent treat AI agents as first-class identities within their identity and access management systems. The incidents are outpacing the governance meant to prevent them, not the other way around.


Shadow AI Made the Problem Bigger, Faster


None of this happened in a controlled, top-down rollout. Much of it happened the way shadow IT always has, one well-intentioned employee at a time. The 2026 Verizon Data Breach Investigations Report found that employee use of unapproved AI tools tripled year over year, now affecting 45 percent of the workforce.


Every one of those unsanctioned deployments typically generates its own credentials, stored outside any corporate secrets management policy, never inventoried, and never rotated. It's the same governance gap described above, except this version was never approved, budgeted, or reviewed by anyone in security or IT to begin with.


The cost of getting this wrong is measurable. IBM's 2025 Cost of a Data Breach report found that 97 percent of organizations that suffered an AI-related security breach lacked proper AI access controls at the time of the incident. That's not a coincidence. It's close to a direct correlation between the governance gap and the breach itself.


Leadership Is Starting to Notice, Even If Governance Hasn't Caught Up


There's a genuine shift happening in how leadership teams talk about this, even if the technical controls haven't caught up yet. KPMG's latest AI Pulse Survey found that 80 percent of leaders now name cybersecurity their single greatest barrier to AI strategy, and 75 percent say security, compliance, and auditability are the most critical requirements for any new agent deployment.


That's a meaningfully different conversation than the one happening a year ago, when speed and capability dominated most boardroom discussions about AI. The pendulum is swinging toward scrutiny, largely because the incident data is forcing it to.


What This Actually Means


None of this is an argument against using AI agents. The productivity case for them is real, and the businesses moving fastest on agentic workflows are, in many cases, moving fastest for good reason. But the identity question underneath that adoption curve hasn't been resolved. It's been outrun.


An AI agent with broad, unreviewed, unrotated access to business systems isn't meaningfully different from a former employee whose credentials were never revoked, except that nobody thinks to check on it the same way, because it was never framed as a person in the first place. It was framed as a tool. Tools don't usually get an identity review. Increasingly, they need one.


The businesses that get ahead of this won't be the ones that move slowest on AI adoption. They'll be the ones that started treating every agent as what it actually is: a new identity in the business, with the same scrutiny any other identity would get, from day one.

Share this blog post