Council Post: Your Next Insider Threat Won’t Be Human: The Risks Of Agentic AI

Morey J. Haber, Chief Security Advisor at BeyondTrust, is an identity and technical evangelist with over 25 years of IT industry experience.

getty

​For decades, information security teams have treated insider threats as a human problem: the disgruntled employee copying files to a USB drive, the administrator abusing privileged credentials or a contractor with over-privileged access to systems and data. Every one of these scenarios rests on the same assumption—that the threat actor is a person. That assumption is no longer true.

With the rapid adoption of autonomous and semi-autonomous AI agents, organizations now have to defend against a new category of insider threats that can operate just like a human, but at machine speed.

Agentic AI systems, designed to perform tasks independently across enterprise systems, are beginning to proliferate and behave like privileged insiders across entire ecosystems and beyond the trusted environments security professionals have struggled so long to protect. These systems can authenticate to services, access sensitive data, trigger workflows, connect to third-party data sources and interact with infrastructure with little or no human intervention. Simply put, agentic AI is quietly becoming one of the most powerful insiders in the enterprise (with a 466.7% year-over-year increase in AI agents operating inside enterprise environments), and most organizations still have no plan to govern and secure it.

Every Agent Is A Privileged Identity

Agentic AI is fundamentally different from traditional automation solutions. Scripts and bots historically executed narrow, predictable tasks under strict controls. Agents, by contrast, can reason, make decisions and interact across many systems dynamically, and to do that they need identities: API tokens, service accounts, machine identities, cloud roles, human impersonation or delegated credentials. Once provisioned, an agent can move through an environment exactly the way a human user would, but with far greater speed, scale and autonomy.

Consider an agent tasked with analyzing customer data. It might access CRMs, ERPs, cloud storage buckets and other agents in a single run. Each request looks legitimate and authenticated. From a cybersecurity perspective, the entire transaction appears normal and is indistinguishable from a potential threat.

Now imagine that same agent, compromised or manipulated, querying every past-due invoice armed with full client details. That output could easily feed a fully automated phishing campaign with fraudulent payment terms and attacker-controlled bank accounts. An old attack vector can now become autonomous, and no one may notice until the money is gone.

The real risk here is the combination of privilege access and autonomy. Every insider threat program is built to control access: least privilege, access reviews and monitoring. Yet when teams deploy agents, they routinely bypass those guardrails for the sake of speed, granting broad entitlements so the agent simply plugs in and works immediately.

The result is a population of super-users: excessive cloud permissions, long-lived API tokens and secrets stored insecurely in code. And because attackers know this, they’ve shifted their aim. Rather than phishing a person, they target the agent—through prompt injection, poisoned data, compromised plug-ins or stolen credentials. Once they control the agent, its privileges become theirs. The insider threat has been outsourced to automation, often using the enterprise’s own tools, with no malware required.

Traditional Identity Tooling Was Built For Humans

This is where many security programs break down. Machine identities, service accounts and API keys already outnumber human users in nearly every organization, and each new agent adds another—with its own permissions, tokens and connectors.

Traditional identity governance was designed around the employee life cycle: joiners, movers and leavers. Agents don’t follow those rules. They can be created instantly, cloned across environments and embedded into applications without security teams’ visibility. The life cycle model that has anchored identity governance for 20 years simply doesn’t match how agents behave. So, where do security professionals go from here?

Governing The Agent Workforce

The next evolution of insider threat management must account for this invisible, fast-moving workforce. The good news is that the controls already exist. They just need to be pointed at agents.

Here are a few priorities for security leaders to consider:

Treat every agent as a privileged identity. Assign each one a human owner or accountable department, a logged and audited identity and an explicit, documented purpose with defined paths to privileged access. Any deviation from that purpose is an indicator of compromise.

Eliminate standing privilege. Agents should never store static credentials in code repositories or configuration files. Replace long-lived secrets with dynamically issued, just-in-time credentials that expire the moment a task completes—so a compromised agent can’t become a persistent insider threat.

Monitor behavior, not just access. Agents generate telemetry like any other system: access logs, API calls, system modifications and data transfers. Baseline what normal looks like and alert on the anomalies—an agent suddenly pulling a large database dump, operating off-hours or reaching resources outside its defined scope should be investigated immediately.

None of this requires slowing AI adoption. It just requires hardening identity governance—the one control plane capable of managing systems that operate at machine speed across the entire enterprise.

The Security Perimeter Has Permanently Shifted

AI agents aren’t inherently dangerous, and they will likely become one of the most powerful productivity tools enterprises have deployed since the personal computer. But security has to evolve with them to prevent unmanageable sprawl and workloads.

The enterprise perimeter is no longer defined by users and devices; it’s defined by identities, privileges and automated systems making decisions inside and outside security infrastructure. If organizations treat agents as simple tools, they'll miss the real risk. If they recognize each agent for what it is—a privileged actor inside the network—they can build the governance models necessary to maintain control and power innovation.​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?