AI Agents Become Key Focus for Managing Insider Risk in Enterprises -- Security Today

AI Agents Become Key Focus for Managing Insider Risk in Enterprises -- Security Today
Summary
Nearly 50% of security leaders view compromised AI agents as their greatest insider threat.
Most organizations face technical gaps in monitoring autonomous AI systems and behaviors.
Security and finance teams often misalign, impacting key initiative implementations and approvals.

Share

Bookmark

Newsletter

Recent research indicates that nearly half of security professionals regard misconfigured or compromised AI agents as their most significant threat, reflecting a shift in how enterprise security is perceived.

As reported in a global survey conducted by Exabeam, executives responsible for enterprise security are increasingly identifying autonomous software programs as major insider threats to their organizational infrastructure. According to data from Sapio Research, 48% of security leaders identified AI agents that possess excessive, compromised, or unintended access as the foremost risk to their companies. This concern surpasses the risks associated with external attackers (reported at 28%), compromised human insiders (12%), and malevolent employees (12%).

The survey solicited insights from 600 decision-makers, evenly split between IT security and financial roles across seven different countries. The findings are detailed in a report titled "The Agentic Insider: From Monitoring to Understanding," which characterizes AI agents as autonomous, goal-driven systems capable of accessing enterprise resources and executing actions with minimal human oversight.

While organizations are reportedly broadening their monitoring efforts—such as applying dedicated AI security tools, enhancing existing security information and event management systems, or implementing behavioral baselining—significant technical deficiencies persist.

27% of respondents pointed to a lack of behavioral context and event correlation as the most substantial weakness in their existing monitoring strategies. Because AI agents often possess valid operational credentials to operate within enterprise systems, typical actions can mask unauthorized or atypical activities over time, complicating threat detection.

The report also underscores a disconnect between security operations and financial executives. Although an impressive 93% of participants stated that security and finance teams are aligned on general risk tolerance, 55% of security leaders acknowledged that they have postponed or scaled back crucial initiatives. The main obstacle identified was the difficulty in expressing technical cyber risks in quantifiable financial terms that are necessary for obtaining approval from chief financial officers.

Loading comments...