Yahoo
Skip to main content
Advertisement
Advertisement
Advertisement
Advertisement

AI Agents Aren't Creating Security Problems. They're Revealing Them.

Locks Security System Concept

Most of what's exposed with AI agents was already broken before AI showed up.

Getty Images

Leaders worry that AI agents will introduce entirely new cybersecurity threats . In reality, the biggest risk isn't what AI creates , but what it reveals. While AI agents don't invent weak governance or poor access controls, they do expose years of accumulated organizational shortcuts, or tech debt, that people learned to work around. AI can exploit those shortcuts at machine speed.

In many organizations, access controls have quietly deteriorated over time. Permissions get copied from one employee to the next, people change roles without losing old access and files are shared "temporarily" but never reviewed. AI agents don't create these problems, but they do remove the friction that once kept sensitive information buried, surfacing it instantly in search results, summaries and prompts.

Imagine all the prompts handed to AI agents across an entire organization in a single day, and you can start to comprehend the scope of the security risk. Gartner predicts that 40% of enterprise applications will be integrated with task-specific AI agents by the end of 2026, up from less than 5% in 2025. Governance hasn't come close to keeping pace.

Advertisement
Advertisement

That security gap is already costing companies. IBM's Cost of a Data Breach Report 2025 found that one in five organizations experienced a breach linked to shadow AI. Those incidents added as much as $670,000 to the average cost of a breach, while hitting customer data and intellectual property especially hard. Further, 63% of the breached organizations had no AI governance policy, while only 37% had approval processes in place before employees started using these tools.

AI Agents Expose Two Governance Gaps

To close the security gap with AI agents, leaders first need to recognize that there are actually two gaps at play.

The first is organizational. Most companies haven't redesigned governance for a workforce that now includes AI agents, or they never had true governance implemented at all and now have to start from scratch. Security breaches involving AI agents rarely occur because someone behaves recklessly. It's the same story behind every shadow IT problem companies have struggled with for decades: The business needed something, the official channel was slow to deliver it, and employees found a faster way without realizing the security implications.

The second security gap is overly permissive systems. If a laptop lets someone install a plugin or upload a file to an outside AI tool with no friction, somebody will use it. This happens not out of malice or negligence but just because it's there and it offers a quick solution.

Advertisement
Advertisement

In short, closing the organizational gap without closing the technical one, or vice versa, leaves the door half-shut. Leaders need to focus on both to get the value out of AI agents without the big liabilities.

The New Hire Standard For AI Agents

One solution to the AI agent cybersecurity problem : Treat agents like new hires, not another piece of software.

You wouldn't hire someone, give them unrestricted access to every system in the company, decline to assign them a manager, and never review their work. Yet that's remarkably close to how many organizations deploy AI agents today.

Instead, give every agent a scoped role, not blanket access. Match its permissions to the specific function it performs, and nothing more.

Advertisement
Advertisement

Second, name a human owner paired with every AI agent. As agents start triggering other agents, every action needs to be traceable back to a human who's accountable for what happens.

Third, give agents the least possible privilege to do the assigned task. Often, this means less—not equal—access than the person responsible for overseeing the agent's output.

This is the part people get wrong most often. Imagine an AI agent with permission to search SharePoint. It doesn't know that the compensation spreadsheet sitting next to the sales forecast wasn't intended for this task. It simply sees data it's authorized to retrieve. That's why an agent often needs less access than the employee it's supporting.

Finally, review the AI agent on a schedule. A Cloud Security Alliance Survey found that 68% of organizations can't reliably tell AI agent activity apart from human activity in their own systems.

Advertisement
Advertisement

Here's a simple test my company's security team uses with clients to gauge agent governance: Could someone on your team explain what a given agent did last Tuesday, who it was acting for, and why it was allowed to take that action? If the answer is no, you don't have an AI problem , but you do have a governance problem, and the agent just happened to be what surfaced it.

AI agents may feel cutting-edge but the same security fundamentals apply. Identity management, data governance and access controls are more important than ever.

AI Agents Expose What Was Already Broken About Your Cybersecurity

Most of what's exposed with AI agents was already broken before AI showed up. Access copied from one person to the next, filed shared "just for now" three years ago and never revisited, a role change that never triggered a permission review—all those small things add up to a lot of cybersecurity risk once AI agents are let loose.

The big takeaway is that AI amplifies whatever's already at an organization, for better or worse. Strong cybersecurity governance becomes stronger, and weak governance becomes more dangerous.

Advertisement
Advertisement

None of this is an argument for moving slower. Trusting people, giving them clear expectations and treating them like responsible adults is what lets organizations move fast without falling apart. AI doesn't change that equation, but it does raise the stakes on doing it well.

This article was originally published on Forbes.com

Advertisement
Advertisement
Mobilize your Website
View Site in Mobile | Classic
Share by: