CyberArk Warns Autonomous AI Agents Create Systemic Insider Threats
CyberArk CIO Omer Grossman warns that autonomous AI agents acting as credentialed corporate actors create significant third-party risks and insider threats.
Chief Information Officer at CyberArk Omer Grossman warns that autonomous AI agents are introducing systemic third-party risks and insider threats by operating as credentialed actors within corporate environments. These agents can execute complex tasks, including provisioning cloud resources and updating records, without human intervention.
Grossman identifies the Model Context Protocol (MCP) as a standardized integration method that reduces friction but simultaneously widens the potential attack surface. He argues that the primary danger has shifted from data poisoning to autonomous execution at scale. This risk is compounded by a gap in corporate security; CyberArk research indicates that while 72% of employees use AI tools at work, 59% of organizations lack the necessary identity controls to manage them.
To mitigate these threats, Grossman advocates for an identity-first defense strategy. This approach includes tracking live agents, limiting access to integration points like MCP, and establishing dynamic behavioral controls. These warnings align with concerns from OpenAI CEO Sam Altman, who has also cautioned that granting AI agents excessive access is dangerous.