BeyondTrust Warns Agentic AI Creates New Enterprise Insider Threats
Morey J. Haber of BeyondTrust warns that autonomous AI agents are creating high-risk privileged insider threats through a 466.7 percent increase in enterprise adoption.
Morey J. Haber, Chief Security Advisor at BeyondTrust, warns that the rapid adoption of agentic AI is creating a new category of insider threats within enterprise environments. These autonomous and semi-autonomous AI agents differ from traditional automation because they can reason, make decisions, and interact across multiple systems using privileged identities like service accounts and API tokens.
Haber reports a 466.7 percent year-over-year increase in AI agents operating inside enterprises. Many of these agents are granted broad entitlements that bypass traditional security guardrails, effectively creating super-users. This vulnerability allows attackers to gain privileged access without using malware by targeting agents via poisoned data or prompt injection.
To mitigate these risks, Haber recommends treating every AI agent as a privileged identity with a designated human owner. He suggests replacing static credentials with just-in-time access and shifting security focus toward monitoring behavioral anomalies rather than relying solely on access logs.