AI Agents Pose New 'Synthetic Insider Threat' to Organizations
A new report by Israeli cybersecurity firm Above Security identifies 166 ways artificial intelligence agents can pose a risk to organizations, creating a new category of threat dubbed 'synthetic insider threats.' Unlike traditional insider threats, which involved human employees with malicious intent, these AI agents operate with employee credentials and at machine speed, often without direct human oversight or interview. The report, developed by Nimr Keiss and Yonatan Malka of Above Security, highlights that AI agents can be manipulated or malfunction, leading to data breaches, unauthorized access, or system disruptions, even without malicious intent.
Data from Verizon and Palo Alto Networks indicates a significant increase in AI usage within the workplace, with 45% of employees regularly using AI tools on work devices, and a majority of this usage occurring through personal accounts. Alarmingly, only 30% of organizations maintain immutable logs of AI agent activities, meaning most AI operations are conducted under unmanaged identities and are difficult to trace. The report outlines four scenarios where AI agents can go awry: a compromised internal AI assistant, an agent tricked by hidden instructions in documents, an over-privileged personal AI tool, or a 'poisoned memory' where malicious instructions persist across sessions.
Above Security also points to five warning signs of rogue AI agents: non-human activity rates under a human identity, outbound traffic to unknown destinations, access exceeding requested permissions, discrepancies between reported success and actual system status, and a single identity operating from multiple locations simultaneously. To mitigate these risks, the company recommends assigning unique, time-limited identities to AI agents, granting permissions strictly based on task requirements rather than employee roles, treating all content read by an agent as data for processing rather than commands, requiring human approval for irreversible actions, and maintaining robust, immutable logs of all agent activities.
Guy Kozliner, CEO of Rig Security, a company that recently raised $12 million for its AI agent identity protection platform, echoed these concerns. He stated that traditional authentication methods are insufficient as AI agents can operate under legitimate employee accounts. Kozliner warned that the number of AI agents is projected to skyrocket, with Fortune 500 companies expected to deploy over 150,000 AI agents by 2028, underscoring the urgent need for organizations to establish control and oversight mechanisms for these powerful tools before their capabilities outpace management abilities.
The same event, reported separately by each outlet. Open a few to compare what different newsrooms emphasize — and what they leave out.
Not the same event — other stories that share this one’s people, places, or theme: background, reactions, and follow-ups.
Ask About This Article
Duki reads it, and every newsroom on the same story, then answers with sources.