AI Agents Are Creating Insider Security Threat Blind Spots, Research Finds

Only 30% of US businesses are actively mapping which AI agents have access to critical systems, creating a security blind spot.

執筆者
Fiona Jackson
Fiona Jackson
Published: Jun 27, 2025
Updated: Jul 2, 2025
3 minute read
eSecurity Planet のコンテンツおよび製品のおすすめは、編集上の独立性を保っています。パートナーへのリンクをクリックすると、当社が報酬を得る場合があります。 詳細を見る

This article was originally published on TechRepublic.

Artificial intelligence agents, autonomous software that performs tasks or makes decisions on behalf of humans, are becoming increasingly prolific in businesses. They can significantly improve efficiency by taking repetitive tasks off employees’ plates, such as calling sales leads or handling data entry.

However, by virtue of AI agents’ ability to operate outside of the user’s control, they also introduce a new security risk: Users may not always be aware of what their AI agents are doing, and these agents can interact with each other to expand the scope of their capabilities.

This is particularly problematic when it comes to identity-based threats. New research from security firm BeyondID has found that US businesses are often allowing AI agents to log in, access sensitive data, and trigger actions independently. Despite this, only 30% are actively identifying or mapping which AI agents have access to critical systems, creating a security blind spot.

The survey of US-based IT leaders revealed that many are concerned about the security implications of introducing AI agents into workflows. The top threat plaguing their minds, as cited by 37% of respondents, is AI impersonation of users. This is likely related to the numerous high-profile scams that have resulted in substantial financial losses.

If not properly secured, malicious actors can spoof or hijack a business’s AI agents to mimic trusted behaviour, tricking systems or users into granting unauthorised access or executing harmful actions. Nevertheless, the BeyondID research revealed that only 6% of leaders consider securing non-human identities to be among their top security challenges.

“AI agents don’t need to be malicious to be dangerous,” the report states. “Left unchecked, they can become shadow users with far-reaching access and no accountability.”

This industry is a particular risk for the security threat

The healthcare sector is particularly at risk, as it has rapidly adopted AI agents for tasks like diagnostics and appointment scheduling, yet it remains highly vulnerable to identity-related attacks. Of the IT leaders surveyed who work in healthcare, 61% said their business had experienced such an attack, while 42% said they had failed a compliance audit related to identity.

Advertisement

“AI agents are now handling Protected Health Information (PHI), accessing medical systems, and interacting with third parties often without strong oversight,” the researchers wrote.

At the end of 2024, TechRepublic predicted that the use of AI agents would surge this year. OpenAI CEO Sam Altman echoed this in a January blog post, saying, “We may see the first AI agents ‘join the workforce’ and materially change the output of companies.” Just this month, the CEO of Amazon hinted that future job cuts may result from the deeper integration of advanced AI agents.

OpenAI and Anthropic are both investing heavily in expanding the capabilities of their agentic products, with Altman trumpeting their snowballing levels of power. By 2028, 33% of enterprise software applications will include agentic AI, up from less than 1% in 2024, according to Gartner. 

However, some organisations don’t want to take the security risk, with the European Commission banning the use of AI-powered virtual assistants during online meetings.

Fiona Jackson

Fiona Jackson is a news writer who started her journalism career at SWNS press agency, later working at MailOnline, an advertising agency, and TechnologyAdvice. Her work spans human interest and consumer tech reporting, appearing in prominent media outlets such as TechHQ, The Independent, Daily Mail, and The Sun.

eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

TechnologyAdvice が所有・運営しています。 © 2026 TechnologyAdvice. 無断転載を禁じます

広告主に関する開示:このサイトに掲載されている製品の一部は、TechnologyAdvice が報酬を受け取っている企業のものです。この報酬は、製品がこのサイトのどこにどのように表示されるか(表示される順序など)に影響する場合があります。TechnologyAdvice は、市場で入手可能なすべての企業やすべての種類の製品を掲載しているわけではありません。