A businessman uses advanced AI agent technology and artificial general intelligence (AGI) to perform data analysis

AI Agents Emerge as Top Enterprise Insider Risk Priority

Nearly half of security leaders rank misconfigured or compromised AI agents as their single greatest threat, new research shows.

Enterprise security executives increasingly view autonomous software programs as a primary insider threat to internal systems, according to new global survey findings released by Exabeam.

Data gathered by Sapio Research reveals that 48% of security leaders rank AI agents operating with excessive, compromised or unintended access as the top threat facing their organizations. The risk posed by these autonomous systems outranked concerns regarding external threat actors (28%), compromised human insiders (12%) and malicious employees (12%).

The survey gathered input from 600 decision-makers split evenly between IT security and finance roles across seven countries. In the report, titled The Agentic Insider: From Monitoring to Understanding, AI agents are defined as goal-driven, autonomous systems capable of accessing enterprise resources and taking action with limited human intervention.

While organizations report expanding their monitoring coverage (specifically, using dedicated AI security tools, extending existing security information and event management systems or deploying behavioral baselining), technical gaps remain widespread.

A lack of behavioral context and event correlation was identified by 27% of respondents as the single largest weakness in their current monitoring strategy. Because AI agents hold legitimate operational credentials to navigate enterprise systems, individual routine actions can obscure unauthorized or anomalous activity over time.

The report also highlights operational friction between security operations and financial leadership. Although 93% of respondents stated that security and finance teams align on overall risk tolerance, 55% of security leaders admitted to delaying or scaling back key initiatives. The primary barrier cited was an inability to articulate technical cyber risk in measurable financial terms necessary for chief financial officer approval.

About the Author

Jesse Jacobs is assistant editor of SecurityToday.com.

Featured

New Products

  • Squire Vulcan Combination Padlocks

    Squire Locks USA Vulcan™ Resettable Combination Padlocks

    Stop competing with flimsy, retail-grade hardware—Squire's professional-grade resettable padlocks deliver heavy-duty boron steel shackles and front-facing dials for rugged outdoor environments.

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises.

  • ADI Control4 product image

    ADI Control4® X4 & Control4® Connect

    Drive long-term system value and reduce post-installation friction with a visually redesigned control interface paired with a secure, future-ready smart service framework.