AI Business

AI Agents Pose New Insider Risk as Companies Struggle With Scale and Control

As enterprises deploy AI agents that operate across systems and delegate tasks to other agents, security teams face a fundamental challenge: visibility and permission limits are no longer enough. Companies must now plan for recovery from actions agents have already taken.

·3 min read
AI agents creating a new insider security risk: theCUBE’s Oktane keynote analysis
AI agents creating a new insider security risk: theCUBE’s Oktane keynote analysis

The security challenge posed by AI agents extends beyond initial access control. Once deployed, these systems can operate across multiple applications, hand off work to other agents, and execute changes at speeds that outpace security team review cycles. This creates what Krista Case, principal analyst at theCUBE Research, describes as a new category of insider threat.

What's interesting here is that as enterprises are adopting AI, they're creating this whole new form of insider risk in the form of these AI agents. In some ways, that might even be a bigger long-term threat to the organizations than what these adversaries are doing with AI.

Krista Case, theCUBE Research

Case shared these observations during an exclusive broadcast at Okta's Oktane event, where she and fellow host Rebecca Knight examined how organizations can govern AI agents and respond when their actions cause damage. Okta's framework addresses three core areas: locating agents within an environment, understanding their capabilities, tracking their runtime behavior, and implementing response measures.

Recovery requires more than revoking access

Simply stopping an agent does not undo its prior actions or prevent cascading effects through connected systems. Case highlighted this critical gap in current approaches.

The kill switch, it revokes the authority and it stops the AI agent from taking any future actions. It doesn't necessarily account for what the agent may have already changed, what other downstream actions it might have triggered.

Krista Case

The problem compounds when agents delegate tasks to other agents. A complete response may require identifying every affected system and restoring them to a known good state, rather than simply cutting off one agent's permissions. Additionally, each agent needs explicit human ownership and permissions matched to its specific function, rather than inheriting all access rights from the human user who created or manages it.

Who is the human that's responsible for this AI agent at the end of the day. We need to make sure that the AI agent doesn't just automatically inherit all of the access and permissions that the human does.

Krista Case

Discovery reveals massive oversight gaps

The sheer number of agents operating in enterprise environments is already exposing control weaknesses. A financial asset management firm discovered approximately 13,000 agents within its infrastructure, yet classified only 1,000 as legitimate. This discrepancy points to agents being deployed outside formal IT governance channels.

This company, in their environment, they discovered approximately 13,000 agents, and they considered only 1,000 of those valid. It kind of shows that upfront discovery piece of the conversation. It really reflected, I think, especially in some of these larger environments, the scale of the problem that we're dealing with.

Krista Case

Finding agents represents only a starting point. Agent activity frequently spans multiple vendors' systems, creating visibility challenges across platform boundaries. Okta's Blueprint Alliance seeks to establish common standards for access management, task delegation, and activity monitoring across vendors. Shared data signals could help clarify agent intent and actions, though questions remain about authority when different platforms provide conflicting recommendations.

https://www.youtube.com/embed/Wea55Yw3dWU?feature=oembed

I do think that this sharing of telemetry, this interoperability, I do think that it matters. I think it's a really important initiative. What I am interested to see as it gets rolled out and as we start to talk with customers about it is if there … conflicting insights across these platforms about an action that needs to be taken. For example, who is going to have the authority at the end of the day and where is that authority going to live in this tech stack?

Krista Case