Cyber SecurityAI & Technology

Adapting Identity Security as AI Agents Reshape the Threat Landscape

By Sarah Cecchetti, Director, Semperis

When the UK’s National Cyber Security Centre (NCSC) releases guidance about a new technology, it’s usually a sign of mainstream adoption. So its publication in May of a new set of best practices for agentic AIis something of a milestone. A few months prior, at the tail end of 2025, McKinsey reported that 62% of organisations were experimenting, piloting or scaling projects. 

Yet with new opportunities come new risks. Recent research reveals that three-quarters (74%) of organisations are concerned that AI in general will increase the frequency of attacks on the identity infrastructure.Tackling these risks must be a priority for IT and security leaders.  

Businesses are moving fast. If security isn’t baked into projects today, they could be storing up problems for tomorrow. 

What could go wrong? 

The NCSC urges organisations to think before they deploy. To consider what might go wrong, reflect on whether agents are even needed, and start projects with “tightly bound pilots”. Unfortunately, it appears that many enterprises are jumping straight in and deploying the technology in high-risk areas.  

Semperis’ study finds that 29% of organisations are using AI agents to handle security-related help desk tickets, including password resets and VPN access. And a further 64% intend to do so within the year. Nearly all have installed AI on at least some local machines where they can access SSH and encryption keys. This should make security teams extremely nervous.  

Without the right governance and monitoring in place, it’s easy to see how bad things could happen. Agents might be “socially engineered” through malicious prompts to assist an adversary with reconnaissance, data exfiltration, persistence or any number of malicious actions.  

Even benign agents can go rogue if strict guardrails aren’t in place – causing glitches, data leaks and other unintended outcomes. In a much-publicised recent incident, the founder of developer PocketOSclaimed a Claude-powered version of AI coding tool Cursor deleted his production database in just seconds.  

Identity security takes centre stage 

Identity security is fundamentally at the heart of these security challenges. Agents, low-code helpers, service principles and the like have non-human identities (NHIs). This helps to cement accountability and enables them to perform key tasks, like accessing resources and interacting with other systems. But when those identities are over-permissioned, things can go wrong.  

Over permissioning turns a hijacked or hallucinating agent from a nuisance into a security risk. It increases the blast radius of attacks and makes pinpointing the cause of incidents harder. A compromised agent could provide an attacker with access to local SSH keys, password managers and browser sessions. It could be used to reach identity controllers and modify policies, groups or conditional access to achieve any manner of adversarial goals.  

Do you know where your agents are? 

Shadow AI compounds these risks, because security teams can’t protect (or govern) what they can’t see. Local agent harnesses can operate through browser sessions, local credentials and endpoint access in ways that are much harder to observe centrally. Two-thirds (65%) of organisations say they fully register, authenticate and authorise AI identities in a formal system. That leaves a sizeable share which don’t. 

There are other governance risks. The survey found that over half (57%) of organisations use the same system for human and AI identities. Yet human identity systems are built around relatively stable identities with durable roles, approvals and audit patterns. Agents, on the other hand, are short-lived, highly dynamic and often task scoped. That makes human-style provisioning too slow and too coarse. 

Taking back control 

Fortunately, there are things every organisation can do today to improve oversight of their agentic fleet. First, treat agents as NHIs rather than the same as human identities. This will help to clarify and de-risk ownership, registration, lifecycle and decommissioning. 

Enforce least privilege, and just enough/just-in-time access for agents in the same rigorous manner as for human identities. This will add some zero-trust best practice to the NHI environment and mitigate the risks associated with malicious and unintended behaviour. 

Follow this by segregating agent and human trust boundaries.Don’t let a lowly AI assistant inherit the same trust assumptions as a human admin. And don’t let recovery depend on the same identity-linked automation that may already be compromised. 

Next, layer on top enhanced monitoring via behavioural analytics to detect anomalous agent behaviour and zombie agents. This means that when something bad happens, the organisation can respond and contain the incident. 

Finally, ensure the organisation can recover identity systems swiftly to a trustworthy state if a breach does occur. These Tier-0 systems are a critical part of minimum viable operations for all enterprises. Prepare and practise for the worst. 

Much of this echoes the advice of the NCSC. As does the most important rule: If you can’t understand, monitor or contain an agent’s actions, don’t deploy it.  

Author

Related Articles

Back to top button