← Back to list

Why Your AI Agents Are Your Newest Insider Threat

The insider threat problem just got bigger — and the newest insider doesn’t have a badge. Rick Hemsley, UK and Ireland Cybersecurity…

Forcepoint in Force Multiplier · 2026-05-11 20:54 · 0 claps · 2.3 min read
#security-leadership #ai-governance #cyber-resilience #emerging-threats #insider-risk
Open on Medium ↗
Wiki topics: AGT · AI Agents BIZ · Business Strategy 🔒 · Cybersecurity 🚀 · Self Improvement

Why Your AI Agents Are Your Newest Insider Threat

The insider threat problem just got bigger — and the newest insider doesn’t have a badge. Rick Hemsley, UK and Ireland Cybersecurity Consulting Leader at EY, joined the latest episode of the To the Point Cybersecurity Podcast with a reframe that every security leader needs to sit with: AI agents aren’t just tools. They’re entities operating inside your environment, touching your most sensitive data, making decisions on your behalf and capable of being turned against you.

Most organizations haven’t updated their threat model to reflect that yet.

[embed]

The numbers are already uncomfortable

EY’s research finds that half of all organizations have already been negatively impacted by AI-introduced vulnerabilities, with average losses of $4 million per incident. At the same time, 68% of companies still allow employees to build and deploy AI agents with little to no oversight. This isn’t a risk on the horizon. It’s a risk that’s already inside the building.

What an AI insider threat actually looks like

The threat isn’t an agent malfunctioning. It’s an agent doing exactly what it was instructed to do — by the wrong party. Through prompt injection, poisoned inputs or supply chain attacks on the models and components an agent depends on, a compromised agent can exfiltrate data, manipulate workflows or relay false information downstream, all while appearing to operate normally. As Hemsley puts it, those agents “are a potential insider risk” and should be treated accordingly.

Your insider threat program needs to cover non-human identities

Insider threat programs were built around people, but the underlying framework applies directly to agents. What does this entity have access to? Does it still need that access? What is it doing with it, and is that behavior consistent with its intended purpose? The same questions you’d ask about a privileged user or a new contractor apply to every agent operating in your environment. Identity isn’t just human anymore, and access governance shouldn’t be either.

The governance gap is what makes this exploitable

Hemsley describes a three-layer gap: business innovation moving fastest, IT lagging behind it, security lagging further still. Threat actors operate in that gap. Agents are being deployed at the speed of business decisions, not security reviews, and the distance between those two speeds is growing. Legacy controls weren’t built for this environment, and relying on them while the gap widens is its own form of risk.

What to do right now

Treat your agents like identities, not applications. Map what they have access to and apply least-privilege principles as strictly as you would for a human user. Build behavioral monitoring into agent workflows and watch for anomalies in how agents interact with data and with each other. Keep humans in the loop at high-stakes decision points — machine speed is necessary in some places, but judgment still matters where the consequences of a wrong decision are significant.

The organizations that treat AI agents as trusted insiders with unchecked access will be the ones learning expensive lessons. Extending existing risk thinking to cover non-human identities isn’t a future agenda item. It’s the work in front of you now.

Listen to the full conversation with Rick Hemsley on Episode 361 of the To the Point Cybersecurity Podcast.


메타데이터
post_id
65200d319bfe
slug
why-your-ai-agents-are-your-newest-insider-threat-65200d319bfe
url
https://medium.com/forcepoint-security/why-your-ai-agents-are-your-newest-insider-threat-65200d319bfe
canonical_url
https://medium.com/forcepoint-security/why-your-ai-agents-are-your-newest-insider-threat-65200d319bfe
author_url
https://medium.com/@forcepoint-security
status
ok
fetched_at
2026-06-14 11:28:49