Security leaders are increasingly concerned about the risks posed by both human insiders leveraging AI tools and the rise of autonomous AI agents within organizations. Employees, including senior staff, are frequently using unapproved AI services to accelerate their work, inadvertently exposing sensitive data and creating compliance gaps that may go undetected by security teams. Additionally, hostile actors are exploiting AI to fake credentials, gain trusted roles, and move laterally within corporate networks, further complicating insider risk management.
At the same time, the rapid adoption of AI agents is transforming the insider threat landscape, with predictions that 40% of enterprise applications will integrate task-specific AI agents by the end of 2026. While these agents can help address cyber-skills shortages and automate security tasks, they also introduce new risks as potential insider threats themselves. Security teams face mounting pressure to quickly vet and secure these technologies, balancing the benefits of increased productivity and strategic defense with the need for robust oversight and risk mitigation.

See attribution, scope, and your downstream exposure.
2 events from the most recent confirmed update back to the earliest known activity.
UpGuard's Greg Pollock warned that organizations face insider risk both from employees using unapproved AI tools and from hostile actors using AI to fake credentials and gain trusted positions. He said these practices can expose data and create legal and compliance gaps, and urged better visibility, reporting, and employee education.
Palo Alto Networks Chief Security Intel Officer Wendi Whitmore said AI agents are emerging as a significant insider threat as enterprise adoption accelerates. She warned that privileged access, prompt-injection weaknesses, and the 'superuser problem' could create new attack paths and called for least-privilege access and stronger controls.
See attribution, scope, and whether this vendor sits anywhere in your supply chain.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.