By Andrew Hartnett
Publication Date: 2025-11-20 02:08:00
The next security breach may not come from a hacker at the gates, but from an AI agent already on your network. Only it wasn’t planted by a cybercriminal – you deployed it. Maybe it’s to summarize meetings, review service tickets, or help developers ship code faster. Whatever it does, it acts autonomously, accessing resources, making decisions, and crossing trust boundaries without friction. This makes it both an asset and a liability. Because unlike human users, these AI agents do not log in, request access through formal channels, and do not always have a clear owner.
This is the new face of the insider threat. It is not malignant, but is often overlooked. Most organizations now have hundreds, sometimes thousands, of non-human identities (NHIs) operating across cloud services, APIs and internal systems. By some estimates, they may outnumber human users by 45:1 in DevOps environments alone, but the ratio across the organization is likely…



