Dive Brief:
-
AI agents are outpacing the ability of existing security systems to manage them, according to a new report by IDC and GuidePoint Security. In some environments, non-human identities are outpacing human identities at a ratio of 75 to 1, the report showed.
-
Non-human identities were the initial entry point in 19% of the security incidents cited by about 650 organizations that reported a confirmed incident. That percentage is effectively the same as the 19% of organizations that cited phishing or stolen credentials as the initial entry point.
-
Nearly eight of every 10 respondents claimed to have high confidence or very high confidence in their ability to see all human and non-human identities across on-premises, cloud and software-as-a-service environments. Yet more than four out of 10 identified inventory or ownership gaps as a top challenge.
Dive Insight:
The security of non-human identities has emerged as a rapidly increasing challenge in organizations across the U.S. As companies face increased pressure to accelerate the use of AI agents, they often lack the proper tools or governance designed to make sure they are operating in a secure environment.
Respondents in many cases said they could not provide an exact count of how many agents they had in their environments, according to the report. They also are having difficulty with managing privileges.
Only 18% of respondents are enforcing least-privilege using just-in-time access with automatic remediation, according to the report. Just-in-time access allows an AI agent only the minimal access it needs for the immediate task in front of it.
The report comes at a sensitive time for the AI industry. Leaders from the major companies are calling for governments to help develop some form of security guardrails, following incidents where AI models broke containment in test environments and launched attacks against outside organizations.
Researchers also warn that malicious state and criminal actors are also using AI to accelerate their attack speeds and capabilities. Recent attacks show that AI is being used to find new vulnerabilities, develop exploits and explore new attack patterns at speeds beyond the ability of security teams to track.
The report is based on a series of surveys by IDC, which included more than 2,500 respondents.