Leadership1 distinct publisher3 min readUpdated
BeyondTrust's Morey Haber counts a 466.7% year-over-year rise in AI agents inside enterprises. They authenticate, hold privileges and move data, and insider-threat programs still assume a human.
The Board Room · Leadership desk

Compiled by The Board RoomSomething wrong?How this is made
A Forbes Tech Council column by Morey J. Haber, chief security advisor at BeyondTrust, argues that the entire insider-threat discipline rests on one assumption, that the threat actor is a person, and that the assumption has stopped being true [1][2]. The figure he attaches to it is a 466.7% year-over-year increase in AI agents operating inside enterprise environments [3], which works out to an agent population roughly 5.7 times what it was a year earlier [4].
The operational point is not that agents are clever. It is that they need credentials to do anything at all. Haber notes that agents authenticate to services, reach sensitive data, trigger workflows, connect to third-party sources and touch infrastructure with little or no human involvement [5], and that to do so they are issued API tokens, service accounts, machine identities, cloud roles, delegated credentials or the ability to impersonate a human [6]. Once provisioned, an agent moves through the estate the way a staff member does, with more speed and scale [7]. That is a headcount decision made by an engineering team, usually without an onboarding review.
His worked example is unremarkable, which is the problem. An agent asked to analyse customer data may hit CRMs, ERPs, cloud storage buckets and other agents in a single run, with every request properly authenticated and, from the monitoring side, indistinguishable from an attack [8]. Turn that same agent, and it can pull every past-due invoice with full client detail, which feeds an automated phishing campaign carrying fraudulent payment terms and attacker-controlled bank accounts [9]. Attackers have adjusted accordingly, going after the agent through prompt injection, poisoned data, compromised plug-ins or stolen credentials, because the agent's privileges become theirs and no malware is required [10].
The privilege posture is self-inflicted. Haber writes that teams routinely bypass the guardrails their own insider programs mandate, least privilege, access reviews and monitoring, granting broad entitlements so the agent plugs in and works immediately [11][12]. The residue is a super-user population: excessive cloud permissions, long-lived API tokens and secrets sitting in code [13].
The governance gap is structural rather than cultural. Machine identities, service accounts and API keys already outnumber human users in nearly every organisation, and each new agent adds more [14]. Identity governance, meanwhile, has been anchored for twenty years to the employee life cycle of joiners, movers and leavers [15][16], and agents do not observe it: they can be created instantly, cloned across environments and embedded into applications without the security team seeing it [17]. An agent nobody enrolled cannot be reviewed, and cannot be offboarded. Haber's position is that the controls needed already exist and simply have to be aimed at agents [18].
What to watch is whether anyone can produce a number. Ask for the count of agent identities in production, who owns each one, what entitlements it holds and what expires those entitlements; a firm that cannot answer for its human joiners and leavers will not answer for a population growing at Haber's rate [3][15]. Watch also whether agents get named owners in the access review cycle, and whether token lifetimes shorten, since long-lived tokens and in-code secrets are the specific failure Haber identifies [13]. Note that this case is argued by a vendor executive at an identity security company [1], and the growth figure is presented without a stated source [3].
Follow any of these and your For You feed starts watching them — no settings page required.
Ranked by verification strength, evidence, and original report placement.
Morey J. Haber is Chief Security Advisor at BeyondTrust, an identity and technical evangelist with over 25 years of IT industry experience, writing for the Forbes Tech Council.
For decades security teams have treated insider threats as a human problem (the disgruntled employee copying files to USB, the administrator abusing privileged credentials, the over-privileged contractor), all resting on the assumption that the threat actor is a person; Haber writes that assumption is no longer true.
Agentic AI systems can authenticate to services, access sensitive data, trigger workflows, connect to third-party data sources and interact with infrastructure with little or no human intervention.
To operate, agents need identities: API tokens, service accounts, machine identities, cloud roles, human impersonation or delegated credentials.
Once provisioned, an agent can move through an environment exactly the way a human user would, but with far greater speed, scale and autonomy.
An agent tasked with analysing customer data might access CRMs, ERPs, cloud storage buckets and other agents in a single run; each request looks legitimate and authenticated, and from a security perspective the transaction appears normal and is indistinguishable from a potential threat.
Evidence-backed comparisons of source perspectives and observed adoption signals. Read the methodology
Which Builder, Operator, and Investor concerns the observed source mix emphasized—not a truth score.
Evidence, demonstrated adoption, hype gap, incentives, and confidence are assessed independently, each on its own current evidence. How these are measured.
Single vendor op-ed, mechanisms described but nothing measured
The cluster contains exactly one item: an opinion column by an identity-security vendor executive. Its descriptive claims about agent identity requirements and lifecycle-governance mismatch are internally coherent, but the headline statistic is unattributed, the marquee harm is hypothetical, and there is no incident, telemetry, survey, benchmark, or third-party research anywhere in the material. No corroborating publisher exists in the cluster.
No verifiable deployment or governance-adoption evidence
The only adoption-shaped datapoint is an unattributed growth percentage plus an unquantified assertion that machine identities outnumber humans. No named organisation, product, agent platform, customer, rollout, or governance implementation is identified, and nothing indicates how many enterprises have actually applied per-agent ownership, just-in-time credentials, or behavioural baselining. Inferring an adoption level from a single vendor statistic would be guesswork.
Urgency framing outruns the supplied evidence
The framing is maximal - agentic AI as 'one of the most powerful insiders in the enterprise', a permanently shifted perimeter, a 5.7x population jump, attackers having already changed targets - while the supporting material is one interested author's assertions plus a hypothetical fraud scenario. The gap is positive but not extreme, because the underlying mechanics (agents hold credentials, over-broad entitlements and long-lived secrets are real failure modes, joiner-mover-leaver governance has no agent lifecycle) are plausible and stated without exaggeration.
Vendor executive prescribing his own category, in a paid-contributor venue
The author is Chief Security Advisor at BeyondTrust, a privileged-access and identity-security vendor, and the article's conclusion is that identity governance is 'the one control plane' capable of handling agents - precisely the category his employer sells. The venue is a contributor council program rather than independent newsroom reporting, and the piece carries no conflict-of-interest disclosure or competing viewpoint. Incentive alignment is strong and unmitigated, though the prescriptions are generic practices rather than named product features, which keeps this below the ceiling.
Confident about provenance and framing, not about the underlying facts
The assessment itself is well grounded on what can be judged: authorship, venue, incentive structure, and the absence of citations are all directly observable in the single supplied item, and the claim ledger maps cleanly onto the text. Confidence is capped near the middle because with one source and no corroboration there is no way to test whether the empirical claims about agent growth, identity ratios, or attacker retargeting are accurate.
security
ToxicPanda 2.0 Widens From 16 Apps to 140, and From Overlays to ADB Shell3 distinct publishers
leadership
Anthropic's own telemetry: 93% of permission prompts approved. Budget for blast radius, not reviewers1 distinct publisher
product
APIs built for human judgment now answer to agents that have none1 distinct publisher
leadership
Gartner says agents aren't ready; 60% of companies plan to deploy them anyway1 distinct publisher
Distinct publishers with included, body-backed reporting in this cluster.
1 article · August 20, 2026