SecurityBrief UK - Technology news for CISOs & cybersecurity decision-makers
United Kingdom
AI agents top insider risk concern for security chiefs

AI agents top insider risk concern for security chiefs

Tue, 22nd Sep 2026 (Today)
Joseph Gabriel Lagonsin
JOSEPH GABRIEL LAGONSIN News Editor

Exabeam has published research identifying AI agents with excessive, compromised or unintended access as the top insider risk concern for security leaders. The survey found that 48% ranked this as their greatest current threat.

The study covered 600 security and finance decision-makers in seven countries and pointed to growing concern about non-human access to enterprise systems. It also suggested organisations are expanding their monitoring of AI agents while struggling to understand agent behaviour across multiple environments.

Among respondents, AI-agent access risks ranked ahead of external threat actors, cited by 28%, while compromised insiders and malicious insiders each drew 12%. The research defined AI agents as autonomous systems that can access enterprise resources and take action with limited human intervention, rather than conversational chatbots.

That shift is changing how companies frame insider risk. Instead of focusing only on human misuse or credential compromise, respondents highlighted the risk of software agents operating beyond intended permissions, accessing sensitive data or triggering investigations that are harder to resolve because the activity appears legitimate in isolation.

Monitoring gaps

Many organisations said they have already put controls in place to monitor AI-agent activity. Exabeam found that 60% use dedicated AI security or governance tools, while 56% extend existing security information and event management, detection or monitoring platforms. The same proportion use behavioural monitoring and baselining, while 29% still rely on manual review.

Even with those measures, respondents reported persistent weaknesses. Limited behavioural context and correlation was identified by 27% as the biggest limitation, while poor visibility across environments, alert prioritisation and manual processes were also cited as significant problems.

Steve Wilson, Chief AI and Product Officer at Exabeam, said the challenge is no longer simply collecting logs or monitoring actions.

"Organisations are making meaningful progress in monitoring AI agents, but monitoring activity isn't the same as understanding behavior. AI agents operate with legitimate access and interact across multiple systems, making individual actions appear routine. Security teams need the context to connect those actions over time so they can distinguish expected automation from misuse, compromise, or unintended behavior," Wilson said.

The findings point to a broader challenge for security teams as businesses add more autonomous software to routine operations. A system may be performing tasks it is authorised to do, but that same legitimate access can make unusual or harmful behaviour harder to detect when each action is viewed on its own.

Finance alignment

The research also examined whether concerns about cyber risk are shared beyond security teams. It found that 93% of respondents said security and finance leaders are aligned on cybersecurity risk tolerance, and 83% of security leaders said their Chief Financial Officer understands the cyber risks they are trying to mitigate.

That apparent alignment did not always lead to spending approval. More than half of security leaders, 55%, said they had delayed or reduced a security initiative because they could not present the risk in financial terms their Chief Financial Officer would accept.

Mike Byron, Chief Financial Officer at Exabeam, said the obstacle is often commercial framing rather than disbelief in the threat itself.

"CFOs rarely question whether a cybersecurity risk is real. The challenge is understanding how a proposed investment reduces that risk in measurable business terms. When security teams connect technical outcomes to business impact, investment decisions become much easier," Byron said.

The results suggest companies are confronting two linked problems as AI agents spread through business systems: understanding what those agents are doing across different environments, and expressing the resulting risk in terms that support budget decisions. The survey indicates that both technical visibility and financial translation remain weak points even where risk awareness is high.

Sapio Research conducted the survey among organisations with 500 or more employees in the United States, Canada, the United Kingdom, France, Germany, the Netherlands and Australia. The respondent group included 300 IT decision-makers responsible for security and 300 finance decision-makers.

The report focused on the rise of agentic systems inside enterprises and the need to distinguish normal automated activity from misuse, compromise or unintended behaviour.