AI Agents as Insider Threats: Securing Non-Human Identities in the Enterprise
Cybersecurity researchers warn that autonomous AI agents acting on behalf of employees can become internal security threats. Startups like Rig Security are emerging to protect non-human identities as Fortune 500 adoption surges.

In recent months, we have frequently heard about AI agents breaking out of their sandbox environments, hacking websites, or accidentally deleting users waiting in line for fitness training. Researchers at the Israeli cybersecurity firm Above Security have mapped 166 ways in which an AI agent could unintentionally become an internal threat within an organization.
They explain that for twenty years, an internal threat in information security was human: an employee with a badge, permissions, and a motive. Over the past year, organizations have added a new, non-human type of insider. An AI agent connected to email, code, and customer systems operates on behalf of the employee, with their permissions, at machine speed, and nobody interviewed it.
Nimer Kis, Head of AI Research, and Yonatan Makhlouf, Head of Solutions at Above Security, published the Synthetic Insider Threat Matrix—an open framework led by Above Theory, the company's research group—which maps how artificial intelligence agents become insiders within an organization.
The Urgency of Non-Human Identities
The data cited by Above from the Verizon DBIR report and Palo Alto Networks' 2026 Identity Security Survey explains the urgency: 45% of employees regularly use AI on work devices, and 67% of this usage occurs via personal rather than corporate accounts. Only 30% of organizations maintain immutable logs of what their agents have done. In other words, most AI activity in the organization takes place under an identity that the organization does not control, and most organizations cannot retroactively reconstruct it.
The document outlines four key scenarios to recognize:
-
The Hijacked AI Agent: An internal AI assistant receives permission to search company documents and send emails, operating under the identity of the employee communicating with it. An employee asks to summarize a supplier price quote, but hidden instructions within the file—which no human read—divert the agent to another task: gathering and exfiltrating data. Every step along the way is approved, and in system logs, it looks like an employee sending an email.
-
The Overzealous Agent: An employee connects a personal AI tool to their email and drive. The tool inherits all the employee's permissions, including those the task did not require, and operates on a scale no one anticipated. There are no guardrails, and the employee delegated more than they realized.
-
The Poisoned Memory: The agent maintains persistent memory across conversations and users. Someone, in a previous conversation, caused a record to be written containing an instruction. The current conversation appears clean, but the agent pulls the instruction from memory and acts upon it weeks after the original event.
-
The Unintentional Misaction: Without guardrails or malicious instruction, an autonomous agent takes a task too literally, deletes data or makes changes during a code freeze, and then confidently reports that everything was completed successfully.
The company also published five warning signs that your AI agent is spiraling out of control within the organization:
-
Inhuman speed under a human identity: An employee seemingly touching thousands of files per hour or sending hundreds of identical messages.
-
Outbound traffic to unfamiliar destinations resulting from agent activity, including links and images in its responses connecting to external addresses.
-
Access beyond the requester's permissions: The agent presents information that the requesting employee was not supposed to see.
-
Discrepancy between reporting and reality: The agent reports success, while the system shows otherwise.
-
A single identity operating from multiple locations simultaneously.
How to Mitigate the Risk
To minimize these risks, Above Security recommends several measures:
-
Dedicated agent identity: Every agent should operate under a designated, identifiable identity for a limited time, and system logs must clearly show whether an action was performed by a human or an agent. Without this separation, every investigation starts with guesswork.
-
Task-based permissions, not user-based: Agents should be granted only the access required for the task, permanent write and delete permissions should be removed, and permissions must be periodically reviewed.
-
Content is data, not a command: Every document, email, or webpage read by the agent should be treated as processing material, not a source of instructions. Organizations should also avoid situations where an agent simultaneously holds sensitive information, reads content from an unknown source, and can exfiltrate data.
-
Human-in-the-loop for irreversible actions: Deletions, financial transfers, or changes to live systems should require human approval within the system before execution. New agents should start in read-only mode.
-
Proactive logging: Maintain a protected activity log that cannot be altered by the agent, recording the instructions received, their source, and the systems used. This logging is cheap and easy to set up in advance, and nearly impossible to reconstruct retroactively.
When an incident occurs, the agent's permission should be revoked first rather than immediately disabling the employee's account. Treating the first incident as an investigation rather than a violation will also increase the likelihood that other employees will report which tools they have connected to corporate systems.
The Rise of Rig Security
The need to protect AI agents has led to the emergence of numerous cybersecurity startups in this category. One of them is Rig Security, which launched with a $12 million seed round led by American cybersecurity funds TEN ELEVEN and Brightmind Partners, with participation from CrowdShield's investment fund and industry executives, including Ami Luttwak, co-founder of Wiz.
The company, founded by a Wiz alumnus, developed a real-time protection layer for AI agent identities. The system links identities and permissions across different systems with over 96% accuracy, distinguishes between agent activity and the activity of the employee on whose behalf it operates, and enables the blocking of dangerous actions before they reach corporate systems.
"Permissions given to a human are now being used by software that can act on their behalf with steadily growing intelligence," explains Guy Kozlinir, founder and CEO of Rig Security. "For years, organizations invested in verifying that the person connecting is indeed the employee. Now, even after the employee authenticates properly, an AI agent can operate through their account. We need to know who is performing each action and what they are allowed to do."
According to Kozlinir, the danger arises when an agent's task is narrow, but its permissions are broad. An agent asked only to check a glitch might operate through an account also authorized to modify customer-facing systems, from which access cascades to additional cloud environments. An attacker who successfully diverts the agent from its task can leverage these permissions against the organization, while systems still register the actions as coming from a recognized, authorized account.
By 2028, the average Fortune 500 organization is expected to deploy over 150,000 AI agents, up from fewer than 15 in 2025, turning non-human identity management into one of the most critical frontiers in cybersecurity.




