AI agents run amok: enterprises scramble as identity attacks surge 449% and governance gaps widen

Venture Beat

The gist

AI agents now outnumber humans in the enterprise, fueling a 449% surge in identity attacks and exposing critical governance gaps that cost businesses millions.

What to know

  • AI-powered vishing and identity compromise attacks have spiked 449%, forcing companies to deploy automated defenses like FIDO2 and PKI-based MFA.
  • Only 10% of organizations have strategies to govern AI agents, despite more than 90% already using them—leaving vulnerabilities ripe for exploitation.
  • 1 in 5 organizations have suffered AI agent-related breaches, with 40% of victims reporting losses between $1 million and $10 million.

AI Escalates the Cyber Arms Race

CISOs face an unprecedented wave of unpredictable threats as generative AI turbocharges both attackers and defenders, shrinking response times and exposing gaps legacy tools can’t contain.

The rapid evolution of generative AI has fundamentally altered the threat landscape for CISOs, amplifying the scale and velocity of 'unknown unknowns' in cybersecurity. As enterprises face mounting pressure from boards to adopt AI for productivity and monetization, security leaders are confronted with bigger, faster-moving problems and shrinking windows to respond. This acceleration leaves defenders racing to keep pace with risks that are not only multiplying, but also increasingly difficult to anticipate or contain.

AI’s dual-edged nature is starkly evident as attackers leverage advanced tools to supercharge social engineering and identity compromise, while defenders counter with automated verification and cutting-edge MFA technologies. The KnowBe4 2025 Phishing Threat Trends Report revealed a staggering 449% spike in AI-powered vishing and a 67% surge in abuse of legitimate platforms, underscoring the urgent need for AI-driven detection and holistic human risk management. In response, defenders are deploying platforms like FIDO2 and PKI-based MFA, and automating identity workflows to neutralize attacks at initial access points, directly targeting adversaries’ most effective tactics.

By late 2025, the arms race between AI-powered attackers and defenders has led to a surge in agentic security automation, with platforms like Cisco’s 8B-parameter Foundation-sec model and JumpCloud’s AI-driven identity management empowering organizations to detect, prioritize, and respond to threats at unprecedented speed and scale. These unified, AI-powered security platforms are rapidly becoming the industry standard, as noted by Anton Chuvakin, who predicts their dominance over modular architectures due to their practical simplicity and integration. Meanwhile, startups like Dux and Echo are racing to secure AI-native environments, reflecting the industry’s recognition that only AI can defend against AI at enterprise scale.

However, the proliferation of AI agents and context protocols introduces new vulnerabilities, as demonstrated by Block’s red team exploiting prompt injection with invisible Unicode to deploy malware via its Goose AI agent. This incident highlights the lethal trifecta of access, exposure, and exfiltration risks inherent in AI model context protocols, with 1,000-2,000 exposed MCP servers found without authentication. In response, defenders are adopting adversarial AI techniques, suspicious Unicode detection, and recipe install warnings, while leaders like Block’s CISO stress the need for transparency and a proactive, experimental mindset to keep pace with the 'wild west' of AI security.

Sources
CyberWire DailyPR Newswire - Consumer TechnologySoftware Analyst Cyber ResearchThe Cybersecurity Pulse (TCP)Detection at ScalePR Newswire - Business Technology

Social Engineering Enters Overdrive

AI weaponizes phishing and vishing with flawless impersonation and deepfake tools, rendering old detection methods nearly useless and plunging enterprises into a new era of hyper-personalized attacks.

The threat landscape for AI-driven enterprises has rapidly evolved, with a dramatic surge in AI-powered social engineering attacks that exploit both human and machine trust. KnowBe4's 2025 Phishing Threat Trends Report spotlights a staggering 449% increase in AI-driven vishing (voice phishing) and highlights how sophisticated threat actors like the Scattered Spider gang have breached major retailers such as M&S, Co-Op, and Harrods to launch highly targeted phishing campaigns. These incidents underscore how identity compromise and the abuse of legitimate brands are now deeply intertwined, fueling a new era of social engineering risk that is both technologically advanced and alarmingly effective.

AI has industrialized social engineering, transforming what was once a manual, error-prone craft into a high-speed, hyper-personalized operation that spans multiple channels and modalities. Attackers now leverage large language models to craft flawless, context-rich lures—referencing internal projects, mimicking departmental communications, and even generating deepfake voice or video snippets for vishing and live chat impersonations. This shift has rendered traditional phishing red flags, like poor grammar or generic messages, largely obsolete, as AI-generated attacks can convincingly mirror organizational language and adapt in real time, making detection by both users and legacy security tools increasingly difficult.

The proliferation of non-human identities and autonomous agents within enterprises has introduced a new class of vulnerabilities, including prompt injection, data poisoning, and the rise of shadow AI. High-profile cases such as OpenAI's ongoing struggle with prompt injection in its Atlas browser and IBM's 'Bob' AI tool being manipulated via indirect prompt injection highlight the persistent and, in some cases, unsolvable nature of these risks. Meanwhile, campaigns like 'Poison Fountain' demonstrate how adversaries can subtly corrupt foundational AI models through data poisoning, degrading reliability and trust, while shadow AI—unsanctioned tools operating outside official oversight—creates operational blind spots that traditional governance cannot easily address.

Defending against this multifaceted threat landscape requires a layered, adaptive approach that goes beyond technical controls. Organizations are urged to combine AI-driven detection tools, phish-resistant MFA (such as FIDO2/passkeys), and robust human risk management—including frequent, realistic training drills and clear reporting channels. As OpenAI and other leaders emphasize, enterprises must treat all AI model inputs as untrusted, implement context firewalls, and limit agent autonomy, recognizing that prevention alone is insufficient in the face of persistent, evolving agentic risks and the relentless ingenuity of attackers.

Sources
PR Newswire - Consumer TechnologyToxSec - AI and CybersecurityTechRadarVenture BeatTechRadarCybersecurity Headlines

IAM Faces an AI Identity Crisis

With AI agents outnumbering humans and acting autonomously, static IAM frameworks are failing—forcing organizations to urgently rethink identity governance and control as breaches and blind spots multiply.

Traditional identity and access management (IAM) frameworks are buckling under the weight of AI-driven enterprise realities. As AI agents proliferate—now outnumbering humans in many organizations—legacy IAM models, built for static human roles and one-time approvals, are proving inadequate. Over 90% of organizations have deployed AI agents, yet a mere 10% possess any governance strategy to discover, control, or manage these non-human identities, underscoring a critical gap that even security giants like JP Morgan Chase, with its $18 billion security budget, have publicly decried. This has sparked a push for new open standards and frameworks, with companies like Okta pioneering agent-specific IAM solutions that recognize AI agents as first-class identities, aiming to provide CISOs with the control and visibility needed to safely enable AI at scale.

Static credentials, OAuth grants, and group-based access controls are relics in the AI era, failing to provide the granular, contextual governance required for AI agents that act autonomously and at scale. CISOs are left in the dark as static API keys proliferate and OAuth offloads critical authorization decisions to end users, making it nearly impossible to track which agents are accessing sensitive enterprise resources. As Ian Livingston puts it, the challenge is 'the contextual understanding in complex relationships of user A is using agent B accessing tool C,' demanding deterministic guardrails and dynamic, session-based permissions that are automatically revoked after each task. Solutions like Aembit's 'Blended Identity' and MCP Identity Gateway, as well as JumpCloud's Zero Trust policies for AI agents, exemplify the industry's move toward dynamic, risk-aware access models that bind agent actions to human context and business purpose.

The operational playbook for securing AI-driven enterprises is being rewritten as traditional incident response, email security, and static monitoring fail to address the unique threat surfaces introduced by AI agents. Prompt injection, memory poisoning, and data exfiltration via conversational interfaces have exposed the limits of legacy controls, with 1 in 5 organizations already suffering AI agent-related breaches—40% of which resulted in losses between $1 million and $10 million. OpenAI's rapid response loop for its Atlas AI browser and the rise of adversarial testing tools like PromptFoo reflect a new paradigm: security must be continuous, context-aware, and embedded throughout the software lifecycle, with proactive prevention, dynamic session security, and AI-specific incident definitions becoming table stakes.

By early 2026, the industry is converging on a consensus: securing both human and machine actors in AI-driven environments requires a holistic shift to agent-specific IAM, zero trust, dynamic access, and session security. This is not just a technical necessity but an operational imperative, as 78% of CISOs report lacking formal strategies for AI identity management within zero trust architectures, and only 1% of organizations have adopted just-in-time privileged access. The urgency is compounded by the rapid adoption of AI-native applications, shadow AI risks eclipsing those of shadow IT, and the normalization of insecure shortcuts under competitive pressure. As Joan Vendrell notes, 'Agentic Security has become one of the most urgent and complex challenges in modern cybersecurity,' with dedicated AI security specialists expected to become the norm by 2030.

Sources
SiliconANGLE theCUBEVenture BeatThe Cybersecurity Pulse (TCP)Business WireAI + a16zPR Newswire - Business Technology

Governance Gap Fuels AI Risk

With most enterprises lacking visibility and policy guardrails for runaway AI agents, trust in digital operations is eroding as high-impact breaches expose sensitive data and costly vulnerabilities.

The explosive adoption of AI agents in enterprises has created a yawning governance gap, with over 90% of organizations deploying these agents but only about 10% possessing any meaningful control or governance strategy. As Jack Hirsch observes, 'over 90% of organizations have AI agents already deployed and generally running amok. And about 10% have a control or governance strategy to discover control and govern AI agents.' This imbalance is further exacerbated by the lack of adequate guardrails in the SaaS ecosystem, even for security-conscious giants like JP Morgan Chase, whose CISO publicly criticized the industry's failure to provide robust authentication and authorization frameworks for agentic AI.

The erosion of trust in AI-driven enterprise environments is both a technical and human challenge, as incidents of AI agents exposing sensitive data across organizational boundaries highlight the urgent need for nuanced policy guardrails and continuous monitoring. With 1 in 5 organizations experiencing AI agent-related breaches—40% of which resulted in losses between $1 million and $10 million—confidence in digital interactions is faltering, and the human factor in governance and education becomes paramount. These breaches underscore the necessity for explicit, context-aware access policies and ongoing employee education to restore trust and resilience in AI-powered operations.

Visibility and proactive governance have emerged as the linchpins of effective AI risk management, as enterprises grapple with the complexity and speed of AI agent actions that defy traditional security models. Leaders like Anneka Gupta emphasize the 'three pillars of AI resilience: visibility, governance, and reversibility,' while Microsoft’s approach integrates full auditability and control over agent actions, including the ability to deactivate misbehaving agents in real time. However, achieving comprehensive visibility remains a formidable challenge, requiring continuous monitoring, granular logging, and collaboration between development and security teams to keep pace with the non-deterministic nature of AI systems.

The governance gap is further widened by the proliferation of shadow AI—unsanctioned tools used without oversight—which now represents the fastest-growing threat inside enterprises. As Dan Herbatschek warns, shadow AI causes untracked data exposure and regulatory noncompliance, demanding a governance-first approach that combines clear policies, technical controls, and continuous employee education. Solutions like WitnessAI, which empower organizations to create tailored AI guardrails using natural language, exemplify the shift toward flexible, industry-specific governance frameworks designed to keep pace with evolving risks and foster trust in AI-driven environments.

Sources
SiliconANGLE theCUBEAI + a16zPR Newswire - Business TechnologyGlobeNewswire - Industry News on TechnologyTuring PostMatthew Berman

Agentic Security Reshapes Defense

Unified, AI-native security platforms and runtime defenses are rapidly supplanting legacy tools as enterprises pivot to continuous, adaptive protection against novel agent-driven threats.

The rapid evolution of AI-native security has ushered in a new generation of defenses—agentic security tools, runtime monitoring, and adaptive threat modeling—that are fundamentally reshaping how enterprises protect themselves in an era of autonomous AI agents. Companies like Zscaler, JumpCloud, and Prompt Security are leading the charge by integrating identity management for both human and machine actors, deploying real-time prompt inspection, and embedding agentic exposure management into their platforms. This shift is driven by the inadequacy of traditional, static security models against the stochastic, semantic nature of AI-powered attacks, as highlighted by the proliferation of runtime threats and the emergence of new attack surfaces such as Machine Control Protocols (MCPs), which govern agent actions and require novel auditing and policy enforcement mechanisms.

Industry trends in late 2025 and early 2026 reveal a decisive move toward unified, AI-powered security platforms and adaptive, data-driven defense strategies. Giants like Microsoft and Cisco are embedding security and observability from the ground up, while startups face pressure to differentiate in a market increasingly dominated by platforms with proprietary telemetry and integrated AI-SPM capabilities. The market’s maturation is also reflected in major M&A activity—such as ServiceNow’s pursuit of Armis and Lightspeed’s $9B fundraise—and the growing importance of security data pipelines and agent-first data lakes, which enable SOCs to optimize detection quality and cost. As Anton Chuvakin notes, the practical simplicity of unified platforms is expected to 'reign supreme' over modular architectures in the years ahead.

However, the technological leap is only half the story; enterprises must also undergo significant cultural and operational shifts to secure an AI-native digital future. As AI adoption outpaces the deployment of effective defenses, organizations are urged to embed security early in the product lifecycle, foster leadership transparency, and cultivate a culture of continuous learning and collaboration. Regulatory pressures—particularly from Europe—are intensifying demands for policy safeguards, accountability, and transparency, while the persistent challenge of prompt injection and the rise of shadow AI underscore the need for proactive, adaptive security models. As OpenAI candidly admits, 'prompt injection is an unsolvable risk,' making runtime monitoring, human-in-the-loop approvals, and adaptive threat modeling essential pillars of modern AI security.

Finally, the future of AI-native security will hinge on the ability to operationalize dynamic, living threat models and leverage AI-driven automation for both detection and remediation—while maintaining trust and resilience. Tools like Claude Code and mcp-panther are enabling same-day detection rule deployments, compressing security cycles that once took months, while adaptive threat modeling helps organizations prioritize and address vulnerabilities before attackers can exploit them. Yet, as organizations cautiously balance the promise of automation with the risks of operational disruption, the consensus is clear: effective AI-native security demands a blend of technological innovation, rigorous guardrails, and a relentless focus on risk-driven prioritization.

Sources
The Cybersecurity Pulse (TCP)Venture BeatAI + a16zThe Cybersecurity Pulse (TCP)Detection at ScaleVenture Beat

Get the stories behind the trends

Deep-dive reporting and the weekly brief, in your inbox.