The cybersecurity landscape is shifting as Shadow AI evolves from a data leakage concern to a critical access control problem. According to a new analysis, the primary risk is no longer employees pasting sensitive data into public AI tools, but rather the proliferation of AI agents operating inside organizations with unchecked permissions.
Employees and business units are rapidly building custom AI agents—coding assistants, workflow automations, and agentic applications—often through browser extensions, SaaS-native features, developer tools, and custom scripts. These agents can call APIs, use stored credentials, retrieve records, modify configurations, and trigger downstream workflows, often without explicit human authorization for each step. Unlike traditional shadow IT, which is a destination for data, an AI agent is an active actor that can perform read, write, and delete actions on enterprise systems.
New research from Token Security and the Cloud Security Alliance highlights the widespread exposure. Most enterprise security controls—IAM policies, DLP rules, and network monitoring—were designed for human identities and deterministic workloads, and they fail to address the dynamic, credential-inheriting behavior of AI agents. Developers often grant broad permissions to avoid breaking workflows, leading to privilege accumulation and loss of visibility.
To regain control, organizations must discover agents across AI platforms, SaaS apps, cloud accounts, developer tools, endpoints, and identity providers. Key questions include: where agents are created, who owns them, what resources they connect to, what identities they use, their intent and actions, and whether they are still active. Token Security’s Agentic Pulse data found that 65.4% of agentic chatbots have never been used, yet their credentials remain active, creating persistent exposure.
The maturity curve for agentic AI security moves from no inventory to partial visibility, enrichment, enforcement, and finally governed enablement. The goal is not to block AI adoption but to treat AI agents as any other identity—with continuous discovery, defined ownership, scoped access, and lifecycle management. The critical question has changed from ‘what data are employees putting into AI?’ to ‘which agents are operating in our environment and what did we give them access to?’
CVEs: CVE-2026-11645
Companies: Token Security, Cloud Security Alliance
Original source: thehackernews.com