Security Risks from Agentic AI: Warning of Permission Avalanches

Notice: This article was created with AI.

What’s It About?

The use of autonomous AI agents in corporate environments carries considerable security risks, experts warn. The problem lies in the structure of existing access permissions: while human employees actually use only a small portion of their access rights, AI agents could theoretically access all available permissions. This creates dangerous vulnerabilities, compared to fragile layers of snow that can trigger avalanches.

Background & Context

A joint investigation by the security companies Oso and Cyera analyzed the access structures of 2.4 million employees and 3.6 billion permissions. The results are alarming: on average, employees actively use only four percent of their assigned access rights. For particularly sensitive data, the actual usage rate is even considerably lower – even though the authority to delete or modify critical information is formally in place.

The central problem arises when AI agents are equipped with the permissions of human users. Unlike humans, who deploy their access rights selectively and contextually, autonomous systems could potentially access all available permissions. According to CyberArk, there are already around 80 machine identities per human identity in companies today, many of them with privileged access rights and inadequate security controls.

Security experts are therefore calling for fundamentally new authorization concepts for AI agents. One promising approach is so-called golden paths: autonomous systems are given dedicated identities with the minimum necessary permissions. By default, AI agents should receive only read access, while design and execution rights must be strictly separated. This strategy aims to minimize the potential for damage in the event of misuse or malfunction.

What Does This Mean?

  • Companies must urgently revise their permission structures before deploying AI agents across the board
  • The existing practice of granting employees far-reaching access rights that they barely use is becoming a critical security risk in the age of autonomous systems
  • New authorization models with minimal default rights and strict separation of powers are indispensable for AI agents
  • The rapidly growing number of machine identities requires specialized security concepts that go beyond classic identity management approaches
  • Organizations should implement golden-path strategies in order to enable controlled and traceable access routes for AI agents

Sources

Eine Agentic-AI-Lawinenwarnung (Computerwoche)

Agentic AI in the Wild: Real-World Use Cases You Should Know

Agentic Security: Accountability and Human Oversight

Agentic AI Security Strategy Gaps (Mimecast)

Weiterführender Artikel: Paperclip: Wenn KI-Agenten ein Org-Chart bekommen

This article was created with AI assistance and is based on the listed sources as well as the language model’s training data.

Further Reading: Paperclip: When AI Agents Get an Org Chart

Leave a Comment

Your email address will not be published. Required fields are marked *

Scroll to Top