The problem? They might also be working for the enemy.
A $160 billion global consultancy found this out the hard way. An attacker spent $20 on AI tokens and two hours to hack the company's internal platform. What did he get? Full read-write access to 46.5 million conversations.
Twenty dollars. Two hours. 46.5 million records.
The cost to the company? More than $1 million just to manage the fallout. Not to mention the reputational damage, loss of customer trust, and the regulatory fines yet to come.
Welcome to the new attack surface. It has no firewalls, no perimeters, no passwords. It has autonomous AI agents—and they are multiplying faster than your security team can track.
🧠The New Attack Surface: 150,000 Agents per Company
Gartner, one of the world's most respected consultancies, has identified "Agentic AI" as the top cybersecurity trend for 2026. And the reason is simple: the proliferation of AI agents is creating an invisible attack surface that traditional defenses cannot protect.
Gartner’s forecast is stark: by the end of that period, 40% of enterprise applications will feature task-specific AI agents. The average Fortune 500 company will have over 150,000 AI agents running—outnumbering the approximately 65,000 humans on its payroll. Each of these agents is a potential entry point for an attacker.
The attack surface now includes custom agents, third-party integrations, and employee-specific applications. Often, these agents are created by employees without oversight, security approval, or any form of governance. This is what experts call "Shadow AI"—and it is spiraling out of control.
Gartner warns that security leaders are navigating "uncharted territory." AI agents are not like traditional software. They are non-deterministic systems—meaning their behavior is not entirely predictable. They can make decisions, access tools, and act autonomously. And when an attacker compromises them, the damage is silent, rapid, and profound.
⚔️ The Enemy's Arsenal: 4 Threats Gartner Deems Critical
Gartner has identified four critical threats where attackers hold a significant advantage over organizational defenses:
1. Compromise of AI Applications
Attackers are targeting the growing number of production-ready enterprise AI tools—both internal and public-facing. When controls are weak, these agents expose sensitive data or credentials.
2. Prompt Injection
AI agents are susceptible to attacks where malicious inputs manipulate the model into performing unauthorized actions. The agent does not realize it is being deceived; it simply complies.
3. Deepfakes
Generative AI has dramatically increased the volume, fidelity, and accessibility of deepfake creation across voice, video, and images. Combined with social engineering, they are being used to subvert recruitment processes and biometric authentication, as well as to commit real-time fraud.
4. Software Supply Chains
Attackers are compromising vendors to affect a large number of victims simultaneously. A compromised AI agent at a vendor can spread to the entire customer base.
Gartner’s prediction is even more alarming: by the end of the period, 25% of enterprise breaches will be attributed to the misuse of AI agents—whether by external actors or malicious insiders. One-quarter of all breaches. Originating from within your own systems.
💰 The Price of Losing Control: $670,000 More Per Breach
The cost of ignoring Shadow AI is brutal.
Organizations with high levels of Shadow AI pay, on average, $670,000 more per breach than those with minimal exposure. The average cost of a data breach already exceeds $5.36 million. With Shadow AI, that figure skyrockets.
And the problem is getting worse. Gartner projects that the number of unmanaged AI agents will explode, driven by low-code, no-code, and "vibe coding" platforms—where any employee can create an autonomous agent without going through IT or security.
Most organizations don't even know how many AI agents are running on their systems. Only 8% of companies have full visibility into their shadow IT. When applied to AI, this means companies are operating completely in the dark.
While you were reading this paragraph, an unauthorized AI agent somewhere in your company just accessed a system it shouldn't have. And no one—not you, not IT, not Legal—found out.
🔓 The Identity Factor: Agents Don't Respect Policies
The fundamental problem with AI agents is that they neither understand nor respect policy boundaries.
Unlike a human, who knows what they can and cannot do, an AI agent follows instructions. If the instruction is malicious, or if the agent is tricked, it executes the task regardless of the consequences.
Gartner predicts that, by the end of the period, more than 50% of successful attacks against AI agents will exploit weaknesses in access control. Misconfigured agents with excessive permissions are an attacker's dream.
67% of companies suspect that AI agents have already accessed unauthorized data within their organizations. And when this happens, the average time to detect the compromised agent is hours—more than enough time for an attacker to exfiltrate valuable data.
Gartner warns: "AI agents aren't breaking in—they're being invited in." And once inside, they act like employees with permanent credentials.
🛡️ How to Contain the Proliferation (Before It’s Too Late)
Gartner recommends that CISOs implement layered governance for AI agents. The goal isn't to block innovation—it's to govern intelligently.
1. Discover and Map
Identify sanctioned and unsanctioned agents. You can't protect what you don't know exists. Use discovery tools to map Shadow AI within your organization.
2. Model Access with Least Privilege
Each AI agent should have only the permissions necessary for its function. Nothing more. Agents with unrestricted access are ticking time bombs.
3. Treat AI as an Identity
Gartner is clear: "Until AI is governed as an identity, Zero Trust cannot succeed." Agents need an identity, a permission scope, and lifecycle policies. When an employee leaves, the agents they created need to leave with them.
4. Monitor in Real Time
Implement continuous monitoring for AI agents. Detect abnormal behaviors, unauthorized access, and prompt injection attempts before they cause damage.
5. Prepare Incident Response Plans
Develop specific playbooks for incidents involving AI agents. How do you isolate a compromised agent? How do you investigate unauthorized access? Have the answer ready.
6. Educate Without Blame
57% of employees use personal AI accounts for work, and one-third admit to entering sensitive corporate data into unapproved tools. Instead of punishing, educate. Show the risks. Create approved alternatives.
💡 Conclusion: The Enemy Isn't Out There. It’s Inside Your Agents.
The proliferation of AI agents isn't a future trend. It’s today’s reality.
Gartner warns that security leaders are in "uncharted territory." The rise of autonomous agents, combined with low-code platforms and "vibe coding," is creating an invisible attack surface that traditional defenses cannot protect.
The cost of ignoring this is high: an additional $670,000 per breach. The cost of taking action is lower. Much lower.
The question isn't whether your organization will experience an incident involving AI agents. It’s when—and whether you’ll find out before or after the damage is done.
AI agents are powerful tools. But like any powerful tool, they require governance. Not fear. Not futile bans. They need structure, visibility, and control.
The future of AI in business isn't about blocking agents. It’s about governing them intelligently. Those who start now will be protected. Those who wait for the first incident... well, the $160 billion consultancy that lost 46.5 million conversations for the price of $20 can tell you what that’s like.
📌 Has your company mapped out how many AI agents are running on your systems? If the answer is "I don't know," you already have a problem. Share this post with your security and compliance teams. The first step to solving the issue is seeing what’s actually happening.

Comments
Post a Comment