8 Sources
[1]
Identity-First AI Security: Why CISOs Must Add Intent to the Equation
Author: Itamar Apelblat, CEO and Co-Founder, Token Security Not long ago, AI deployments inside the enterprise meant copilots drafting emails or summarizing documents. Today, AI agents are provisioning infrastructure, answering customer support tickets, triaging alerts, approving transactions,
[2]
Securing AI infrastructure is critical - here's how to do it
I believe that 2026 will be a defining year for cybersecurity. Sometime during the year, AI-powered threats will have the ability to adapt in real time. This will force organizations to defend against them - and they will need to do it fast. Some of the AI-enabled cyberattacks will be against AI
[3]
Nearly two-thirds of companies have lost track of their data just as they're letting AI in through the front door to wander around | Fortune
The extensive research, conducted by S&P Global's 451 Research and commissioned by Thales -- a global technology leader in the cyber -- highlights a troubling disconnect between rapid AI adoption and foundational data control. Across vital markets, including the automotive, energy, finance, and
[4]
The Human Risk Reckoning: Why security must evolve for an AI-augmented workforce
Security models that were effective a few years ago are now under immense strain because of how rapidly organizations are changing. As we move into 2026, many teams are dealing with a larger and more complex risk landscape. This is largely driven by rapid artificial intelligence (AI) adoption,
[5]
AI and deepfakes are proving to be a security nightmare for businesses everywhere
Misconfigured AI can quickly turn into a malicious insider, experts warn * Thales 2026 Data Threat Report says 61% see AI as top data security risk * Enterprises grant AI broad access, creating insider-like risks * 48% report reputational damage from AI-driven misinformation Artificial
[6]
How businesses can stop their AI agents from running amok
Most organizations will by now be familiar with the concept of AI agents - autonomous systems that perceive, make decisions and take actions to achieve specific goals within an environment. In fact, a staggering 82% of organizations are using AI agents today, often across multiple business
[7]
AI vs AI: Defense Without Humans in the Loop | PYMNTS.com
By completing this form, you agree to receive marketing communications from PYMNTS and to the sharing of your information with our sponsor, if applicable, in accordance with our Privacy Policy and Terms and Conditions. Seconds later, another system steps in. A defensive AI spots the abnormal
[8]
Friend or foe? AI: The new cybersecurity threat and solutions
Cyber-attacks have more than doubled worldwide in just four years, from 818 per organization in 2021 to almost 2,000 per organization last year, according to the World Economic Forum (WEF). It's a staggering statistic. And small businesses are particularly exposed, now seven times more likely to
Share
Copy Link
A new global report reveals that 61% of organizations now identify AI as their primary data security risk, as AI agents gain broad access to enterprise systems with fewer controls than human workers. The research exposes a troubling gap: companies are granting AI tools insider-level privileges while 47% of sensitive cloud data remains unencrypted and nearly two-thirds have lost track of their data entirely.
AI agents have evolved far beyond passive assistants drafting emails or summarizing documents. Today, these autonomous systems provision infrastructure, triage security alerts, approve transactions, and write production code across enterprise environments
1
. This operational shift creates what CISOs recognize as a familiar but amplified challenge: access control. Every AI agent authenticates to systems using API keys, OAuth tokens, cloud roles, or service accounts, behaving exactly like an identity because it is one1
. Yet in many organizations, AI agents are not governed as first-class identities, instead inheriting privileges from their creators or operating under over-scoped service accounts1
.
Source: TechRadar
Global research by S&P Global's 451 Research, commissioned by Thales and surveying 3,120 security and IT professionals, reveals that 61% of organizations now explicitly cite AI as their top data security risk
3
5
. The core problem stems from enterprises eagerly embedding AI into daily workflows while granting these automated systems broad access to vast troves of enterprise data, frequently with fewer security controls than those applied to human employees3
. Sebastien Cano, Senior Vice President of Cybersecurity Products at Thales, emphasized this alarming shift: "Insider risk is no longer just about people. It is also about automated systems that have been trusted too quickly"3
5
.
Source: TechRadar
The research exposes widening data visibility gaps across cloud infrastructures, with only 39% of companies able to fully classify data and nearly half (47%) of all sensitive cloud data remaining entirely unencrypted
3
. Perhaps most troubling, nearly two-thirds of organizations have lost track of their data just as they're letting AI agents wander through enterprise systems3
. Because AI agents continuously ingest and act upon information across sprawling cloud and SaaS environments, enforcing least-privilege access becomes incredibly difficult. When machine credentials are compromised by malicious actors, the resulting data exposure could prove devastating3
.Modern AI infrastructure spans models, training frameworks, data pipelines, RAG architectures, APIs, open-source libraries, development tools, and deployment environments
2
. Each component represents a potential attack surface. AI-powered threats are expected to adapt in real time during 2026, forcing organizations to defend against them rapidly2
. Immediate threat scenarios include data poisoning at scale, where attackers manipulate training data to introduce hidden vulnerabilities or backdoors, and supply chain compromise through backdoored foundation models distributed via legitimate channels2
. Adversarial attacks that manipulate model inputs in real time pose serious risks when AI operates in security, finance, or safety-critical environments2
.Attackers are already exploiting access vulnerabilities. Credential theft is now the leading attack technique against cloud management infrastructure, cited by 67% of organizations that have experienced cloud attacks
3
. Simultaneously, 50% of organizations rank secrets management as a top application security challenge, illustrating the immense difficulty of governing machine identities, tokens, and API keys at scale3
. Traditional identity and access management answers who is requesting access, but AI agents break the assumption of determinism that IAM was built upon1
.Identity-first security for AI requires recognizing that every autonomous agent must be governed, audited, and attested just like a human user or machine workload
1
. However, identity governance alone proves insufficient. AI agents are dynamic by design, interpreting inputs, planning actions, and calling tools based on context1
. This is where intent-based permissioning becomes essential, evaluating whether an agent's declared mission and runtime context justify activating its privileges at that moment1
. This approach addresses two common failure modes: privilege inheritance, where developers test agents using their own elevated credentials that persist in production, and mission drift, where AI agents pivot mid-run based on prompts or adversarial input1
.
Source: BleepingComputer
Related Stories
While companies struggle with internal AI access, malicious actors leverage the same technology for sophisticated external attacks. Nearly 60% of companies report experiencing deepfake-driven attacks, and 48% have suffered reputational damage tied to AI-generated misinformation or impersonation campaigns
3
5
. Deepfakes use AI-generated fake audio, video, or images to convincingly impersonate real people, manipulating victims through voice cloning to trick employees, creating AI-generated video to authorize payments, or fabricating public statements5
. Human error continues contributing to 28% of data breaches, but adding rapid automation means small mistakes can now scale wider than ever3
.Despite escalating automated threats, security investments struggle to keep pace with AI-driven access. Only 30% of companies surveyed have dedicated AI security budgets, while the majority (53%) still rely on traditional security budgets and programs built primarily for human users and perimeter-based defenses
3
5
. Eric Hanselman, Chief Analyst at S&P Global 451 Research, stated that "as AI becomes deeply embedded into enterprise operations, continuous data visibility and protection are no longer optional"3
. Organizations must treat AI infrastructure as mission critical and apply defense-in-depth strategies across every layer of the AI lifecycle2
.The workplace no longer consists only of people. AI agents are increasingly embedded into critical workflows, operating alongside employees and interacting with sensitive data
4
. Organizations are not applying the same level of behavioral risk training to AI agents as they do to their workforce, creating a new and largely unmanaged kind of insider risk4
. Human risk management must be positioned as a core piece of security strategy rather than a supporting initiative4
. Organizations that act early to implement identity governance, access policies, and encryption for both human and machine identities will be best positioned to benefit from AI without exposing themselves to catastrophic risk2
3
.Summarized by
Navi
[1]
19 May 2026•Technology

02 Jan 2026•Technology

12 May 2026•Technology

1
Science and Research

2
Technology
3
Policy and Regulation
