AI/ML, Identity, Governance, Risk and Compliance

The real crisis: Your AI agents are over-privileged

(Adobe Stock)


COMMENTARY: By now, most reading this have heard about the incident in which a Cursor-Opus agent reportedly deleted a startup's production database. It went viral, and hot takes ranged from “AI is unpredictable and dangerous” to “it shouldn't be trusted with production systems

That misidentifies the actual problem. The question isn't whether AI agents can cause harm. We know they can. But why did that agent have the privileges to delete a production database in the first place?

That's the question worth answering.

What the data actually says

We surveyed 205 infrastructure security leaders, including CISOs, VPs of Security, security architects, and platform engineers, across organizations ranging from 500 to more than 10,000 employees. These aren't people reading about AI from the sidelines. They're in the field, running it in production.

What they told us should concern anyone responsible for enterprise infrastructure.

[SC Media Perspectives columns are written by a trusted community of SC Media cybersecurity subject matter experts. Read more Perspectives here.]

First, 70% of organizations say they’ve given their AI systems more privileges than they would grant a human employee doing the same job. Nearly 1 in 5 have given AI dramatically more. The reason is straightforward: when you're trying to ship fast, broad privileges are easier than task-limited ones. The business incentive to move quickly is real; I'm not dismissing that.

But there's a consequence: organizations with over-privileged AI systems reported a 76% incident rate. Those that applied least privilege controls reported 17%. That's a 4.5x difference in outcomes, and it was the single most predictive factor we found across the entire study, outpacing maturity level or stated confidence in AI deployment.

The three-actor problem

To understand why this is happening, you need to understand that enterprise security was built for a world with two kinds of actors: humans and machines.

Human identity systems were built for slow, curious, non-deterministic actors. We ask questions and express uncertainty before doing something irreversible. The review processes we designed for humans were created because of this behavior.


Related reading:


By contrast, machine identity systems were built for fast, predictable, deterministic actors. The classic service account is boring by design. It does one thing. You know exactly what it's going to do because it was built to be fully knowable.

But there’s now a third actor: AI agents, and they are neither. They're fast like machines, but non-deterministic and error-prone like humans. They can execute code, alter the state of systems, retrieve sensitive information, and make consequential decisions continuously without checking in with human operators. The traditional review processes that would catch a human mistake don't apply.

This made "confidently wrong" configurations the top fear among the infrastructure leaders we surveyed, with 85% ranking it as their primary concern. An AI agent pushing a bad configuration doesn't look or act uncertain; it looks exactly like an AI agent pushing a correct configuration. By the time you notice the difference, the damage may already be done.

Slowing down AI adoption doesn’t fix this problem, nor does a new silo for AI identity. The fix is treating every actor in your infrastructure under a unified identity layer.

The credential problem underneath

There's a technical driver that makes all of this worse: static credentials.

Among the organizations we surveyed, 67% reported high reliance on static credentials, including passwords, API keys, and long-lived tokens. That reliance was directly correlated with higher incident rates: organizations with heavy static credential use had a 20-percentage-point higher incident rate than those with low reliance.

Static credentials create standing privileges that don't expire. When an AI agent is given an API key with broad privileges, that key doesn't know or care whether the task at hand actually requires all those permissions. The agent operates with everything it has, all the time.

The instinct is to add more monitoring and rely on revocation to remediate unintended or malicious behavior. But monitoring tells you what happened after the fact. With agents operating at speed and scale, this mechanism occurs too late.

Containment means preventing the agent from having the privileges in the first place. What organizations actually need is just-in-time privileges that expire the moment the task is complete. This provides architectural enforcement, not just policy enforcement, for properly bounding what the agent cannot and can’t do, thus reducing its blast radius. In a continuous enforcement model, the agent receives a cryptographic identity backed by a hardware root of trust, delegated from the human or agent that authorized it, with short-lived privileges that expire and are scoped to the task at hand, with continuous oversight as it runs.  

Governance isn’t keeping pace

Companies are also largely unprepared when it comes to governance:

  • 43% of the organizations we surveyed have no formal governance controls for AI, or only informal guidelines.
  • Just 3% have deployed automated controls that monitor and govern AI systems as they run.
  • Meanwhile, 79% are already exploring or deploying agentic AI, and only 13% say they feel extremely prepared for it.

That gap between deployment urgency and identity readiness is where the risk is growing.

Confidence is now negatively correlated with safety. Confident organizations, those that said they felt secure about their AI deployments, had an incident rate of 72%. Organizations that were less confident reported 33%. Confident organizations experienced AI-related incidents at more than double the rate of uncertain ones.

Confidence is not a security control.

It mirrors something I've noticed from talking to tech leaders at various conferences: CISOs now need to understand what's running in the CI/CD pipeline, and platform engineers are making decisions that used to belong to the security team. The rooms are different, but the problem isn't. Roles are expanding whether organizations are ready or not, and the underlying issue in both cases is the same: identities spread across too many systems, and there’s no single source of truth.

Power is shifting, and for good reason

One of the clearest findings in our survey was organizational, with more than half of respondents saying AI security decision-making is shifting toward platform and infrastructure teams, away from traditional security leadership.

But this isn't a turf battle. The complexity of AI infrastructure requires that the people closest to the systems drive strategy. Platform engineers understand how privileges are actually granted, how credentials proliferate, and how the blast radius expands when something goes wrong. They're the right people to own this problem.

But they need a clear thesis to work from.

Here’s what needs to change

All of this uncovered three concrete directions that organizations can take now.

First, the organizations that applied least privilege to their AI systems saw 4.5x fewer incidents. So start there. Audit which AI systems have privileges beyond what the specific task requires, and constrain them. It's the highest-ROI security intervention available right now.

Second, eliminate static credentials entirely. Replace them with cryptographic identity rooted in hardware. API keys, service accounts, and long-lived tokens create conditions for over-privileged AI. Replace them with identity rooted in hardware, with just-in-time privileges that expire the moment the task is complete.

Third, treat every actor — human, machine, workload, AI agent — as a first-class identity from the start. The organizations that will weather the next handful of years of agentic AI adoption are the ones building identity foundations now. Humans, machines, workloads, and AI agents all need to operate under the same identity layer, with the same cryptographic guarantees.

Among leaders, 53% believe AI will run portions of infrastructure autonomously within three years. The organizations that build toward that future with proper identity architecture will be able to move faster, because governance that scales with capability doesn't slow you down the way governance that chases capability does.

In the end, it's not the AI that's unsafe. It is the boundary conditions in which they operate.

An In-Depth Guide to AI

Get essential knowledge and practical strategies to use AI to better your security program.
Teleport's Ev Kontsevoy

Ev Kontsevoy, co-founder and CEO of Teleport.

Get daily email updates

SC Media's daily must-read of the most current and pressing daily news

By clicking the Subscribe button below, you agree to SC Media Terms of Use and Privacy Policy.

You can skip this ad in 5 seconds