AI

Exclusive: AI Agents to Cause 25% of Enterprise Breaches by 2028

Featured image for "Exclusive: AI Agents to Cause 25% of Enterprise Breaches by 2028"
Summary

As organisations increasingly invest in tailored generative AI applications for enterprise automation, AI agents are emerging as pivotal components in digital transformation strategies.

As organisations increasingly invest in tailored generative AI applications for enterprise automation, AI agents are emerging as pivotal components in digital transformation strategies. These agents, whether operating autonomously, semi-autonomously or within multi-agent systems, harness artificial intelligence to perceive, make decisions and carry out actions to achieve a variety of goals.

While AI agents promise notable advancements, they also introduce fresh risks alongside existing threats posed by AI models and applications. Gartner predicts that by 2028, 25% of enterprise breaches will be linked to AI agent abuse, stemming from both external attackers and malicious insiders.

The exponential growth of the currently invisible attack surface created by AI agents necessitates the development of advanced security and risk management strategies. This heightened exposure is expected to attract bad actors from outside the organisation as well as internal threats, prompting enterprises to act swiftly in implementing robust controls to mitigate potential risks.

To address these challenges effectively, organisations must prioritise identity governance and administration encompassing both human and non-human identities. This involves isolating sensitive content and data from AI processes and entities that should not have access. Additionally, enterprises should explore emerging solutions from specialist vendors offering runtime data protection — providing contextual, dynamic access management and data classification while enforcing least-privilege access policies. These approaches should complement existing identity and access management, as well as information governance frameworks, to safeguard enterprise data and system access.

As AI agent activity intensifies, organisations failing to secure these operations will become increasingly vulnerable to hackers and malicious insiders exploiting the expanding, unprotected threat surface.

To prepare for the growing presence of AI agents, enterprises should invest in educating staff on the specific risks associated with these technologies, which are becoming ever more embedded in enterprise products. It is advisable to adopt either homegrown or third-party tools to manage AI agent risks, meeting three key requirements:

Moreover, enterprises must extend end-user behaviour monitoring and analysis capabilities to detect and alert on unusual activity originating from AI agents, including unauthorised collaboration with external entities.

Related Articles

Featured image for "Usman Gul’s Metal Raises $4.5 Million to Build AI Tools for Startup Fundraising"
AI

Usman Gul’s Metal Raises $4.5 Million to Build AI Tools for Startup Fundraising

Featured image for "ServiceNow and Aramco Digital Partner to Expand AI Across Enterprise Workflows"
AI

ServiceNow and Aramco Digital Partner to Expand AI Across Enterprise Workflows

Featured image for "VAST Data and CrowdStrike Extend Cybersecurity to Enterprise AI Data"
AI

VAST Data and CrowdStrike Extend Cybersecurity to Enterprise AI Data

Featured image for "Accenture and AWS Deepen Middle East Cloud Push as AI Demands Grow"
AI

Accenture and AWS Deepen Middle East Cloud Push as AI Demands Grow

Featured image for "NTT DATA's New Riyadh Lab Takes Aim at the Enterprise AI Pilot-to-Production Gap"
AI

NTT DATA's New Riyadh Lab Takes Aim at the Enterprise AI Pilot-to-Production Gap

Featured image for "Unifonic Brings Agentic AI Into Customer Experience at LEAP 2026"
AI

Unifonic Brings Agentic AI Into Customer Experience at LEAP 2026