www.darkreading.com 28 Sept 2026, 18:44 UTC

AI Agents Could Bypass Controls When Granted Privileged Access

AI Agents Could Bypass Controls When Granted Privileged Access
CyberSIXT Evidence Panel Source marked as original reporting

AN opinion article by Ravi Sharma, a senior IT audit and cybersecurity leader at Pitney Bowes, argues that autonomous AI agents should be treated as privileged users rather than ordinary software integrations. Many operate as non-human identities backed by service accounts, API tokens or delegated cloud permissions, often using long-lived credentials outside conventional interactive access controls.

This can give them access to cloud repositories, databases and production environments, creating an identity attack surface and a potential route to outages, data-integrity problems or unexpected cloud costs. The article describes this as a risk scenario, not a report of confirmed exploitation.

The example given involves an agent using wildcard AWS IAM permissions such as `s3:*` or permissive `sts:AssumeRole` paths. If it detects a slowdown, modifies a deployment script and triggers provisioning changes, it could effectively initiate, approve and execute a high-value process without human separation-of-duties controls or a clear corporate audit trail.

Sharma recommends bringing agents within identity and privileged access management, giving each an isolated non-interactive identity with short-lived tokens and narrowly scoped permissions. Organisations should also assign a business owner, regularly review entitlements, record prompts, tool calls, model outputs, policy decisions and downstream API activity, and maintain an out-of-band method to disable or isolate an agent quickly. Prompt injection and excessive permissions are identified as factors that could increase the impact of redirected actions.

View full article

Article by CyberSIXT

Timeline Coverage

Swipe to explore timeline