A recent report from Sophos highlights that the rapid adoption of AI tools within enterprises has created a new and significant attack surface for cyber threats. The report notes a staggering 466.7% increase in active AI agents in just one year, with these agents gaining privileged access to core business systems. Cybercriminals are now targeting the credentials and access of AI identities, exploiting weak governance policies around AI security.
The report asserts that organizations risk exposure without proper AI governance, suggesting AI agents be treated like human users with restricted access and manual verification to mitigate risks.