HomeOur Blog
Blog Posts

The AI Agent Insider Risk is Coming from Inside The House

Above Security Team

Above Security Team

Table of contents
Above Security Team

Above Security Team

The pippin’ hottest take this year has been from Above: Agentic security is the same insider threat model only increased by volume. 

That’s right. As various security tools seek to help deploy agentic AI securely, the Above team is sipping on some well-steeped Earl Grey talking about how an agent is a glorified script that knows how to act on its own behalf while relying on the credentials that the organization provides him. 

While a human can move physically across the office and, presumably, has free will, the agent is confined to the tools and access to them that the organization provides. Even when you look at the big PR dustup from early summer, the real story around OpenAI and Claude wreaking havoc across the internet boiled down to a single human who forgot to limit the AI agent’s public internet access permissions.

When it comes to AI security, the call may not be coming from inside the house, but the insider risk is coming from the organization’s internal permissions and network.

Why Are AI Agents Insider Risks?

While making analogies between current AI agents and movie AI robots is generally hyperbolic, it makes sense from the insider risk perspective. In Stanley Kubrick's 2001: A Space Odyssey (1968), the AI HAL starts out as trustworthy and friendly, even playing chess with the crew. He degrades into a malicious insider as he manages two different user-driven directives, relating information to the crew and preventing the crew from learning the mission’s true purpose. HAL is not inherently dangerous. The risk arises from the directives given and the system permissions granted to him. 

Similarly, albeit not in a deadly way, corporate AI agents take actions on a user’s behalf, creating a whole new set of potential security team challenges. An AI agent may have legitimate access to a system while still acting in a way that creates a new risk. For example, if the person responsible for the AI’s access grants delete permissions to a human resources tool, the AI has legitimate access that potentially allows it to delete a record. If the access remains limited to read, then the AI can scan the data but not make potentially risky changes. 

From a security perspective, an AI agent may be trustworthy as the organization provides access and authorizes it into systems. When organizations grant agents permissions, they can take completely legitimate actions.

Why Does the Industry Need to Re-think Insider Risk?

Historically, organizations have approached insider risk from the wrong directions. Nearly every tools has been built around either rules or anomalies:

While these tools show potentially harmful actions, they fail to provide the context that security teams need. When looking at human actions, security teams need context into intent, the emotional motivations underlying the actions. 

While AI agents may not have emotions, identifying the insider risk they pose still requires looking at context. 

Collecting the contextual data is one step. However, when using AI tools to understand what that context means, security teams need to separate the evidence from the conclusion.

What kind of data helps determine context?

When investigating human-based insider risk, security teams need to understand the person involved with context about their job satisfaction and financial state. Someone who was passed over for a promotion would be more likely than someone who recently received a raise to steal sensitive customer information. An AI, however, has none of these human problems, yet the agents fail to act in a vacuum. 

AI agents act within the context of your environment, meaning you can gather information about:

  • SaaS activity: app usage patterns and data interactions across connected software
  • OAuth grants/scopes: what an agent has actually been authorized to touch, versus what it's doing
  • Endpoint/clipboard signals: where data moves on the device level, including copy and paste behavior
  • Browser extensions: a surface they specifically call out as fragmented and easy to miss
  • Email and communications sentiment: used by a dedicated "Communications agent" to read intent/tone across collaboration tools
  • Identity and access data: correlated with behavior to catch things like shared credentials

Building a Modern Insider Risk Model for a the Synthetic Insider

When viewing AI agent risk as an insider risk, security teams need a new model to understand how these non-human, synthetic insiders lead to data leaks and breaches. Security teams know that a prompt injection attack can compromise data, but they have no tools that detect when an AI engages in a series of legitimate actions and presents an external malicious actor with information. The AI agent is the risk. The external malicious actor is the catalyst that jump starts the AI.

The Synthetic Insider Threat Matrix consists of five pillars that describe how a synthetic subject works so that security teams can identify the relationships between the conditions when trying to investigate an incident:

  • Configuration: Objectives and constraints that define behavior, including public-facing conversational systems, internal assistants, embedded AI features, event-triggered agents, autonomous agents, and misaligned directives (like HAL!).
  • Invocation: Input, even, message, tool output, memory state, or other triggers causing the subject to act. 
  • Adverse outcomes: Organizational harm like, exfiltration, unauthorized record changes, fraud, destructive action, impersonation, non-compliant output, boundary escape, harmful propagation, or unbounded resource consumption.
  • Opacity: Conditions frustrating observation, attribution, explanation, reproduction, or containment, such as concealed reasoning, evaluation-aware behavior, unreliable self-reporting, missing provenance, or gaps in logging.

Looking Inward for Accountability

AI agents and employees have a lot in common, including authorized access to systems, ability to interact with digital resources, functions to complete. However, security teams know what to look for when they investigate human insider risk, even if the process is manual or investigations are time-consuming. 

As AI agents become integrated across systems and lines of business, companies need to understand the context in which these technologies work. AI, at least so far, has no feelings to worry about, but its authorizations and access may be broader than the organization wants them to be. 

Security teams need to rethink how they monitor AI security. They need to think about whether patterns of actions match the AI’s original function. They need continuous visibility into the agent’s behavior to prevent permission drift. While the agent can act independently in many ways, it lacks the ability to monitor itself. The security team needs a tool to help manage this monitoring at the volume that the AI agents create data.

Share

Contact us

You've made a great move.
We'll be in touch shortly

Close
Watch Now