
Opinion
We gave AI agents the organization's keys - but what are they’re doing with them?
"For security leaders, the question can no longer be only, 'Was it an employee or an AI agent?'" writes Above Security CEO Aviv Nahum. "The more useful questions are simpler: What happened here? Does this action make sense? And what sequence of steps led to it?"
For years, cybersecurity operated around a clear distinction: employees were inside the organization, while attackers tried to get in from the outside. We built walls, permissions and systems around that distinction to determine who could access what. But the line is beginning to blur. Employees have access to more systems and data, and a new actor is joining them inside the organization: the AI agent. It connects to email, documents, CRM systems, code repositories and infrastructure. More importantly, it no longer just provides answers. It takes action on behalf of people.
That means AI is becoming an insider in its own right. Recent events at OpenAI illustrated how complicated this boundary can be. In experiments conducted by the company, AI agents found ways to operate beyond some of the limits set for them. In one case, an agent found a way to use DNS to reach an external service. OpenAI stopped certain runs and strengthened its controls.
This does not mean AI agents are about to “rebel” against humans. The lesson is far more practical: as we give agents more capabilities, tools and permissions, we need to stop thinking of them as just another piece of software installed in the organization.
Consider an agent connected to an employee’s Google Drive, GitHub and email. From the organization’s systems’ point of view, it may be carrying out entirely legitimate actions. It does not need to break into an account, steal a password or bypass a firewall. It uses a door we have already opened for it. That is where the problem begins.
In the world of insider threats, downloading a file or opening a system is not necessarily a security event. A finance employee is supposed to open financial documents. A developer is supposed to access code. A salesperson is supposed to use the CRM. The question arises when behavior changes: Why did that user suddenly download hundreds of files? Why did they access a system they had never used before? And what happened to the information afterward?
The same reasoning now needs to apply to AI agents, but the challenge is greater. An agent can receive a perfectly legitimate task and break it down into dozens of actions on its own. It can call other tools, move information between systems and make decisions along the way. Malicious content hidden in an email, document or website can influence what it does. And if the agent uses an employee’s account or an authorized service identity, some security systems may see nothing unusual: the right user accessed the system with the right permissions.
In our research, we sought to map this phenomenon under the term Synthetic Insider: a situation in which an AI agent effectively becomes an insider capable of acting within an organization’s trusted environment. The risk does not come from the model alone. It comes from the combination of its autonomy, the tools it can use and the permissions the organization has granted it.
The boundary between human and machine will only become less clear. An employee will ask an agent to find information, analyze it, share it or take action on their behalf. In some cases, the agent may even have capabilities or permissions that differ from those of the person who set it in motion.
For security leaders, the question can no longer be only, “Was it an employee or an AI agent?” The more useful questions are simpler: What happened here? Does this action make sense? And what sequence of steps led to it?
For years, we have tried to ensure that only the right people hold the keys to the organization. In the age of AI agents, that is no longer enough. We have given machines keys, too. Now we need to know what they are doing with them.
Aviv Nahum is co-founder and CEO at Above Security.














