Security Teams Gain from AI Yet Fear Autonomous Agents

Security Teams Gain from AI Yet Fear Autonomous Agents
Security Teams Gain from AI Yet Fear Autonomous Agents (Image Credit: AI-generated by Ian Murphy using Adobe Firefly)Autonomous AI agents are a dual-use weapon for cybersecurity teams. They have improved productivity across cybersecurity teams. However, they are also emerging as one of the most significant cybersecurity threats facing organisations. This comes from a survey of 134 people that was conducted by Exabeam during Infosecurity Europe in June. It gives an insight into how practitioners now view the benefits and risks of AI.

Findlay Whitelaw, Field CISO at Exabeam (Image Credit: LinkedIn)
Findlay whitelaw, field ciso at exabeam

Findlay Whitelaw, Field CISO at Exabeam, said, “As organisations deploy AI across the business, they’re introducing a new class of trusted identities.

“AI agents can access systems, process sensitive information and make decisions autonomously using legitimate credentials. Security teams aren’t just protecting people anymore. They’re securing trusted identities, whether they’re human or AI.”

A Limited Snapshot

This is a good point-in-time survey, taken at a key tradeshow where Exabeam was able to verify attendees. It asked just four questions:

  • Has AI impacted your security team’s productivity?
  • Which poses the greatest threat today?
  • Have insider threats changed over the past 12 months?
  • Does executive leadership underestimate insider threat risk?

The survey lacked qualitative follow-up with respondents. With just four questions, it would have been a real benefit to get more detail on what the answers showed.

Productivity Gains are Real and so are the Threats

The numbers are important. They show a clear productivity gain from AI. 36% saw significant improvement, and 52% said it was moderately improved. Only 1% said it slowed their processes.

A qualitative follow-up would have asked several pertinent questions. Where was the productivity gain? Was it in the analysis of logs and data? Did it speed up the assessment of risk? Is it used to generate reports? What training was needed to help analysts get the most out of the AI tools? What tools were used?

40% still see external threat actors as the greatest threat. However, the landscape is shifting. 25% now view autonomous AI agents as a growing threat. This places them just behind compromised insiders at 26%.

Gravitee reports that only 30% of organisations are very prepared to manage autonomous agents as distinct authenticated users. That means many organisations cannot distinguish between a compromised employee and an AI using their credentials.

The disconnect lies in the insider threat. The last two questions address that directly. 46% see an increase in insider threat, but again, this should be caveated with limited distinction between users and AI. Additionally, there is a problem with how leadership see insider threats. 24% significantly underestimate it, and another 49% underestimate to a lesser degree. That’s 73% not getting it.

What is Exabeam’s Approach?

In September last year, it integrated Google Agentspace and Google Cloud’s Model Armor telemetry into the New-Scale Security Operations Platform. It enables security teams to monitor, detect, and respond to threats from AI agents acting as digital insiders.

In January, it announced its connected AI security system. That is integrated into Google Gemini Enterprise. It delivers real-time visibility into agent actions, enabling secure AI adoption and faster response to emerging threats.

Two weeks ago, it boosted its Agent Behaviour Analytics (ABA) with new capabilities. This is about greater visibility of AI. It addresses the shift to autonomous agents making decisions, accessing data, and executing tasks across the enterprise. Importantly, it also acknowledged the need for enterprises to make AI agents first-class identities. That allows it to know what is an agent and what is a human.

That recent release also allows organisations to address the risks in the OWASP Top 10 for Agentic Applications 2026. That list shows how big an issue malicious AI abuse is.

The findings align closely with the security challenges Exabeam is positioning its platform to solve.

How Does This Match Industry Reports?

The numbers in this survey match what other vendors and reports show, and that is important. Despite being short, it seems to be an accurate reflection of a greater area of concern.

The Cloud Security Alliance and Darktrace published the State of AI Cybersecurity 2026 report in February. It drew on responses from 1,500 security leaders. 44% were concerned with the security implications of third-party LLMs such as ChatGPT and Copilot.

Another concern (92%) was the use of AI agents across the workforce and their impact on security. From a benefit perspective, anomaly detection (72%) through advanced pattern matching was the biggest gain.

Kiteworks also identified a disconnect between executives and practitioners. The company’s State of AI Cybersecurity 2026 report reveals a disconnect between executives and practitioners. 56% of CISOs strongly agree that AI improves defensive capabilities, while only 25% of hands-on security operators feel the same.

In his 2026 cybersecurity predictions, Forrester’s Paddy Harrington expects a public breach caused by AI this year. He believes that the fallout will result in employee dismissals.

He wrote, “Since its launch in 2022, GenAI has caused several data breaches or affected the integrity or availability of sensitive data. As companies begin building agentic AI workflows, these issues will only become more prevalent.”

Enterprise Times: What Does This Mean

Agentic AI has a lot of potential but comes with significant risk. How organisations choose to handle this will be interesting. You cannot just change your processes and hope that is good enough.

What you need is visibility of what the AI is doing. That is different to the visibility of how AI makes a decision. This is about identifying every agent, knowing what it has access to and being able to track its behaviour.

While Exabeam has a long history in User Behavioural Analysis and is now applying that to AI, it is not the only player in the market. Splunk also addresses AI security monitoring, although its approach differs from Exabeam’s Agent Behaviour Analytics.

Securonix is a direct competitor in this space with its Agentic Mesh and Sam. It also sees AI and humans working together in the SOC, as Carl Pharoah talks about in this Enterprise Times podcast.

As AI agents become more autonomous, the likelihood of a high-profile AI-related breach increases. What happens then? How many CISOs will realise they have underestimated the insider threat because they only think about people? How will they prove to the board that they are able to spot the AI risk before it becomes front-page news?

The post Security Teams Gain from AI Yet Fear Autonomous Agents appeared first on Enterprise Times.


Discover more from RSS Feeds Cloud

Subscribe to get the latest posts sent to your email.

Discover more from RSS Feeds Cloud

Subscribe now to keep reading and get access to the full archive.

Continue reading