Notebookcheck Logo

Autonomous AI hacking agents outrank human hackers

Autonomous AI hacking agents outrank human hackers.
ⓘ Freepik.com
Autonomous AI hacking agents outrank human hackers.
A new Exabeam-commissioned survey finds 48% of security leaders rank autonomous AI agents with excessive access as their top threat, ahead of hackers and insiders.

As ransomware numbers rise, enterprise security teams are facing a rapid shift in how they rank threat vectors. New research commissioned by Exabeam and conducted by Sapio Research found that 48% of IT and security leaders now consider autonomous AI agents with excessive or unintended system access to be their single greatest threat, ahead of external hackers, compromised insiders, and malicious employees.

The survey polled 600 security and finance decision-makers across the US, Canada, the UK, France, Germany, the Netherlands, and Australia, all from organizations with 500 or more employees. External threat actors came in second at 28%, while compromised insiders and malicious human employees each accounted for 12%.

Why agentic systems slip past traditional defenses

Exabeam defines the AI agents in question as goal-driven, autonomous systems that can access enterprise resources and act with limited human oversight, distinct from conversational chatbots. Because these agents typically operate using legitimate administrative credentials, API keys, and elevated privileges, actions taken by a rogue or misconfigured agent can bypass conventional perimeter defenses and user behavior baselines without triggering standard security alerts. The risk does not require malicious intent on the agent's part, only unchecked access.

Monitoring struggles to keep pace with adoption

As organizations expand their use of autonomous AI across business operations, security vendors are moving to build out dedicated agent behavior analytics to track machine decision-making alongside existing human access logs. Exabeam's report, titled The Agentic Insider: From Monitoring to Understanding, notes that while companies are already expanding their AI agent monitoring efforts, many still struggle to understand agent behavior across systems and business context fully.

It's worth noting the survey measures perceived risk among decision-makers rather than confirmed incident data, so it shouldn't be read as evidence that AI agents have overtaken hackers in actual breach volume. Still, the finding points to a clear shift in priorities: as agents gain broader access to enterprise systems, closing the gap between granting that access and actually monitoring how it's used is becoming a pressing concern for security teams.

Juggling updates for Windows administrators

The finding lands at a moment when enterprise IT teams are already juggling a steady stream of Windows updates and patches across their fleets. Microsoft's own recent preview update, KB5124010, brought a mix of new features and two disclosed known issues, a reminder that keeping baseline systems patched and stable is still a full-time job even before AI agents enter the picture. As organizations layer autonomous agents on top of that existing patch and access management workload, the same administrators will need to extend their oversight from operating systems and endpoints to the agents now operating alongside them.

Google LogoAdd as a preferred source on Google
Mail Logo

No comments for this article

Got questions or something to add to our article? Even without registering you can post in the comments!
No comments for this article / reply

static version load dynamic
Loading Comments
Darryl Linington, 2026-09-24 (Update: 2026-09-24)