ERP Security Struggles to Keep Pace With AI Agents #AI


Agentic AI
,
Application Security
,
Artificial Intelligence & Machine Learning

CIOs Confront Rising Identity and Security Risks as AI Agents Gain Access to ERP

As AI agents gain access to ERP systems, CIOs face risks from better-equipped attackers and authorized agents that can take harmful actions. (Image: Shutterstock)

As companies connect more artificial intelligence agents to their finance, procurement and supply-chain management platforms, a new type of AI risk is emerging.

See Also: Why Traditional DLP Can’t Keep Up With AI Data Growth

Incidents are no longer only coming from attackers getting in – through stolen passwords, social engineering or unpatched servers – or from AI helping attackers hone their tools. Now, security and IT teams need to manage agents that have been properly permissioned but have the potential to take harmful actions inside critical business systems.

“The category that is genuinely new doesn’t have an attacker in it,” said Roland Palmer, CISO and vice president of security at JumpCloud. “Instead, it’s an agent with legitimate access doing what it was told. No breach, every credential valid, every permission granted.”

Recent data from ERP-threat detection and compliance vendor Onapsis shows that AI is being integrated into more enterprise resource planning software, with 58% of respondents saying they began using AI applications or agents that touch their ERP systems within the previous six months. More than 62% already use AI-generated code in ERP applications, while another 26% planned to do so by the end of 2026.

In June 2026, Onapsis polled 204 senior cybersecurity leaders at U.S. organizations with more than 1,000 employees that use SAP, Salesforce or Oracle.

While the pace of AI implementation is high, trust in these systems is lagging.

More than 70% of respondents expressed only limited or no trust in AI protecting their most critical data, and nearly 69% had limited confidence that their defenses could detect an AI-based attack. Nearly 22% of respondents reported a security incident during the previous 12 months in which attackers used AI against a business-critical platform. Another 15.2% suspected such an incident but couldn’t confirm it.

Many teams are leery. Nearly 57% of respondents said at least one business unit had objected to putting AI into the ERP environment. Security was the most resistant function, cited by 41.4%, followed by IT at 20.7%. The leading reasons were lack of confidence in AI security, cited by 75%, and compliance risk, at 71.6%.

The ERP AI Threat Landscape

Experts say AI is both helping attackers leverage old techniques in new ways and creating genuine new risk categories.

Juan-Pablo Perez-Etchegoyen, chief technology officer of Onapsis, said that while attackers once focused on operating systems, databases and web applications, many have turned to ERP systems, as AI can help them analyze code and build more specialized payloads more quickly.

“AI allows you to be able to navigate multiple huge volumes of libraries and data, and combine those into specific payloads that can be used to exploit applications,” he said.

Eamonn O’Neill, CTO and co-founder of SAP managed-services provider Lemongrass, said that while AI can aid attackers, many companies running ERP in the cloud are more protected by layered defenses around their systems. But AI-assisted social engineering remains one of the biggest threats to ERP data.

“We’re all familiar with phishing that we all spot straight away. The spelling’s bad, the layout’s bad,” O’Neill said. “AI can write letters that are as good as anybody can write.”

Palmer agreed that much of the AI-driven threat comes from attackers using AI to improve on established techniques. “The patterns aren’t changing, the polish and volume are,” he said.

Palmer identified agents producing harmful outcomes with valid credentials and approved permissions as a genuine new risk category. Authorized agents can be manipulated through prompt injection, leak sensitive data or take damaging action without breaking any systems.

How to Build Trust in Agents

Onapsis survey respondents said there were tactics that could help them have greater trust in AI agents moving through ERP systems. Stronger access management would improve trust for nearly 62% of respondents and almost 46% said that adding personal data protections would boost trust. Isolating sensitive data in sandboxes or digital twins would increase trust for about 37% of respondents.

Perez-Etchegoyen said design choices made before agent deployment can help create more trustworthy systems, rather than retrofitting security controls later.

Agents should have distinct identities, the minimum permissions needed to do their jobs and access to only the tools they need. Zero trust and least-privilege principals can reduce the blast radius if an agent is compromised or manipulated. “The incident is specifically restricted to what that agent could do,” he said.

O’Neill said agent identities should be managed like human identities, and that existing access-management systems can be extended to them, including segregation of duties and a distinction between the ability to read data and the ability to change it.

Before an agent can change an ERP record, a company should test its permissions and possible downstream effects. Otherwise, he said, “don’t switch it on.”

Palmer said his team treats each agent like a new employee. They are given an identity and minimum permissions, and access is expanded if and when it proves reliable. Agents all also need human oversight and at the end of the day, a person needs to be accountable for their choices.

“Work migrates to agents, while accountability doesn’t, shouldn’t and most importantly can’t,” Palmer said.

Gate the Feature Not the Vendor

As more ERP vendors add agents into their platforms, customers need to stay rigorous in their vetting and monitoring processes. For Palmer, that means asking four questions about every AI feature added: Can it be turned off? What identity does it act as? What does it log when it acts? Can its access be scoped separately from the user’s?

“Immature answers are workable if we plan for the immaturity using tactics like off-by-default, scoped rollout and a committed date,” he said. A vendor that provides no answer doesn’t clear the feature for deployment.

“We gate the feature, not the vendor, because you rarely get to reject an ERP, but you can sometimes defer its AI module,” he said.

For internally developed AI platforms, Perez-Etchegoyen recommends following a familiar playbook for change management, security testing, code analysis, threat modeling and defining authorizations to ensure AI-generated code doesn’t introduce vulnerabilities or faulty access checks directly into business workflows.

O’Neill, meanwhile, said he wouldn’t deploy an agent until its access had been reviewed through a standard governance, risk and compliance process, including segregation of duties checks and confirmation that its permissions match its assigned work. Those requirements become more important when an agent can write to ERP.

“Almost like you would with a person,” O’Neill said. “I would not let a person with a role that hasn’t been properly clarified access to an ERP system.”



Click Here For The Original Source.

——————————————————–

..........

.

.