As organizations recognize Insider Threat Awareness Month this September, cybersecurity leaders are drawing attention to a broader set of risks emerging as AI becomes embedded across the enterprise. Autonomous agents are gaining access to sensitive systems, employees are feeding corporate data into GenAI tools, and deepfakes and synthetic identities are making it easier for outsiders to obtain or exploit legitimate access.
The result is a changing definition of the insider threat, increasingly centered on what happens after an identity, human or otherwise, is trusted.
AI agents represent perhaps the newest example. Businesses are rapidly deploying autonomous systems capable of interacting with corporate applications and data, potentially allowing mistakes or unintended actions to spread much faster than a comparable human incident.
“Organizations are giving AI agents broad access to corporate systems and data, and unlike human insiders, they move at machine speed,” said Arvind Parthasarathi, CEO and founder of CYGNVS. “An agent pursuing the wrong objective — or the right objective without proper guardrails — can create a security, legal or regulatory crisis before the human response team even understands what happened.”
Parthasarathi said companies need to determine in advance who can shut down an agent, how it should be contained and what evidence must be preserved if something goes wrong.
Human employees are creating another AI-related challenge, often without malicious intent. The widespread availability of GenAI has made it easy for workers to use unauthorized tools to summarize documents, analyze information or write code, potentially taking sensitive corporate data with them.
“The bigger risk today is far less dramatic and far more common: well-meaning employees pasting sensitive data, source code, or customer information into GenAI tools because it’s faster than the approved workflow,” said Arti Raman, CEO of Portal26. “That’s not malice, it’s a visibility gap, and it’s happening inside nearly every enterprise right now.”
Raman argues that simply blocking AI is unlikely to solve the problem. Instead, security teams need visibility into how employees are using the technology so risky behavior can be identified before sensitive information is exposed.
Meanwhile, attackers are using the same advances in AI to blur the line between an outsider and a legitimate employee.
“GenAI, deepfakes and synthetic identities have fundamentally changed the hiring threat model. Bad actors can now pass an interview, get hired and receive legitimate credentials, without having to break in,” said Bojan Simic, CEO and co-founder of HYPR. “The security failure happens when we authenticate a credential without first establishing that it belongs to the right human.”
Simic said insider threat defenses increasingly need to begin before an employee’s first day, with stronger identity verification connected directly to the process of issuing corporate credentials.
Deepfake technology can also target employees who are already inside the organization. Publicly available video and information about executives can give attackers the raw material to impersonate senior leaders and manufacture seemingly legitimate requests.
“Executive impersonation is a growing insider threat method, as attackers can now combine publicly available video with knowledge of an organization’s leadership, processes and culture to create highly convincing requests,” said Amit Shuster, VP of Product and Engineering at Vetric. “A familiar face and voice can make an urgent instruction from a CEO to transfer funds, disclose sensitive information or bypass a control feel legitimate.”
Organizations therefore cannot rely on the apparent authenticity of a video or voice as proof that a request is genuine. Shuster said investigators also need visibility into how impersonation content is being created and distributed across platforms.
Finding evidence of these threats creates its own challenge. Insider activity takes place through systems and accounts that organizations already trust, meaning suspicious behavior may only become apparent when investigators connect multiple pieces of information.
“The warning signs rarely live in a single alert or data source,” said Mike Wade, VP of Customer Success at Gravwell. “They emerge when security teams can connect activity across identity, network, endpoint, cloud and other telemetry over time.”
Wade said organizations should preserve broad security telemetry rather than assuming they know in advance which information will matter during an investigation. Once data has been filtered out or discarded, critical context may be impossible to reconstruct.
The common thread across these threats is legitimate access. An attacker may obtain it by getting hired under a false identity. An employee may misuse it unintentionally through an AI tool. A deepfake may convince someone with legitimate privileges to take an unsafe action. Or an autonomous agent may already possess the permissions needed to cause harm.
For security teams, Insider Threat Awareness Month is becoming more about understanding how trusted access can be obtained, manipulated and misused in an increasingly AI-driven enterprise.
Join our LinkedIn group Information Security Community!
