Kiteworks Agent Marketplace
Which AI assistant do you use?
Brief

When access outpaces governance: the real insider risk of the agentic era

Security leaders now rank AI agent access as their single greatest threat, and the workable answer is policy evaluated at the point of access rather than permissions decided once in advance.

  • Governance & Retention
  • Access & Sharing
  • Compliance

Enterprises are handing AI agents the keys to their most sensitive content faster than anyone is writing the rules for how those keys get used. That gap between deployment speed and governance maturity is quietly becoming the defining security problem of 2026, and security leaders now say so themselves.

Agent access just became the top-ranked threat

In a study fielded by Sapio Research on behalf of Exabeam in June 2026 and published September 16, 2026 — The Agentic Insider: From Monitoring to Understanding, surveying 600 security and finance decision-makers across seven countries — 48% of security leaders named AI agents operating with excessive, compromised, or unintended access as the single greatest threat facing their organization today. That puts agent access ahead of external threat actors (28%), and well ahead of compromised insiders and malicious insiders (12% each). For the first time in a threat category security teams have tracked for years, an infrastructure problem outranks an adversary.

What actually counts as an "agent"

It matters how the study defines its subject. Its authors are careful to separate "goal-driven, autonomous systems that can access enterprise resources and take actions with limited human intervention" from "conversational chatbots." That distinction is the whole problem in miniature. A chatbot answers inside a chat window; an agent acts — reading a contract repository, pulling a customer record, drafting and sending a message, updating a system of record — and it does so, by design, with limited human intervention. As Exabeam's Gabrielle Hempel put it in a related analysis, an agent can be "valid identity, authorized access, expected tools, no attacker" and still produce an incident. The more autonomy an organization grants an agent — which is the entire economic case for deploying one — the less realistic it becomes to govern that agent by deciding in advance, for every task, exactly what it may touch.

Why manual scoping breaks down

That is the trap most organizations are walking into. The instinctive response to "the agent has too much access" is to scope it down: narrower roles, tighter service accounts, per-agent permission reviews. That works for the first agent. It does not work for the fiftieth, and it especially does not work when the same agent's task changes hour to hour, or when the content estate it needs to reach spans email, file shares, CRM records, and structured data nobody inventoried with agents in mind. Manual scoping assumes a static, enumerable set of resources and a static, enumerable set of tasks. Agentic AI violates both assumptions continuously.

Monitoring isn't the same as understanding

Exabeam's data shows the strain this creates even where governance hasn't been neglected. Sixty percent of security leaders have stood up dedicated AI security or governance tooling, and 56% have extended existing SIEM and detection platforms to cover agents. But 27% still cite limited behavioral context and correlation as their biggest monitoring gap, and as Exabeam's Chief AI and Product Officer Steve Wilson observed, "organizations are making meaningful progress in monitoring AI agents, but monitoring activity isn't the same as understanding behavior." Monitoring tells you what an agent did after it did it. It does not tell you, before the fact, whether it should have been allowed to.

The budget problem hiding behind the security problem

A second constraint compounds the first: money. Fifty-five percent of security leaders say they have delayed or scaled back a security initiative because they could not frame the risk in financial terms their CFO would accept — even though 93% report security and finance are broadly aligned on risk tolerance, and 81% say their CFO understands cybersecurity risk in general terms. The gap isn't trust; it's translation. "CFOs rarely question whether a cybersecurity risk is real," Exabeam CFO Mike Byron noted; the harder task is "understanding how investment reduces risk in measurable business terms." A governance model that can point to specific, logged decisions — this identity was denied this data for this purpose, on this date — translates far more easily into a budget conversation than a monitoring dashboard does.

The missing layer: policy decided at request time

Put those pieces together and the shape of a workable answer comes into view. It isn't better monitoring of agents after they act, and it isn't a larger spreadsheet of per-agent permissions decided before they act. It's a policy layer that sits at the point of access itself and evaluates, for every request, whether this data may be used for this purpose by this identity — human or agent — before anything moves. That decision has to be made dynamically, from the attributes of the data, the identity, and the requested action, rather than settled once in advance for a role that will inevitably go stale. And every decision, allow or deny, needs to be logged, so the record of enforcement doubles as the evidence auditors and CFOs both need.

This is the direction Kiteworks has built toward with its Data Policy Engine, which evaluates data, identity, and requested action in real time against policy and enforces a directive — block, view-only, justification required, or allow — logging every decision to an immutable audit trail. Extended specifically to agents, Kiteworks describes the same checkpoint applying before any AI request touches data: identity verification, attribute-based policy evaluation, and audit logging, with agent identity tied back to the human who authorized it. The company's own framing of the stakes is blunt: AI agents "exercise zero independent ethical judgment. They will access any data they are not explicitly prevented from touching."

That's not a reason to slow down agent deployment. It's a reason to stop treating access as something decided once, and start treating it as something decided every time.

If you are working through what a policy boundary should look like for agents in your own environment, email sales@kiteworks.com or start a conversation. You do not need Claude or MCP setup to ask. See the agent catalog and assistant support.