TL;DR: AI-powered attacks now reach data exfiltration in 72 minutes, down from nearly five hours the year before, according to Palo Alto Networks’ 2026 Unit 42 Global Incident Response Report. That speed leaves periodic testing, manual triage, and CVSS-led prioritisation behind; continuous exposure management is now the defensive baseline.
At a glance
What this is: AI is compressing the attack lifecycle into minutes, with exfiltration now occurring in as little as 72 minutes according to the source article’s cited incident data.
Why it matters: That matters because identity, access, and control failures now become exploitable before most teams can detect, validate, and respond, especially where NHIs and delegated access create quiet attack paths.
By the numbers:
- AI-powered attacks now reach data exfiltration in under 72 minutes.
- The fastest attacks now move from initial access to data exfiltration in 72 minutes, down from nearly five hours the year prior.
- 90% of breaches still trace back to preventable, table weaknesses like misconfigured access controls, excessive permissions, and unpatched public-facing applications.
- IBM X-Force found that 56% of disclosed vulnerabilities required no authentication to exploit.
👉 Read Novee's analysis of how AI-powered attacks are compressing the breach timeline
Context
AI-powered attacks have shifted the problem from whether an attack will happen to how quickly defenders can still contain it. When data theft happens in well under two hours, the limiting factor is no longer only prevention, but whether access control, identity governance, and response workflows are designed for machine-speed abuse. That is a governance failure as much as a technical one, because the speed gap is widening faster than most control review cycles.
The identity angle is especially important where non-human identities, AI agents, service accounts, and delegated tokens sit inside the same trust fabric as human users. The article shows that attackers increasingly exploit standing privileges, trusted integrations, and automation paths that security programmes often review less often than human accounts. That is now a structural weakness, not an edge case.
Key questions
Q: What breaks when organisations rely on periodic access reviews for AI systems?
A: Periodic access reviews break when the identity scope changes between review cycles. AI-enabled workflows can create, use, and retire access faster than reviewers can validate it, so certification no longer reflects reality. That leaves stale permissions active and makes breach exposure harder to detect before it is used.
Q: Why do non-human identities become a bigger risk in AI-speed attacks?
A: Because NHIs often provide the shortest route from discovery to real access. Service accounts, tokens, and API keys are machine-readable, frequently over-privileged, and sometimes poorly owned, so an AI-driven attacker can pivot through them quickly after finding an initial weakness. Effective governance turns these identities into controlled boundaries rather than reusable entry points.
Q: What do security teams get wrong about AI-assisted attack speed?
A: They treat speed as a detection problem alone, when it is also a governance problem. If privilege is excessive, trust relationships are broad, and validation is periodic, attackers can complete the chain before alerts are actioned. Reducing blast radius matters as much as improving alert quality.
Q: How should organisations respond when attackers can exfiltrate data in under 72 minutes?
A: They should rehearse containment against machine-speed timelines, not business-hours timelines. That means rapid privilege revocation, live evidence capture, isolation of exposed integrations, and clear decision authority for identity and response teams. If those steps are manual and sequential, the attacker usually finishes first.
Technical breakdown
How AI compresses reconnaissance and initial access
AI agents can process far more telemetry, application context, and public exposure data than a human operator in the same time window. That lets attackers move from broad scanning to targeted reconnaissance, then to initial access through exposed services, public-facing applications, or identity weak points. The more connected an environment is, the more AI can use correlation to identify which assets matter and which weaknesses are reachable. In practice, this reduces the time between discovery and exploitation to a level that invalidates periodic assessment assumptions.
Practical implication: teams need continuous exposure detection and validation, not scheduled scans alone.
Why identity-based attack paths are now the quietest route
The article shows that attackers increasingly prefer identity techniques because they create less network noise than obvious malware delivery. Service tickets, over-privileged service accounts, session tokens, and delegated access can all be abused without triggering the same alerts as traditional intrusion chains. This is where non-human identity governance becomes central: NHIs often have persistent permissions, weak monitoring, and unclear ownership. When AI is used to chain those weaknesses, the result is fast lateral movement with minimal visible friction.
Practical implication: inventory NHIs, reduce standing privilege, and monitor token and service-account use as first-class identity events.
How AI changes lateral movement and exfiltration at machine speed
Once inside, AI can chain small misconfigurations into a route toward higher privilege or sensitive data. The article describes attackers combining an over-privileged account with an unpatched internal API, then using automated scripts to collect data and suppress defensive visibility. That pattern matters because the defender is now competing against orchestration, not isolated actions. A single AI-assisted operator can coordinate discovery, escalation, collection, and exfiltration in one continuous workflow rather than as separate human tasks.
Practical implication: correlate identity, endpoint, and application signals in real time, and verify that escalation paths are actually blocked.
Threat narrative
Attacker objective: The attacker objective is rapid data exfiltration achieved before defenders can complete detection, validation, and containment.
- Entry begins with AI-assisted reconnaissance that identifies reachable vulnerabilities, exposed identities, and public-facing services faster than human teams can review them.
- Escalation occurs when attackers abuse identity-based access such as service tickets, service accounts, session tokens, or over-privileged automation paths to move quietly through the environment.
- Impact follows when AI coordinates lateral movement, data collection, and exfiltration fast enough to outrun normal incident response workflows.
Breaches seen in the wild
- MITRE ATT&CK Enterprise Matrix — MITRE ATT&CK Enterprise — adversary tactics and techniques, threat detection, attack chain mapping, credential access, lateral movement, privilege escalation.
- Coupang Signing Key Breach — Unrevoked signing key credentials expose 33.7 million records after employee offboarding failure at Coupang.
Read our 52 NHI Breaches Analysis report for a comprehensive view of breaches impacting Non-Human Identities including AI Agents.
NHI Mgmt Group analysis
AI speed turns control lag into the primary breach condition. The article’s core finding is not simply that attackers are faster, but that the defender’s validation and escalation cycles are slower than the attack path itself. That creates a control gap between detection and containment that periodic testing cannot close. For identity programmes, that means the decisive question is not whether a control exists, but whether it can still act before a machine-speed attacker completes the kill chain.
Standing privilege is now a force multiplier for AI-assisted attackers. Service accounts, tokens, and delegated automation paths remain attractive because they are persistent, low-friction, and often less scrutinised than human credentials. The article correctly surfaces that most breaches still exploit preventable access weaknesses. For NHI governance, the implication is clear: ownership, privilege scope, and usage visibility are the controls that now determine blast radius.
Machine-speed offense exposes a governance debt in application and identity programmes. The source shows that attack chains are increasingly assembled from ordinary weaknesses such as over-privilege, exposed integration points, and unpatched public services. Governance debt: the backlog created when access reviews, patching, and service-account oversight are designed for a slower threat model than the one actually in play. Practitioners should treat that backlog as an exposure metric, not an administrative nuisance.
AI-augmented offense collapses the separation between cyber risk and identity risk. Attackers do not need novel malware when they can abuse identity trust, automation, and delegated authority at scale. That means IAM, PAM, and NHI governance are now central defensive controls for cloud, application, and AI-enabled environments alike. The practical conclusion is that identity assurance and attack surface management must be run as one programme, not parallel ones.
Continuous validation is becoming the only meaningful assurance model. When attacks reach exfiltration in 72 minutes, evidence from quarterly reviews arrives too late to change the outcome. That does not make prevention irrelevant, but it does make exploitability testing, privilege minimisation, and response rehearsal part of the same operational loop. Practitioners should expect security assurance to shift from retrospective reporting to live control verification.
From our research:
- Only 1.5 out of 10 organisations are highly confident in their ability to secure NHIs, compared to nearly 1 in 4 for securing human identities, according to Astrix Security & CSA.
- From our research: Lack of credential rotation is cited as the top cause of NHI-related attacks by 45% of organisations, followed by inadequate monitoring and logging at 37% and over-privileged accounts at 37%, according to Astrix Security & CSA.
- Forward-looking analysis: Use the NHI Lifecycle Management Guide to tighten provisioning, rotation, and offboarding before machine-speed abuse turns governance lag into loss.
What this signals
Governance lag is now an exposure metric. If a programme still depends on periodic review cycles, it is effectively assuming attackers will wait for the calendar. They will not. The operational shift is toward continuous entitlement validation, continuous exposure testing, and faster revocation for NHIs, especially where automation can reach production systems.
The most exposed programmes will be the ones that treat AI tools as productivity additions rather than identity-bearing systems. Once an AI assistant, CI/CD worker, or service token can modify data or call external APIs, it belongs inside the same access governance model as any other privileged identity. That is where OWASP NHI Top 10 and the MITRE ATT&CK Enterprise Matrix become useful for mapping how abuse actually unfolds.
Blast-radius first: the practical control objective is no longer perfect prevention. It is limiting how far a compromised identity, token, or integration can move before containment closes the path. That means tighter privilege scope, cleaner offboarding, and evidence that access is truly task-bound rather than assumed safe because it is automated.
For practitioners
- Compress identity review cycles Move service-account, token, and integration review from periodic audit cadence to continuous monitoring with ownership, scope, and last-use checks. Prioritise accounts that can call external APIs or reach sensitive internal systems.
- Eliminate standing privilege where automation touches sensitive assets Replace always-on access with task-scoped entitlement for AI assistants, CI/CD automation, and backend services that can modify data or invoke administrative functions. Revalidate every privileged path used by machine actors.
- Instrument the identity layer for machine-speed abuse Correlate service ticket use, token issuance, delegated access, and anomalous API calls in near real time so you can spot quiet escalation paths before exfiltration completes.
- Test containment against 72-minute attack windows Run response exercises that assume exfiltration can complete within a single incident meeting. Measure whether containment, evidence capture, and privilege revocation can happen before the attacker closes the delegation chain.
- Map AI-enabled workflows to their real blast radius Document which AI coding tools, copilots, and automation pipelines can read secrets, write code, or reach production systems. Remove unnecessary permissions and separate development trust from operational access.
Key takeaways
- AI-assisted attacks have shortened the time between access and exfiltration to a point where periodic controls are no longer sufficient.
- The most dangerous weakness is not novelty, but standing privilege and weak visibility across non-human identities and delegated access.
- Security programmes now need continuous validation, faster identity revocation, and tighter blast-radius control to match machine-speed offense.
Standards & Framework Alignment
This section maps relevant standards and security frameworks to the operational risks and controls described in this guidance.
MITRE ATT&CK address the attack and risk surface, while NIST CSF 2.0, NIST SP 800-53 Rev 5, CIS Controls v8 and NIST AI RMF set the governance and control requirements practitioners need to meet.
| Framework | Control / Reference | Relevance |
|---|---|---|
| MITRE ATT&CK | TA0006 , Credential Access; TA0008 , Lateral Movement; TA0010 , Exfiltration | The article centres on AI-assisted credential abuse and fast lateral movement to data theft. |
| NIST CSF 2.0 | PR.AC-4 | Access control and least privilege are central to the article's breach patterns. |
| NIST SP 800-53 Rev 5 | IA-5 | Authenticator management governs the secrets and tokens attackers abuse in these attack chains. |
| CIS Controls v8 | CIS-5 , Account Management | The article repeatedly shows how unmanaged accounts and privileges drive compromise. |
| NIST AI RMF | MANAGE | AI systems and agentic workflows introduce governance and risk controls that need formal management. |
Map exposed identities and automation paths to these tactics and prioritise the controls that break the chain early.
Key terms
- Machine-speed threat: A threat that progresses faster than manual identity controls can reasonably observe or stop. In practice, it turns short-lived access misuse into a governance problem because the window for detection, decision, and revocation may close before the control cycle completes.
- Standing Privilege: Standing privilege is access that remains active even when no immediate task requires it. For NHI programmes, it is a common failure mode because long-lived credentials and persistent roles create unnecessary exposure. Reducing standing privilege usually means tighter expiry, on-demand access, and clearer review of who or what still needs access.
- Non-Human Identity (NHI): A digital identity assigned to a non-human entity such as a software application, service account, API key, bot, machine, or AI agent that enables it to authenticate and interact with systems without direct human involvement. NHIs now outnumber human identities in most enterprises by 25 to 50 times.
- Blast Radius: The potential scope of damage if a specific credential or identity is compromised. Identities with broad permissions have a larger blast radius and represent a higher priority for least-privilege enforcement and security controls.
What's in the full article
Novee's full article covers the operational detail this post intentionally leaves for the source:
- The full attack timeline with stage-by-stage examples of how AI compresses reconnaissance, access, and exfiltration.
- The practical differences between periodic testing, continuous exposure management, and offensive validation at machine speed.
- The source's examples of AI-related supply chain compromise, identity abuse, and application attack paths.
- The vendor's remediation framing for teams trying to adapt to faster attack cycles.
Deepen your knowledge
The NHI Foundation Level course, the industry's only accredited NHI security programme, covers NHI governance, machine identity security, and secrets management. It helps practitioners connect identity controls to the broader security programme they already run.
Published by the NHIMG editorial team on August 1, 2026.
NHI Mgmt Group — the independent authority on Non-Human Identity, IAM, and Agentic AI security. nhimg.org