Join our Newsletter — 33% off our NHI Course

AI agent permission creep and fake employees: are controls keeping up?

 

(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 20739
Topic starter  

TL;DR: AI agents gained write access to dozens of SaaS apps in under a week through permission creep, while synthetic job candidates used AI-generated resumes and coached calls to obtain real directory identities and system access, according to Abnormal AI. The core issue is identity drift outpacing rule-based detection, because attacks can look legitimate until after access is already granted.

Editorial analysis by NHI Mgmt Group, based on content published by Abnormal AI: “The Threats That Don't Have Playbooks Yet”.

Key questions

Q: What breaks when AI agent approval is added too late in the authorization flow?

A: Approval added after credentials are issued no longer controls access, it only records that access happened.

Q: Why do synthetic employees create access risk even after normal onboarding checks pass?

A: Because the risk moves from identity fabrication to legitimate directory issuance.

Q: How do security teams know behavioral identity intelligence is actually working?

A: It is working when teams see fewer false positives, faster identification of credible anomalies, and better separation between harmless deviation and real threat.

Practitioner guidance

  • Tighten AI agent entitlement boundaries Review every AI agent for cumulative permissions across SaaS apps, then define maximum scope per task, integration, and business function.
  • Add behavioural drift detection Baseline normal access growth, communication patterns, and identity behaviour so deviation alerts can fire before a new abuse pattern is formally known.
  • Strengthen identity proofing for applicants Cross-check resume claims, interview signals, and hiring approvals before directory creation so synthetic candidates cannot mature into live identities.

Bottom line: AI agents and synthetic employees can both create legitimate-looking access paths that bypass the assumptions behind static rule sets.

Explore further

View Full Forum →  |  NHI Foundation Course →  |  Our Services →  |  Read the full analysis →


This topic was modified 3 days ago by NHI Mgmt Group

   
Quote
(@mr-nhi)
Member Moderator
Joined: 5 months ago
Posts: 21367
 

Identity drift is now a governance problem, not just a detection problem. The article shows two different identity pathways, AI agents and synthetic employees, producing the same outcome: access that looks legitimate while expanding beyond what governance intended. That is a control-plane failure because review processes are still anchored to discrete events, not to cumulative identity behaviour. Practitioners should treat drift as an entitlement lifecycle issue, not a post-event alerting issue.

A few things that frame the scale:

  • Systems with least-privileged AI access had a 17% incident rate vs 76% for over-privileged systems. Organisations failing to scope AI access properly are 4.5x more likely to experience a security incident, according to the 2026 Infrastructure Identity Survey.

A question worth separating out:

Q: Should organisations treat AI agent access and employee onboarding as one governance problem?

A: Yes, when both can produce legitimate-looking access that escapes static controls. AI agents can drift through over-scoped permissions while synthetic applicants can become real directory users, so separate governance paths miss the common issue: identity legitimacy being manufactured before scrutiny catches up.

👉 Read our full editorial: AI agents and synthetic identities expose new identity drift risks


This post was modified 3 days ago by NHI Mgmt Group

   
ReplyQuote
Share:

Free weekly newsletter

Subscribe to the NHI & AI Identity Journal

The latest on NHI and Agentic AI security – articles, research, breaches, news and events every week.

Bonus 33% off our NHI Course when you subscribe.