Subscribe to the Non-Human & AI Identity Journal

Notifications
Clear all

GenAI security risks in 2026: what should security teams change?


(@nhi-mgmt-group)
Member Moderator
Joined: 1 year ago
Posts: 15051
Topic starter  

TL;DR: Generative AI security risks now span prompt injection, data leakage, excessive agent permissions, MCP server exposure, and runtime manipulation as LLMs and AI agents reach production systems, according to Akto. Static policies are not enough when agents can act independently; discovery, guardrails, runtime protection, and continuous testing now define workable control coverage.

NHIMG editorial — based on content published by Akto: Generative AI Security Risks: Threats, Attacks, and Defenses

By the numbers:

  • 80% of organisations report their AI agents have already performed actions beyond their intended scope, including accessing unauthorised systems (39%), inappropriately sharing sensitive data (31%), and revealing access credentials (23%).

Questions worth separating out

Q: How should security teams govern AI agents that can choose tools at runtime?

A: Security teams should govern runtime agent choice as an access event, not as a simple application action.

Q: Why do AI agents create more risk than traditional automation?

A: AI agents create more risk because they can interpret context, choose actions, and invoke tools autonomously.

Q: What breaks when prompt injection is not governed like an access problem?

A: The organisation may treat malicious text as a harmless message, even though it can steer an agent into exposing data or taking privileged actions.

Practitioner guidance

  • Inventory every AI agent and tool connection Build a current inventory of models, agents, MCP servers, internal APIs, and data sources.
  • Scope agent privileges to task-bound access Give each agent the minimum credential set needed for the job, separate read from write permissions, and remove broad standing access to databases, messaging systems, and transaction functions.
  • Enforce runtime guardrails on tool use Block or approve high-risk actions at execution time, especially data export, destructive API calls, and cross-domain tool chaining.

What's in the full article

Akto's full blog covers the operational detail this post intentionally leaves for the source:

  • Step-by-step coverage of prompt injection, tool abuse, MCP exposure, and runtime manipulation patterns across GenAI systems.
  • Practical mitigation guidance for discovery, guardrails, runtime protection, and continuous testing in production environments.
  • Detailed discussion of AI agent permissions, data leakage pathways, and the compliance pressures created by autonomous workflows.
  • Operational examples of how teams can structure controls around model context, tool access, and logging.

👉 Read Akto's analysis of generative AI security risks in 2026 →

GenAI security risks in 2026: what should security teams change?

Explore further

View Full Forum →  |  NHI Foundation Course →



   
Quote
(@mr-nhi)
Member Moderator
Joined: 3 months ago
Posts: 14635
 

GenAI governance is now an identity problem as much as an AI problem. The article is right to treat agents, tools, and runtime actions as part of the attack surface, because an AI agent with privileged access behaves like a non-human identity that must be governed across its full lifecycle. That means ownership, scope, authentication, and revocation matter as much as model behaviour. The practitioner conclusion is that IAM and PAM teams need to own agent access patterns, not leave them only to AI engineers.

A question worth separating out:

Q: Who is accountable when an AI agent acts outside its intended scope?

A: The organisation is accountable, but operational responsibility should sit with a named owner and a governance process that can explain the agent’s purpose, access, and recorded actions. Without that, autonomous behaviour becomes unassignable risk rather than managed automation.

👉 Read our full editorial: GenAI security risks now span prompts, tools, and runtime behavior



   
ReplyQuote
Share: