LLMjacking is a machine identity abuse problem before it is an application security problem. Exposed AI endpoints behave like non-human identities because they can accept requests, hold privilege, and create cost without a human operator in the loop. That shifts the governance question from endpoint hardening alone to who can reach, invoke, and resell the service. Practitioners should read this as a lifecycle and access-control issue, not a niche AI anomaly.
A few things that frame the scale:
- 59% of compromised machines in a major 2025 supply chain attack were CI/CD runners rather than personal workstations, according to the State of Secrets Sprawl 2026.
- 96% of organisations store secrets outside of secrets managers in vulnerable locations including code, config files, and CI/CD tools, according to the Ultimate Guide to NHIs.
A question worth separating out:
Q: Should organisations treat AI as an application or as an identity?
A: Treat it as an identity when the AI can access data, invoke tools, or participate in workflows that affect business systems. That framing makes least privilege, just-in-time access, and lifecycle governance relevant. If you keep treating it only as an application, you will miss the access and delegation behaviours that actually create risk.
👉 Read our full editorial: LLMjacking is becoming a commercial supply chain risk for AI endpoints