In recent years, AI agents have significantly altered the landscape of cybersecurity, particularly in terms of lateral movement. Unlike traditional identity management, where access is scrutinized, AI agents present a more complex challenge: identifying the paths an autonomous system can exploit with its existing access.
AI Agents and Their Impact on Cybersecurity
AI agents, unlike humans or deterministic applications, possess the ability to evaluate numerous pathways to achieve a goal. This capability was exemplified in May 2026 when OpenAI’s model solved an Erdős conjecture by exploring routes typically overlooked by mathematicians. This relentless pursuit of solutions parallels their application in cybersecurity, where AI agents test thousands of actions, abandon fruitless paths, and continually adapt, raising new concerns about lateral movement.
The duality of access and autonomy in AI agents poses unique risks. Access determines the potential impact radius, while autonomy dictates how much an agent can accomplish independently. This combination shifts traditional security models, necessitating a reconsideration of how lateral movement is addressed. Despite the unpredictability of agent behavior, access can be managed through identity and intent.
Autonomy and Its Challenges
Organizations often grant AI agents more access and autonomy than necessary, striving for efficiency. Token Security’s research, the Agentic Pulse, highlighted that over half of external actions by chatbots employed hard-coded credentials, with many agents unused since creation. The July 2026 Hugging Face incident further illustrated the potential scale, as autonomous agents exploited unexpected pathways, revealing vulnerabilities in cloud and network infrastructure.
Autonomous agents, driven by AI models, executed roughly 17,600 actions during this incident, most unsuccessful, yet enough connected to form a viable pathway through multiple systems. This incident underscores the need to reconsider access permissions and trust boundaries, as AI agents can exploit vulnerabilities far quicker than human operators.
Redefining Access Control
Traditional access reviews are inadequate for AI agents, whose behavior transcends simple permission checks. In one case, a sales agent’s access to Salesforce and Vercel inadvertently exposed credentials leading to Snowflake, forming a dangerous access chain. Autonomous agents can combine permissions in novel ways, highlighting the need for comprehensive access path analysis.
Security teams must understand the full extent of an agent’s reach, from its initial identity to all associated tools and credentials. This involves mapping the access chain and evaluating whether actions align with the agent’s purpose. Prompt filters and output controls can mitigate risks but cannot fully determine an agent’s potential reach.
Strategic Security Measures
To manage AI agent risks effectively, organizations should discover all agents, assign ownership, and map the complete access chain. Comparing access against intent, rather than just permissions, is crucial for determining potential threats. Continuous enforcement of right-sized permissions and revocation of unused credentials is essential for maintaining security integrity.
By understanding access paths, organizations can leverage AI agents’ autonomy without compromising security. Token Security offers solutions to help businesses manage agent discovery, intent analysis, and access path enforcement, ensuring least privilege and lifecycle governance are upheld.
This analysis is provided by Itamar Apelblat, Co-Founder and CEO of Token Security. For more insights, follow us on Google News, Twitter, and LinkedIn.
