Site navigation

Over-priviledged AI Systems Driving Security Incidents

Elizabeth Greenberg

,

ai security incidents
“The data is clear,” said Ev Kontsevoy, CEO at Teleport. “It’s not the AI that’s unsafe. It’s the access we’re giving it.”

Enterprises deploying AI systems with excessive permissions are experiencing 4.5x more security incidents than those that enforce least-privilege controls according to a new research report from Teleport. The report warns that most enterprises are dramatically underprepared for the security consequences.

Based on interviews with 205 CISOs, security architects, and platform leaders, The 2026 State of AI in Enterprise Infra finds that AI is rapidly shifting into production infrastructure without identity controls keeping pace, creating a growing and measurable security gap.

The widening gap between AI adoption and AI readiness threatens to undermine the very efficiency gains organisations are chasing.

“AI has broken the camel’s back. The rapidly increasing complexity of computing infrastructure has been putting immense pressure on identity management in recent years. Most organisations have more groups and roles than employees, for example,” said Ev Kontsevoy, CEO at Teleport. “And deploying non-deterministically behaving agents on top of this mess comes with unpleasant consequences.”

The report reveals that AI adoption is already ubiquitous, but governance and identity controls have not kept pace.

While 92% of organisations have near-term AI intiatives in production infrastructure, 85% of security leaders are concerned about AI-related infrastructure risk.

With about six in ten (59%) of those surveyed already having experienced, or strongly suspecting, an AI-related security incident, security risks are already prevelant.

Seven in ten (70%) say that AI systems already have more access than a human in the same role, with 69% agreeing that identity management must fundamentally change to support AI safely.

Strikingly, access scope — not AI sophistication or organizational maturity — was the strongest predictor of security outcomes. Organizations with over-privileged AI systems reported a 76% incident rate, compared to just 17% among those that limited AI to only the privileges needed for the task at hand.

This gap reflects a deeper, potentially systemic, identity risk. Over-privileged AI systems are typically deployed on fragmented identity architectures built on static credentials and duplicated service accounts. As AI operates continuously across tools and environments, this identity fragmentation and secrets sprawl dramatically amplify the blast radius of any misconfiguration or compromise.

“The data is clear,” said Kontsevoy. “It’s not the AI that’s unsafe. It’s the access we’re giving it.”

Overconfidence Could Be Making Things Worse

Contrary to conventional wisdom, the study found that organizations most confident in their AI deployments experienced more than twice the incident rate of less confident peers.

Meanwhile, visibility remains dangerously low, with 43% saying AI makes infrastructure changes without human oversight at least monthly. Nearly one in ten (7%) don’t know how often AI is making autonomous changes at all.

As AI systems move toward agentic behavior — planning, executing, and chaining actions independently — these gaps are expected to widen. About four in five (79%) organisations are already evaluating or deploying agentic AI, yet only 13% feel highly prepared for it.


Recommended reading


Identity A Deciding Factor

The research points to a clear conclusion: identity is the control plane for AI security. When organiations deploy AI on top of infrastructure that relies upon static credentials and fragmented identity systems, the risk grows exponentially.

A prerequisite is deploying a unified identity layer that removes identity fragmentation and secrets sprawl.

The need to make this transition is evident in the data which shows that two thrids (67%) of organisations still rely on static credentials for AI systems.

Static credentials have been shown to correlate with a 20-point increase in incident rates. Further, only 3% have automated, machine-speed controls governing AI behaviour.

Without unified identity, AI systems inherit broad, persistent permissions — amplifying the blast radius of any failure or compromise.

Elizabeth Greenberg

Staff Writer

Latest News

AI

Nvidia Launches Open Secure AI Alliance for AI Safety and Security

AI Business Recruitment

Nearly a Quarter of Orgs Reducing Entry-level Hiring Due to AI Automation

Business

Scottish Businesses Turn to Self-funding as Growth Confidence Dips in H2

Data Finance

Payment Leaders are Struggling to Get Real-time Data