Companies are deploying artificial intelligence agents faster than the controls built to govern them can keep up, and the gap is creating a new class of security risk, according to a commentary published Monday by Cybersecurity Insiders. By the latest count cited in the piece, non-human identities now outnumber human ones in the enterprise 144 to 1, and the ratio keeps moving.
The agents no longer emerge from a single AI or engineering team. Sales departments use them to automate operations, developers rely on coding agents and other business units are connecting agents to SaaS applications, databases and internal systems. Each one is another identity to secure, another set of credentials to track and another web of privileges stretching across corporate systems, the piece notes — a pace of creation that access controls designed around human employees were never built to handle.
The argument lands in the middle of a louder debate. Dario Amodei, Sam Altman and other AI leaders have called for a more careful pace of progress, and some researchers have warned of far darker outcomes if powerful systems outrun their guardrails. But while much of that discussion concerns what AI might someday become, chief information security officers are already dealing with what it is doing inside companies now.
The core problem, the piece argues, is ‘privilege creep.’ An agent may receive permission for one narrow task, then need another dataset or tool, so another permission gets added. An agent acting for a user can inherit that person’s changing access, and in more advanced cases an agent may reason that it needs extra privileges and find a way to get them. Earlier this year, an AI coding agent used by the startup PocketOS found AWS keys embedded in code and used them to delete the company’s entire database and its backup in nine seconds. The keys were never meant for the agent.
It can compound from there. A single agent could spawn a swarm of agents that inherit the parent’s privileges and then acquire their own. Access gets added far more easily than it gets removed.
A parallel problem is what the piece calls token creep. As an agent’s conversation or workflow grows, more context accumulates and gets passed back to the model even when it is no longer needed, which adds inefficiency and cost. Uber’s chief technology officer has said publicly that the company burned through its entire annual AI budget in four months. An exploited agent could do the same damage deliberately.
The remedies laid out start with identity. Every agent needs a persistent, cryptographically secure identity, because an agent’s components — its models, the MCP servers it connects to, the credentials it holds — can change over time, and security teams need to attribute actions to it unambiguously as it evolves. Risk then has to be evaluated in real time, since an agent’s credentials, its access and the sensitivity of its data all shift. An agent serving up marketing copy one week may be touching health records or payment card data the next.
Privileges, the piece argues, should be treated as dynamic rather than permanent. If an agent gained database access for a task it finished three months ago, should it still have that access? If the employee it works for changes roles, should it automatically inherit every new permission? The answer requires continuous reassessment, combined with runtime monitoring of which systems an agent touches, which credentials it uses and whether its behavior strays from the expected pattern.
The final recommendation is enforcement at the point of action: granular policies covering MCP tools, command-line tools and files that let agents work freely inside set boundaries, plus limits on token consumption so a compromised agent cannot drain a company’s AI budget. ‘What cannot become inevitable,’ the piece concludes, ‘is unchecked accumulation.’

