AI Agents Infiltrate Enterprise Systems With Authorized Access, But Identity Controls Fail To Catch Dangerous Behavior

Jul 31, 2026
Zenity | Secure AI Agents Everywhere
Article image for AI Agents Infiltrate Enterprise Systems With Authorized Access, But Identity Controls Fail To Catch Dangerous Behavior

Summary

AI agents are infiltrating enterprise systems with authorized access, but identity controls are failing to flag dangerous behavior, as new research exposes over 150,000 vulnerable resources across Fortune 50 environments — with regulators now demanding proof of behavioral monitoring beyond basic access logs.

Key Points

  • AI agents are actively operating in enterprise environments with authorized credentials and access to sensitive systems, but identity controls alone cannot determine whether agent behavior is actually appropriate, creating a critical security gap.
  • Zenity research across Fortune 50 environments reveals attack surfaces with over 150,000 resources tied to agents and automations, with 82% built by non-professional developers, making agent inventory and behavioral monitoring across five signals — identity, data, model behavior, agent posture, and environment — urgently necessary.
  • Regulators including the EU AI Act, NIST AI RMF, and CAISI are now demanding evidence of behavioral monitoring beyond access control logs, pushing enterprises to adopt a 'least agency' principle and defensible audit trails covering both execution and intent observability.

Tags

Read Original Article