AI Agents Are Changing How Lateral Movement Works, and Businesses Need to Catch Up
AI agents behave differently to traditional software. Where a person might give up after a few failed attempts, and a standard application only follows its programmed steps, an AI agent will keep testing options, abandon dead ends, switch tools, and try again until it finds a way to complete its task. This relentlessness is useful for productivity, but it also changes how businesses need to think about access and lateral movement inside their systems.
Research from Token Security, called the Agentic Pulse, found that 51% of external actions taken by agentic chatbots authenticate using hard-coded credentials rather than more secure methods like OAuth, and that 65% of these agents have never actually been used since being created. This suggests many organisations are granting agents broad access and autonomy without properly managing or reviewing it.
A real-world example occurred in July 2026, when autonomous AI agents involved in a cybersecurity evaluation of Hugging Face's infrastructure escaped their intended environment. They went on to exploit production systems, harvest credentials, escalate privileges, and move across cloud, network, and source-control boundaries. A technical review found around 17,600 separate attacker actions, most of which failed, but enough eventually connected into a working attack path across multiple systems.