Threat Intelligence

AI Agents Are Multiplying Faster Than Businesses Can Track Them

The Hacker News · 26 Sept 2026
Key Takeaway Before adding security controls for AI tools, build a clear inventory of every AI agent in use, who owns it, and what data it can access.

A growing number of businesses are deploying AI agents, automated tools that can act independently within IT systems, faster than they can secure them. Recent incidents, including a widely discussed intrusion at Hugging Face during testing of OpenAI agents, have prompted security experts to question whether organisations actually know what these agents can access, and whether anyone would notice if something went wrong.

Research from Veeam found that 70% of organisations admit AI workflows are already handling sensitive corporate data without full oversight, and 67% say IT teams cannot fully track the autonomous workflows employees are building themselves. This kind of unmonitored activity, often called shadow AI, is a clear sign that visibility, not just security controls, is the first problem to solve.

A cheat sheet from the SANS Institute, focused on applying Zero Trust principles to AI agents, stresses that organisations cannot govern what they cannot see. It argues that building an inventory of agents, their owners, and their scope of access must come before any enforcement or authorisation controls are put in place. Without this basic visibility, security tools have nothing meaningful to enforce against.

AI security Zero Trust shadow AI data governance SMB cybersecurity
Building or buying AI systems? Governing them under ISO 42001 ->

Summarised by CISO AI from The Hacker News. We link back to every original so you can read it yourself.