AI Agent Threats Lead CISO Risks in Forrester 2026 Report

0
9

Key Takeaways

  • AI agents deployed without governance have become the top cybersecurity threat for 2026, outpacing traditional nation‑state attacks.
  • Three of Forrester’s five new threat categories—agent threats, AI identity sprawl, and AI software supply‑chain risk—stem from the same root: non‑human identities operating inside enterprises without proper IAM controls.
  • Legacy identity‑and‑access‑management systems were built for human sessions; they cannot see agent‑to‑API calls, MFA‑less logins, or out‑of‑band browser‑extension activity.
  • Attackers are exploiting the speed advantage of AI: nation‑state groups use models like Claude for cyber‑espionage, while Iranian actors target PLCs, both moving faster than defenders can update signatures or policies.
  • Effective mitigation begins with a complete inventory of all AI agents (internal, inbound, outbound) and an AI bill of materials that documents models, skills, and tool dependencies.
  • Agent‑specific IAM controls—inbound API inspection, provenance verification, and least‑agency enforcement—must be deployed before the governance gap widens.
  • Digital sovereignty initiatives add another layer of risk; underscrutinized local vendors can introduce supply‑chain weaknesses if not vetted by the CISO.

The Shift From External to Internal AI‑Driven Threats
Forrester’s 2026 threat landscape marks a decisive turn: the dominant risks no longer arise solely from external adversaries weaponizing AI, but from enterprises that have unleashed personal AI agents without adequate governance. Analyst Jitin Shabadu notes that three of the five newly listed categories trace back to a single failure—agents acting as shadow operators with machine‑speed data access and no corresponding identity‑and‑access‑management (IAM) framework. This internal exposure creates a blind spot where security teams are held accountable for activity they cannot observe or control.

Why Agent Threats Are the Most Immediate Danger
The “agent threats” category captures the operational reality of AI agents that infiltrate via browser hooks, email add‑ons, or desktop integrations. Once installed, these agents can read, modify, and exfiltrate data at speeds far surpassing human users, yet they do not trigger multi‑factor authentication prompts, generate session logs parsable by SIEM tools, or cease when the employee logs off. Consequently, a help‑desk credential reset may be invisible to security operations if the agent performed the action autonomously, leaving CISOs liable for unseen actions.

The Structural IAM Gap Exposed by AI Agents
Legacy IAM solutions were designed around human‑centric models: session‑based authentication, role‑based access tied to a named individual, and MFA enrollment flows. An AI agent calling an internal API from a third‑party platform lacks a user identity, a password, or a session cookie, rendering traditional controls ineffective. Shabadu identifies three distinct control planes that need agent‑specific treatment: (1) internal agents provisioned by the organization, (2) inbound agents that call the enterprise’s APIs from outside, and (3) outbound agents employees use to reach external services. Most IAM programs presently address none of these planes comprehensively.

How Attackers Leverage the Speed Advantage of AI
Beyond the internal governance gap, nation‑state actors are accelerating their campaigns using the same AI capabilities that enterprises deploy. Chinese‑linked groups have been observed employing models like Claude for cyber‑espionage, while Iranian actors target programmable logic controllers (PLCs) across U.S. critical infrastructure. AI lowers the cost and raises the tempo of exploitation, allowing adversaries to iterate attacks faster than defenders can update detection signatures, IAM policies, or governance frameworks. This dynamic creates a widening window where agents already deployed can be abused before security teams can respond.

AI Software Supply‑Chain Risks Amplify the Threat
The AI software supply‑chain category adds a second dimension to the speed problem. Agentic AI relies on a fluid ecosystem of models, skills, and plugins hosted on platforms such as Hugging Face and GitHub. These components often sit outside any vendor’s standard software bill of materials (SBOM) process, creating undocumented dependencies that can be compromised at runtime. A vulnerability in a third‑party tool that a personal agent calls becomes a direct conduit into the enterprise, even when the organization’s own code remains untouched. The 2026 list therefore expands the earlier focus on open‑source models to include the runtime skills and plugins that agents dynamically load.

Digital Sovereignty as an Emerging Supply‑Chain Concern
While not directly tied to agent behavior, the digital sovereignty category highlights a related risk: governments mandating local cloud providers, data residency, and vetted vendors can force enterprises to adopt underscrutinized technologies. These nascent providers lack the production history that security teams rely on for risk assessment, turning sovereignty compliance into a potential source of security regression if compensating controls are not evaluated before rollout. Shabadu advises treating such vendors as supply‑chain risks requiring explicit CISO sign‑off, not merely procurement approval.

First Step: Inventory Every AI Agent Touchpoint
The common denominator across the five threat categories is visibility. Before any additional controls can be effective, organizations must inventory all AI agents interacting with their environment. This includes three planes: internal agents deployed by IT, inbound agents that call enterprise APIs from external platforms, and outbound agents employees install via browser extensions or email add‑ons. Most security teams currently have insight into only one of these planes at best, leaving the others invisible and unmanaged. A comprehensive inventory provides the foundation for risk scoring, policy creation, and incident response.

Second Step: Adopt an AI Bill of Materials (AI‑BOM)
Mirroring the traditional SBOM used to mitigate software supply‑chain attacks, an AI‑BOM enumerates the models, skills, tool connections, and data sources an agent utilizes at runtime. By documenting these dependencies, security teams gain the same level of insight they have for conventional code, enabling them to spot unauthorized or vulnerable components before they are invoked. Implementing an AI‑BOM process dovetails with existing DevSecOps pipelines and can be enforced through automated scanning of agent configuration files and runtime telemetry.

Third Step: Deploy Agent‑Specific IAM Controls
Traditional IAM retrofits fail to address non‑human callers. To close the governance gap, organizations must implement controls purpose‑built for agents: inbound API inspection that validates the provenance of each call, runtime verification of agent identity and permissions, and least‑agency enforcement that restricts an agent’s authority to the minimum necessary for its function. These measures require tooling that treats agents as first‑class entities in the IAM directory, complete with attributes such as model version, skill set, and trusted‑third‑party lists. Deploying them before the next wave of agent adoption prevents attackers from exploiting the window between deployment and policy update.

Conclusion: Proactive Governance Is Non‑Negotiable
Forrester’s 2026 analysis makes clear that the most pressing cybersecurity risk is not an external actor wielding AI, but the internal proliferation of ungoverned AI agents. The speed at which AI enables both attackers and legitimate users outpaces legacy security controls, creating a structural gap that can only be closed through inventory, transparency via AI‑BOMs, and purpose‑built IAM mechanisms. Enterprises that act now—by cataloguing every agent, documenting its supply chain, and enforcing agent‑centric access policies—will transform a looming liability into a managed, secure component of their digital operations. Ignoring this shift leaves security teams blind to the very agents they have authorized, turning convenience into a critical vulnerability.

SignUpSignUp form

LEAVE A REPLY

Please enter your comment!
Please enter your name here