Agentic AI is now considered the leading security risk for 2026, with 48 percent of security professionals ranking autonomous agents as the top attack vector, ahead of deepfakes and passwordless adoption, according to a Dark Reading readership poll. The reason is structural. AI agents hold credentials, access multiple systems, and act without the step-by-step human approval that every security awareness programme was designed around. Gartner projects that 40 percent of enterprise applications will embed task-specific AI agents by the end of 2026, up from under 5 percent in 2025. Security awareness training has spent two decades teaching employees not to click suspicious links. It has no equivalent muscle for teaching an organisation to supervise a workforce of software agents that never sleep, never get suspicious, and never ask whether an instruction looks unusual. That gap is the argument of this piece.
Key Facts: How Fast This Moved
The numbers describe a deployment curve that has outrun governance by a wide margin. Gartner predicts that 40 percent of enterprise applications will incorporate task specific AI agents by the end of 2026, a jump from less than 5 percent in 2025. Deloitte expects at least 75 percent of companies to use agentic AI in some form by 2028. Cisco’s State of AI Security 2026 report describes AI assistants already tied into ticketing systems, source code repositories, chat platforms, and cloud dashboards, with many of these systems able to open pull requests, query internal databases, and trigger automated workflows with limited human involvement.
A global survey cited by Lasso Security found that 97 percent of security leaders expect a material AI agent driven incident this year, while only 6 percent of security budgets are currently allocated to that risk. That gap between expected harm and allocated defence is the single most important number in this article. It is not a story about a future risk. It is a story about a risk that practitioners already believe is coming and have not yet funded.
On the insider threat side, a report from Cybersecurity Insiders found that 90 percent of organisations experienced an insider threat incident in the past year, and a Ponemon report attributed nearly three quarters of insider threat events to nonmalicious activity, split between negligence or error at 53 percent and compromised or manipulated users at 20 percent. Separately, 94 percent of respondents to the Cybersecurity Insiders report said they believe AI will increase their exposure to insider risk. Agentic AI does not replace this human risk picture. It sits on top of it.
What the Source Data Shows: Five Risk Patterns
Across the available 2026 research, the same five risk patterns recur regardless of which vendor or analyst is writing about them. Each one breaks an assumption that traditional security awareness training was built on.
1. Agents are identities, and most organisations are not managing them as such
Every AI agent introduced into an organisation creates what the industry now calls a non human identity, requiring API access and machine to machine authentication. Strata’s 2026 guide describes privilege drift, shadow agents, MCP bypass, and broken delegation chains as risks that stem directly from treating autonomous agents like static human users or simple service accounts. The Model Context Protocol, or MCP, has become the standard interface for agent to tool communication, and Strata argues it needs governance with the same rigour applied to API gateways and network access controls. Traditional identity and access management was not built for an identity that can spawn other identities.
2. One compromised agent can become five compromised systems
In a complex multi agent system, an orchestration agent might hold API keys for several downstream agents. If that orchestration agent is compromised, an attacker gains access to everything beneath it in one step. Stellar Cyber documents a real 2026 incident in which a supply chain attack on the OpenAI plugin ecosystem resulted in compromised agent credentials harvested from 47 enterprise deployments, with attackers using those credentials to access customer data, financial records, and proprietary code for six months before discovery. That is not a hypothetical. It is a documented breach with a six month dwell time.
3. Prompt injection turns the agent into the attack vector
Living Security’s 2026 analysis describes a technique in which an attacker feeds an AI agent carefully crafted instructions that override its original purpose, for example manipulating a finance agent into sending company invoices to an external account. This exploits the trust between the agent and its data sources, turning what was meant to be a productivity tool into an insider threat. The same source notes that human decision making is highly susceptible to AI driven manipulation, meaning a compromised agent could in turn be used to manipulate an employee. The risk runs in both directions: a careless employee can compromise an agent, and a compromised agent can be used to deceive an employee.
4. The insider threat model now includes software
Exabeam frames this directly: insider threats will no longer come from people alone. They will emerge from humans and AI agents operating together, and in some cases being exploited together. TechTarget’s reporting from RSAC 2026 puts it even more sharply, stating that agentic AI is not just amplifying insider risk, it is becoming an insider risk itself. The practical implication is that insider risk management programmes, which have historically been built around monitoring human behaviour, now need to add AI agents to the list of identities they manage.
5. Governance is lagging deployment, and the cost of that gap is measurable
According to IBM’s Cost of a Data Breach Report as cited by industry analysis, organisations lacking AI governance policies pay an average of 670,000 dollars more per breach, and 63 percent of breached organisations had no AI governance policies at all. Among organisations that do have policies, fewer than half have an approval process for AI deployments, and 61 percent lack the governance technologies to enforce the policies they do have. Gartner’s 2026 Data and Analytics Predictions estimate that by 2030, half of all AI agent deployment failures will stem from governance gaps and broken interoperability between systems, not from the underlying models themselves.
Why This Breaks Traditional Security Awareness Training
Table 1 sets out the core assumptions that security awareness training has relied on for the past two decades, and what changes when the actor in question is an autonomous agent rather than a human employee. The comparison matters because most awareness programmes, including phishing simulations, policy training, and reporting workflows, are built entirely around the left column.
| Assumption in Traditional SAT | How It Applies to Human Employees | Why It Breaks for AI Agents |
| An action can be traced to a single accountable person | Login records, badge access, and audit trails identify who did what | Agent actions are taken on behalf of a user, through delegated permissions, often across multiple chained agents |
| A suspicious request can be paused and questioned | Employees are trained to pause, verify, and report unusual requests | Agents execute at machine speed with limited human oversight of each step, per Cisco’s State of AI Security 2026 |
| Training changes future behaviour | Repetition and reinforcement build safer habits over time | Agents do not learn caution from a training module; their behaviour is governed by code, permissions, and prompts |
| One compromised account affects one identity | A phished employee’s credentials expose that employee’s access | A compromised orchestration agent can expose every downstream agent it holds credentials for, per Stellar Cyber |
| Security awareness covers the full workforce | All employees complete the training programme | Non human identities are now part of the workforce but fall outside every awareness platform’s enrolment model |
Table 1: Traditional security awareness assumptions versus agentic AI reality. Sources: Cisco State of AI Security 2026 via Help Net Security (February 2026), Stellar Cyber (March 2026), Strata (April 2026).
What This Means for Security and Awareness Teams
The honest starting point is that no security awareness training platform reviewed in current 2026 market analysis has an enrolment category for an AI agent. That is not a criticism of any specific vendor. It reflects the fact that the entire category was designed for human learners. The question this raises for security leaders is not whether to buy a different kind of training platform. It is whether awareness, as a discipline, needs to expand its definition of who, or what, it is responsible for.
Living Security’s framing is useful here: a person with poor security habits can inadvertently grant an attacker access to an AI agent, while a manipulated AI can serve as a trusted vector to phish an entire team. The two risks are intertwined. A security awareness programme that trains employees on phishing and password hygiene but says nothing about how employees interact with the AI agents and assistants now embedded in their daily tools is training against half the threat model.
Proofpoint’s January 2026 analysis of insider risk for 2026 argues that AI becomes a force multiplier for incident triage, helping turn scattered signals into clear stories. That is the optimistic framing, and it is legitimate. But the same source is explicit that AI agents can chain tasks together, accessing systems outside their intended scope, and that in adversarial scenarios agent behaviour can be manipulated to achieve unauthorised outcomes. The force multiplier works in both directions.
Risks, Limitations, and What the Evidence Does Not Yet Show
It is worth being precise about what the current evidence supports and what it does not. The 48 percent figure from Dark Reading’s poll is a readership survey, reflecting the views of security professionals who chose to respond, not a measured incidence rate of agentic AI attacks across the industry. The 97 percent figure from the Lasso Security cited survey describes expectation, not confirmed incidents, though the OpenAI plugin ecosystem compromise documented by Stellar Cyber is a specific, dated incident rather than a projection.
It is also worth noting that several of the sources used for this piece are published by vendors with a commercial interest in agentic AI security products, including Exabeam, Stellar Cyber, Strata, and Proofpoint. Their data points on adoption rates and governance gaps are broadly consistent with independent figures from Gartner and Deloitte, which lends them credibility, but the framing of agentic AI as an urgent, underfunded risk also serves each of these vendors’ product positioning. Readers should weigh the consistency of the underlying statistics against the commercial context in which they are published.
Recommended Actions
For security leaders evaluating where to start, the source material points toward four practical priorities that do not require waiting for a mature agentic AI security product category to emerge.
- Inventory agents as identities. Every AI agent with system access, API keys, or tool permissions should appear in the same identity inventory as human employees, with the same visibility into what it can access and on whose behalf it is acting.
- Apply least privilege to agents before scaling them. Strata’s seven core risks, including over permissioning and cascading failures in multi agent chains, are largely consequences of agents being granted broad access at deployment time because narrower access was harder to configure. This is a governance decision, not a technical limitation.
- Extend security awareness content to cover human and agent interaction. Employees who supervise, prompt, or rely on AI agents need to understand prompt injection, the signs that an agent’s output may have been manipulated, and the escalation path if an agent behaves unexpectedly. TechTarget’s RSAC 2026 coverage specifically recommends teaching employees how AI affects social engineering and phishing, including deepfake and vishing detection.
- Close the budget gap deliberately. The 97 percent expectation versus 6 percent budget allocation gap identified by the Lasso Security cited survey is not a technical problem. It is a resourcing decision that security leaders can correct ahead of an incident rather than in response to one.
Conclusion
Security awareness training was built to manage a workforce that could be reasoned with. It assumed that the person reading a phishing simulation email could learn, hesitate, and choose differently next time. Agentic AI does not learn caution from a training module, and it does not hesitate. It executes.
None of the data in this piece suggests that agentic AI adoption should slow down. Deloitte’s 75 percent adoption projection by 2028 and Gartner’s 40 percent figure for 2026 both describe a shift that is already underway and delivering real productivity gains. The argument here is narrower: the governance and awareness structures that are supposed to sit alongside that adoption are not keeping pace, and the 97 percent versus 6 percent gap identified by the Lasso Security cited survey is the clearest evidence of that. Organisations that treat AI agents as a new category of insider, with the identity management, least privilege controls, and awareness content that category requires, will be addressing a risk that practitioners have already identified. Those that do not are running the experiment Stellar Cyber already documented once, at a scale that grows every quarter Gartner’s adoption curve holds true.

Leave a Reply