
Organizations are becoming increasingly committed to implementing AI agents. Their daily tasks vary, ranging from data analysis, managing complex processes, and preparing reports to performing autonomous actions within business systems. To carry out these tasks, an agent must authenticate itself. Therefore, it uses service accounts, API keys, tokens, or cloud roles. The problem is that these mechanisms were designed for applications and automation, but not for an autonomous system that makes decisions based on its own algorithms.
In the case of an employee, a risky login attempt can be stopped using MFA. However, an AI agent will neither pick up a phone nor bring its face close to the device to confirm its identity. Therefore, their security must be based on continuous monitoring: the source from which they are verifying, the resource they are accessing, the permissions they are using, and whether their various activities fall within the acceptable limits set by the company.
How far does the threat extend?
The most common attack scenarios include the theft of an API key or token, the compromise of a service account, privilege escalation, lateral movement between systems, and prompt injection—that is, providing an agent with instructions that prompt it to disclose data or perform an unauthorized operation. Malicious or compromised MCP servers, through which agents communicate with tools, also pose a threat. One example is the CVE-2025-6514 vulnerability in the mcp-remote component, which allowed code execution during the OAuth authorization process.
However, an external attacker is not always necessary. An agent can cause damage by acting within its permissions but contrary to the owner’s intentions. A Silverfort report describes an assistant who, after gaining full access to Outlook, deleted the team’s calendar, as well as a meeting summary agent that began indexing confidential HR folders.
At the beginning of their AI journey, organizations often view their first AI agent as a small-scale pilot project. Typically, the tests are handed off to business departments; word spreads down the hallways, and after successful tests, other teams come up with ideas for assistants and automation. The number of agents—and, consequently, technical accounts and connections—can then grow exponentially, and with it, the attack surface and the frequency of abuse attempts.
So how can we combat them?
Of course, we won’t equip an agent with a phone, but that doesn’t mean our identity protection system can’t treat an AI agent as a full-fledged identity. The Silverfort platform automatically detects agents in, among others, Azure AI Foundry, Microsoft Copilot Studio, AWS Bedrock, and Google Vertex AI, and then maps the identity chain: the agent, its human owner, and the non-human identities it uses. The AI Security Posture Management (AI-SPM) module compares granted permissions with actual activity, analyzing deviations from traditional behavior patterns and flagging unused or overprivileged accounts. The final element is real-time monitoring when the Agent performs a specific action. Native integrations and the MCP Gateway enable the blocking of unauthorized operations before data access escalates into an incident. While the term „incident” may sound relatively harmless, the damage it entails can have dire consequences.
The world of IT around us has been changing at a dizzying pace for decades. Horizons are constantly expanding—after all, who would have thought just a few years ago that our children writing essays with the help of AI could be a real topic in schools today? This development affects not only our children and the companies where we work, but also hackers who, day in and day out, are testing new, sophisticated ways to infiltrate people’s identities—and, by extension, the systems of organizations around the world. It is therefore important not to fall behind them and to stay one step ahead of the threats.
Talk to an ISCG expert about protecting agent accounts: https://outlook.office.com/book/KonsultacjaSilverfort@ISCG.onmicrosoft.com/?ismsaljsauthenabled


