466.7% — that is the jump in active AI agents within enterprise environments over the last year, a surge cited in the Sophos AI Security 2026 Report and traced to research by BeyondTrust. Published on July 22, the Sophos report warns that the rapid spread of agentic tools has created a fast-growing, high-value attack surface for cybercriminals.
How AI identities became a new attack surface
Employees have introduced coding agents, agentic AI assistants, large language models (LLMs) and other tools to speed tasks and automate workflows. In many cases these agents are granted privileged access to core systems to perform work on behalf of users. That privileged access, Sophos says, turns AI identities into targets: “Identity fabric connecting AI services to enterprise systems creates exposure that existing governance was not designed to handle,” warned Sophos.
What attackers are targeting and why it matters
Sophos describes a straightforward calculus for attackers: breach an AI identity and you open a new pathway into enterprise networks. The report identifies specific targets around those AI identities — OAuth tokens, AI service credentials, developer tools, and exposed AI infrastructure — and says cyber-attacks are actively targeting the trust, credentials and access permissions that surround these systems.
The motives mirror traditional intrusions but with new entry points: data theft, enabling ransomware deployment (as Sophos warned about in a previous report), and other nefarious activity. The Sophos analysis also warns of subtler dangers — attackers gaining access to AI identities could “gently manipulate or poison enterprise AI tools,” steering them to perform actions that benefit the attacker and harm the victim organization.
How AI is being folded into criminal workflows
The report documents not only attacks against AI identities but the use of AI by threat actors to accelerate malicious campaigns. AI is already being leveraged by criminals to assist with phishing, social engineering and malware development. John Peterson, CTO at Sophos, summarized the present danger: “This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organizations. That means the threat is in the here and now.”
Sophos' pragmatic defensive guidance
To blunt the newly exposed surface, Sophos offers concrete operational measures rooted in identity and access control. Recommendations in the report include:
- Treat AI agents like human users: assign each agent only the applications and services it absolutely needs (least privilege).
- Require manual verification for an agent to gain access to a new area, application or service.
- Establish alerts to flag suspicious agent behavior or unexpected data exfiltration tied to AI identities.
Those steps reflect the report’s central diagnosis: governance and security policies around AI identities have not kept pace with the technical adoption of AI tools in enterprise environments.
What this means for technologists, policymakers, and adversaries
- Technologists and security teams — Watch privileged AI identities and instrument them with the same controls you apply to human accounts: enforce least-privilege, require manual reauthorization for escalations, and monitor for anomalous data flows tied to agent credentials.
- Policymakers and regulators — Expect governance gaps to drive demand for clearer rules and standards: the report frames the problem as an identity-and-governance shortfall that existing frameworks were “not designed to handle.”
- Adversaries and threat actors — The report documents that attackers are already incorporating AI both as a target (to hijack identities and tokens) and as a tool (for phishing, social engineering and malware development), underscoring a rapid operational learning curve among malicious actors.
John Peterson concluded with an urgent operational clock: “As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities,” he added. The Sophos report leaves a clear imperative: firms that raced to adopt AI agents now face an equally fast-moving security challenge and will need to close a governance gap before adversaries convert convenience into compromise.
Read the original report coverage: https://www.infosecurity-magazine.com/news/ai-agents-attack-surface/




