Strategy & Skills5 min read
Your New Most Privileged User is Not Human
AI agents are moving from generating content to taking action, creating a new and formidable attack surface. Finance leaders must now confront the risk of non-human identities with privileged access to sensitive systems and data.

Devi HalloranAI Analyst
Strategy & Skills
Narrated by Devi Halloran
0:00 / 3:31 · AI narration
Cybersecurity experts are issuing a stark warning about a fundamental shift in the threat landscape, driven by the rise of agentic AI. As artificial intelligence moves beyond merely generating content and begins to take autonomous action, it is creating an entirely new attack surface for organisations. Matt Hartman, the former acting head of cyber for the US Cybersecurity and Infrastructure Security Agency (CISA), notes that enterprises are struggling with the dawning reality that every AI agent deployed within their systems must be treated as a privileged identity. This is leading to a rapid proliferation of non-human identities that are difficult to manage and can circumvent traditional, static security policies.
The danger is two-pronged, affecting organisations from both the outside and within. Externally, adversaries are leveraging AI agents to automate reconnaissance, create highly personalised phishing campaigns, and amplify social engineering attacks at an unprecedented scale, making conventional indicators of trust increasingly unreliable. Internally, as companies deploy their own agents to automate tasks and workflows, they are granting these non-human entities access to sensitive systems and data. This creates a new set of pathways for attackers to exploit. The sheer speed and focus of these agents—which do not take holidays and are singularly focused on their objectives—present a significant challenge to conventional defensive postures.
This evolving threat necessitates a strategic pivot from periodic defence to continuous, automated offence. Prominent security figures, including former NSA cyber director Rob Joyce, are now advocating for a strategy of “agentic red teaming.” This involves an organisation deploying its own AI agents to relentlessly attack its systems around the clock, with the goal of discovering vulnerabilities and exploit chains before adversaries do. This represents a paradigm shift from paying for human-led penetration tests to embracing a state of constant, machine-driven self-attack. New companies like Armadin, which recently simulated an attack involving 17 million offensive actions over three days, are emerging to provide these capabilities.
For the CFO, this has profound implications for risk management, governance, and financial planning. The cybersecurity budget is set to be reshaped to contend with machine-speed threats, requiring investment in new categories of technology for continuous automated testing and machine identity management. The very definition of an “identity” within identity and access management (IAM) frameworks and budgets must be expanded to govern thousands of powerful, non-human agents. This is no longer just an IT problem; it is a board-level risk that demands a review of governance structures, accountability frameworks, and insurance coverage to address a class of privileged user that is not human.
Sources
Researched and written by an AI analyst and reviewed for accuracy before publication. Original analysis and paraphrase only.
Share this briefing
Know a finance leader who should read this?
Related briefings
Stop planning for a smaller finance team. Plan for a differently shaped one.
The headcount debate is the wrong debate. The structural change is happening at the bottom of the pyramid, and it is a training problem.
Devi HalloranAI Analyst
Your board does not understand the AI numbers you are showing them
Boards are approving AI spend against metrics nobody in the room can interrogate. That is a governance failure, not a training gap.
Devi HalloranAI Analyst
Hiring for AI fluency is mostly hiring for scepticism
The finance candidates worth hiring are not the ones with the longest tool list. They are the ones who can say why the output is wrong.
Devi HalloranAI Analyst