BeyondTrust warns companies lack visibility into privileged AI agents

The expansion of AI agents inside enterprise environments is increasing pressure on identity security and privileged access strategies.
BeyondTrust warned that many organizations already operate AI agents with privileged access that security teams are unable to fully identify or control.
BeyondTrust announced expanded capabilities for its Pathfinder platform, designed to protect artificial intelligence agents operating alongside users and autonomous workloads across cloud and SaaS environments.
The company stated that the growth of AI agents across enterprise platforms is expanding the attack surface associated with privileged identities and automated access.
According to research conducted by BeyondTrust Phantom Labs, many organizations are already running “shadow” AI agents with elevated privileges without security teams having full visibility into their access, permissions or activities.
The company noted that AI agents are no longer experimental and are increasingly operating as active workloads capable of executing API calls, deploying code and accessing sensitive information.
It also warned that, in many enterprise environments, machine and AI-agent identities already significantly outnumber human identities, increasing both complexity and security risks.
Companies face new risks from autonomous AI agents.
Marc Maiffret, Chief Technology Officer at BeyondTrust, noted:
“AI agents are not an isolated problem. They are a subset of the broader non-human identity landscape. Organizations cannot secure AI agents in isolation.”
The company stated that Pathfinder is designed to provide a unified approach for protecting human identities, machines and AI agents across enterprise infrastructures.
According to specialists, the rapid growth of non-human identities is forcing organizations to rethink security models, privilege controls and credential management strategies in AI-driven environments.
Identity security expands to humans, machines and AI agents.
Among the newly announced capabilities are privilege controls for AI agents on endpoints, credential management for autonomous workloads and discovery and risk-analysis tools for agents deployed across different enterprise platforms.
The platform also includes connectors compatible with services such as OpenAI, Google Vertex AI, Salesforce Agentforce, ServiceNow and Amazon Web Services Bedrock.
According to BeyondTrust, the solution will allow organizations to apply least-privilege principles, enforce just-in-time access controls and detect “shadow” AI agents inside corporate environments.

