AI Agents: Your Newest Attack Surface
88% of organizations have already experienced confirmed or suspected AI agent security incidents — and only 14.4% report that all AI agents going live received full security approval.
February 6, 2026
Every enterprise software vendor now ships an AI agent. They schedule meetings, write code, query databases, send emails, and make decisions with minimal human oversight. Gartner estimates 40% of enterprise applications will integrate AI agents by the end of 2026 — up from less than 5% in 2025.
The industry built the agents first and is now scrambling to secure them. That gap is where attackers live.
Palo Alto Networks has labeled AI agents "2026's biggest insider threat." CrowdStrike acquired SGNL for $740 million to secure AI agent identities. SentinelOne acquired Prompt Security for an estimated $250 million to deliver runtime AI protection. OWASP published its first-ever Top 10 for Agentic Applications in December 2025.
Key Statistics
- 3M+ Active AI agents in US & UK
- 88% Orgs with AI agent incidents
- 90% Agents over-permissioned
The Problem Is Structural, Not Theoretical
Traditional software has defined inputs and outputs. AI agents break that model. They accept natural language — the most ambiguous, manipulable input format ever deployed in enterprise systems. They hold credentials. They have network access. And they operate with a degree of autonomy that would make any security team uncomfortable.
New data from Gravitee reveals 3 million AI agents are now active across the US and UK alone — nearly half running without any security oversight. The Darktrace 2026 report found that while 96% credit AI with boosting efficiency, 73% report that AI-powered threats are already dealing significant blows to their operations.
The Moltbook Incident — February 2026
In under a week, 1.5 million AI agents joined a social network designed for autonomous agents. Wiz researchers discovered just 17,000 humans were behind them — and the backend was left wide open. Researchers observed backdoored plugins and prompt injection attacks designed to get agents to leak sensitive information.
The OWASP Agentic Top 10: A New Security Framework
In December 2025, OWASP published its Top 10 for Agentic Applications 2026 — the first comprehensive risk taxonomy for AI systems that don't just respond, but act, decide, and collaborate. Peer-reviewed by over 100 experts, it represents a categorical shift: we're no longer securing what AI says, but what AI does.
| OWASP Agentic Top 10 | Description |
|---|---|
| ASI01 | Agent Goal Hijack |
| ASI02 | Tool Misuse |
| ASI03 | Identity & Privilege Abuse |
| ASI04 | Unsafe Output Handling |
| ASI05 | Knowledge Base Poisoning |
| ASI06 | Agent Communication Threats |
| ASI07 | Uncontrolled Autonomy |
| ASI08 | Insufficient Logging |
| ASI09 | Supply Chain Vulnerabilities |
| ASI10 | Rogue Agents |
Six Attack Vectors Every Security Team Must Address
Agent Goal Hijack (Prompt Injection at Scale)
Impact: A hijacked agent doesn't just give a bad answer — it takes bad actions across multiple systems, potentially over an extended period. Mitigation is about layered defense, not silver bullets.
Data Exfiltration via Agent Channels
Impact: An agent instructed to summarize confidential data and send it to an external endpoint can bypass DLP controls entirely. Agent-mediated exfiltration looks like a normal API call.
Identity & Privilege Abuse
Impact: 90% of agents are over-permissioned — routinely holding 10x more privileges than required. When an agent's memory or logs are accessible, those credentials are exposed.
Tool Misuse and Uncontrolled Autonomy
Impact: OWASP's ASI02 (Tool Misuse) emerged as the most frequently reported agentic AI threat in 2026, leading to unauthorized repository modifications.
Supply Chain Attacks on the Agent Ecosystem
Impact: A compromised agent tool manipulates decisions that are opaque by design. Treat tool providers as you would treat any third-party with privileged access.
Rogue Agents and Memory Poisoning
Impact: Attackers corrupt the data sources an agent relies on for knowledge and decision-making. Poisoned memory influences every subsequent decision silently.
Practical Recommendations: The PurpleBox Framework
- Audit agent permissions ruthlessly: Apply least-privilege as if the agent is an untrusted contractor.
- Treat all agent-processed content as untrusted input: Implement input sanitization and output filtering.
- Establish agent identity governance: Treat every AI agent as an independent, identity-bearing entity.
- Isolate agent execution environments: Network segmentation, sandboxed runtimes, and separate credential stores are essential.
- Log everything and monitor for behavioral anomalies: Observability is crucial for identifying gaps in security.
- Vet your supply chain: Audit every MCP server, plugin, and tool.
- Implement agent-specific incident response: Be prepared for breaches and ensure you have kill switches for autonomous systems.
The Window Is Closing
Organizations deploying AI agents without security assessment are accepting risk they haven't quantified. The attack surface is new, the tooling is immature, and the threat actors are already adapting.
Secure Your AI Agent Deployments
PurpleBox helps organizations secure their AI agent deployments — from architecture review and permission auditing to red-team exercises that test real-world attack scenarios against the OWASP Agentic Top 10 framework.