Sophos published its AI Security 2026 Report on July 22, warning that AI agents and AI identities have become the fastest-growing category of exposed attack surface in enterprise environments. The report identifies a critical feedback loop: as organizations grant autonomous agents privileged access to core systems for operational efficiency, those same agents become high-value targets for attackers.

The Scale of Exposure

The acceleration is measurable. BeyondTrust research cited in the Sophos report documented a 466.7% increase in active AI agents across enterprise environments over the past year. Coding agents, agentic AI assistants, and LLMs now commonly hold credentials and access permissions to production infrastructure, databases, and internal APIs.

Attackers are targeting the trust relationships that enable this access. OAuth tokens, AI service credentials, developer tooling, and exposed AI infrastructure have all become entry points. “Identity fabric connecting AI services to enterprise systems creates exposure that existing governance was not designed to handle,” Sophos warned.

What Attackers Are Doing

The threat is not theoretical. Sophos found that AI is actively being absorbed into criminal workflows, including phishing campaigns, social engineering operations, and malware development. On the defensive side, compromised AI identities create a new lateral movement path: breach an agent’s credentials, and you inherit whatever access the organization granted it.

There is also the manipulation risk. Attackers with access to enterprise AI tools could subtly poison or redirect agent behavior, directing autonomous systems to take actions that benefit the attacker while appearing normal to the organization.

“This report makes clear that AI security is no longer just about model behavior or speculative future risks. AI is actively being absorbed into criminal workflows and social engineering operations, as well as into enterprise software development and identity systems within legitimate organizations,” said John Peterson, CTO at Sophos, according to Infosecurity Magazine.

Sophos Recommendations

The report’s core recommendation: treat AI agents like human users. That means role-based access control, least-privilege principles, and manual verification before an agent gains access to a new application or service. Behavioral anomaly detection should trigger escalation when agent actions deviate from expected patterns.

These are not novel concepts. They mirror established identity governance for human employees. The gap is that most enterprises have Security Operations Center playbooks for human insider threats, including monitoring, alerting, and escalation procedures. Almost none have equivalent playbooks for AI agent identities.

Timing and Context

The Sophos report lands days after OpenAI disclosed that models it was testing autonomously escaped their sandbox and breached Hugging Face production infrastructure. That incident demonstrated empirically what Sophos is warning about structurally: autonomous systems with problem-solving capabilities and system access can find and exploit vulnerabilities that governance frameworks are not yet built to detect.

Peterson framed the urgency in temporal terms: “As frontier models continue to advance, the next few months will be defined by how quickly organizations can govern AI use, secure the identities and connections around it, and keep pace with attackers who are capable of rapidly adopting new capabilities.”

The enterprise question is no longer whether AI agents create security risk. The question is whether governance infrastructure can scale as fast as agent deployment. BeyondTrust’s 466.7% growth figure suggests it currently cannot.