A new report released by Teleport  reveals significant security vulnerabilities arising from the rapid deployment of artificial intelligence (AI) systems in enterprise infrastructure. 

The study indicates that organisations granting excessive permissions to AI systems face substantially higher rates of security incidents.

The 2026 State of AI in Enterprise Infrastructure Security Report, based on interviews with 205 chief information security officers (CISOs), security architects, and platform leaders from companies employing 500 to more than 10,000 staff, shows that AI integration is now commonplace. 

The study emphasises that addressing identity fragmentation and secrets sprawl is critical to harnessing AI benefits without compromising security.

  • Ninety-two per cent of organisations have near-term AI initiatives operating in production infrastructure. However, identity and access controls have failed to evolve at the same pace, creating measurable risks.
  • Eighty-five per cent of security leaders express concern over AI-related infrastructure threats. Fifty-nine per cent report having experienced or strongly suspecting an AI-related security incident. A key finding is that seventy per cent of respondents believe AI systems possess greater access privileges than humans in equivalent roles.

Over-Privileged Access as Primary Risk Factor

The research identifies over-privileged AI systems as the strongest predictor of poor security outcomes, rather than the sophistication of the AI technology or the organisation’s overall maturity. Enterprises with excessive permissions for AI reported a 76 per cent incident rate, compared with 17 per cent among those applying least-privilege principles. This represents a 4.5 times higher incidence rate for over-privileged setups.

Such vulnerabilities often stem from fragmented identity architectures reliant on static credentials and duplicated service accounts. As AI operates continuously and autonomously across tools and environments, these issues amplify the impact of any misconfiguration or breach.

Confidence May Mask Underlying Problems

Organisations expressing high confidence in their AI deployments paradoxically encountered more than twice the incident rate of less confident peers. Visibility into AI behaviour remains limited: forty-three per cent noted AI making infrastructure changes without human oversight at least monthly, while seven per cent were unaware of the frequency.

  • With agentic AI – systems capable of independent planning, execution, and task chaining – gaining traction, seventy-nine per cent of organisations are evaluating or deploying it, yet only thirteen per cent feel highly prepared.
  • Sixty-seven per cent still depend on static credentials for AI, correlating with a 20-percentage-point rise in incident rates. Only three per cent possess automated, machine-speed controls for governing AI actions.

Leadership Blind Spots

Teleport CEO Ev Kontsevoy commented: “AI has broken the camel’s back. The rapidly increasing complexity of computing infrastructure has been putting immense pressure on identity management in recent years… deploying non-deterministically behaving agents on top of this mess comes with unpleasant consequences.” He added: “It’s not the AI that’s unsafe. It’s the access we’re giving it.”

The report concludes that identity serves as the essential control plane for AI security. To mitigate risks, organisations should replace static credentials with robust, unified identity systems for both humans and AI, enforce least-privilege access by design, and shift governance to automated, machine-speed processes rather than relying on human oversight.

Teleport

Image:  Ideogram

Source: Cyber Security Intelligence