Highlights
Agents inherit the employee's identity, so security teams cannot separate agent actions from human ones.
The approval click is the new phishing click, and its blast radius is far larger.
Pattern-matching detection covers a sliver of cases because exposure lives in human permission, not strings.
The first agent incidents were people, not attackers: personal use of company licenses.
The settled view in security this year is that AI agents are a new attack surface, and that a new surface demands a new category of tooling. Budgets are being drawn up accordingly. The view is half right, and the wrong half is the expensive one.
The identity nobody can see
In a conversation with a security leader at a mid-size technology company this week, the real problem surfaced before I asked about it. His developers run coding agents under their own credentials. "I don't want it running as me," he said. He wants an agent that can do A, B, and C and nothing more. What he has instead is a world where, from the outside, he cannot tell what the agent did from what his employee did.
That sentence is the whole argument. An agent is not a new actor on the network. It is an employee's authority, delegated and accelerated. Every agent incident is therefore a human incident with a shorter fuse, and the control point is not the model: it is the person who said yes.
The click that matters now
Consider how that yes gets given. The same leader put it plainly: companies tell users they are responsible for what their agents do, but that does not mean users understand what the responsibility means. They click yes, yes, yes, and "don't ask me again" on every permission prompt. Of course they do.
We spent twenty years learning that the employee who approves without reading is the vulnerability. Nothing about that employee has changed. What changed is the blast radius of the approval: a write-enabled API sitting behind a reflex. His nightmare was not a sophisticated adversary. It was an agent getting creative inside a customer-record system it was allowed to touch, at a company that never bought the backup tier that would let it recover.
Why pattern matching misses it
He was equally blunt about the detection his endpoint vendor offers for this problem: pattern matching that, in his words, would cover less than ten percent of instances. That tracks. A regex looks for what an agent did. The exposure lives in what a human permitted, in what sequence, and with how much standing authority. Strings do not carry that. Behavior does.
Watch before you write rules
A second security lead, running security alone at a small company, described the instinct beneath it all. Before locking anything down, he wants to watch how people actually use these tools, because rules written in the dark are arbitrary rules. The early evidence supports him. In one deployment we have seen, the first incidents that visibility surfaced were not attacks. They were people: an employee spending roughly two thousand dollars of company tokens on a side business. Policy violations, not intrusions. The adversary was convenience.
A narrower claim
Agent governance behaves like gravity: it pulls toward the largest mass of authority, and in every company that mass is a human being. So instrument the human side of the loop. Know who approved what, which standing authority they delegated, and what happened next. A company that already measures how its people behave under pressure holds the only baseline that matters. Extend it from clicking a phishing email to clicking an approval prompt, and agent risk stops being a new category and becomes a familiar one.
Key Takeways
Inventory which agents run under employee credentials and treat each as delegated human authority.
Log the approval event itself: who clicked yes, to what, and with what standing permission.
Observe real agent usage for a few weeks before writing blocking rules.
Replace string-matching detections with behavior and sequence signals tied to a named person.
Extend your human risk score to include approval behavior, not only phishing clicks.




