Australian employees are increasingly concerned about the risks posed by their new AI “coworkers”, according to recent research
This stems from the fact that many workplaces are giving AI agents access to business-critical systems before they have put the appropriate safety measures and security policies in place.
The rapid growth of non-human identities (NHIs) in Australian enterprises, combined with the increasing use of AI in decision-making, human resources, and recruitment, is raising new questions about human oversight, governance, and cybersecurity.
While business leaders are thrilled at the idea of boosting team productivity and optimising manual tasks, the arrival of autonomous-AI has been nothing short of terrifying for the IT department.
Instead of giving AI agents free reign over their systems, organisations should think of AI agents as curious, highly capable, and unpredictable coworkers that don’t always behave themselves. Organisations must prepare for the moment those agents fail to take the right course of action, or stumble across a hidden weakness in their environment and accidentally expose some sensitive information.
Why agentic AI creates new security risks
Agentic AI has significantly increased cyber risk for the average organisation. Every agent creates a new non-human identity (NHI) that must be secured just as rigorously as a human employee account. Already, NHIs significantly outnumber human users in organisations according to Microsoft, with that ratio trending toward a 100:1 ratio as AI adoption grows.
However, Australian organisations are still figuring out how to manage these identities effectively, leaving them exposed to identity-based cyberattacks, sensitive data breaches, and the loss of control over AI systems in the meantime.
That concern is being reflected across Australian workplaces, where IT teams are grappling with the growing security risks tied to identity misuse, data exposure, and lack of human oversight for AI systems.
Concerningly, one in 10 Australian organisations aren’t confident that they could regain control of their systems if AI exposed their administrator credentials, according to Semperis’ latest survey findings. Overall, recovery confidence in Australia is well below the global average, suggesting a wider resilience gap.
Why human oversight still matters
Leadership teams need to stop treating AI adoption, purely, as a productivity issue and start treating it as a security priority that demands ongoing checks and balances.
It is unlikely that your workplace has any formal whole-of-team framework for ‘identity security management’, let alone a framework specific to AI agent identities. This growing gap is revealing a compounding compliance problem that can put real employees at risk.
A large majority of Australian organisations (95%) already use, or plan to use, AI agents to resolve sensitive IT helpdesk tasks, such as password resets and VPN access. Additionally, more than one-third of employees on average have AI installed on their local PCs, where sensitive company data may be reachable to anyone – or anything – that can access it. A data breach can result in entire organisations facing costly downtime, stolen data, financial and reputational damages, and legal consequences.
Unify your organisation’s security strategy
As more AI agents pop up in Australian workplaces, your organisation’s security strategy should factor in both human employees and digital assistants/NHIs.
Regardless of how AI is deployed in workflows, all organisations should be adopting a ‘model of least privilege’ – this is where users are only granted the minimum level of file access required to do their specific jobs.
For example, the marketing team would generally require less access to sensitive company information like financial documents compared with say the accounting team.
To better protect your organisation’s identity environment, you should be asking the below questions about all of your AI agents:
- Does the AI agent have too much unchecked access to sensitive company data that isn’t necessary for its actual function? For example, does it need administrator access with the ability to shut down critical business functions, or does it only require the same level of access you’d give an intern in their first week. If you find the AI agent has been given unrestrained access, reduce this where possible. Remember, it’s a robot - so you shouldn’t give it the same level of trust as a human coworker.
- Where do non-human identities (NHIs) exist across your organisation, and who is responsible for managing the accounts? You can’t protect what you can’t see, so it’s important to take stock of all the NHIs in your digital workplace environment. This way, you can monitor them for any rogue behaviours that could place your company at risk.
- Finally, do you have a cyber resilience plan in place in case an AI agent fails? It’s best to plan for the worst-case scenario, so your organisation can recover quickly and get back to business as usual! Consider what would happen if your AI agent unknowingly exposed your organisation’s administrator login credentials. Would you be able to easily recover access in the event of a cyberattack – and have you got a plan in case this ever happens?
The takeaway
With the rapid growth of non-human identities in Australian workplaces, human resources and organisational leaders are now faced with a hard truth: if you are going to adopt generative-AI and digital assistants into your workflows, you must assume those agents will fail at some point – and plan accordingly.
Alex Weinert is the chief product officer at Semperis