惯性聚合 高效追踪和阅读你感兴趣的博客、新闻、科技资讯
阅读原文 在惯性聚合中打开

推荐订阅源

S
SegmentFault 最新的问题
S
Secure Thoughts
Google DeepMind News
Google DeepMind News
cs.AI updates on arXiv.org
cs.AI updates on arXiv.org
S
Security Affairs
TaoSecurity Blog
TaoSecurity Blog
Cloudbric
Cloudbric
Cisco Talos Blog
Cisco Talos Blog
cs.CV updates on arXiv.org
cs.CV updates on arXiv.org
H
Heimdal Security Blog
The Last Watchdog
The Last Watchdog
T
Threatpost
Hacker News: Ask HN
Hacker News: Ask HN
Security Latest
Security Latest
Know Your Adversary
Know Your Adversary
Threat Intelligence Blog | Flashpoint
Threat Intelligence Blog | Flashpoint
S
Securelist
Microsoft Azure Blog
Microsoft Azure Blog
The GitHub Blog
The GitHub Blog
阮一峰的网络日志
阮一峰的网络日志
D
Docker
V
Vulnerabilities – Threatpost
Attack and Defense Labs
Attack and Defense Labs
Hugging Face - Blog
Hugging Face - Blog
W
WeLiveSecurity
Engineering at Meta
Engineering at Meta
aimingoo的专栏
aimingoo的专栏
Last Week in AI
Last Week in AI
L
LINUX DO - 热门话题
NISL@THU
NISL@THU
D
Darknet – Hacking Tools, Hacker News & Cyber Security
The Cloudflare Blog
博客园_首页
P
Privacy International News Feed
Scott Helme
Scott Helme
N
News and Events Feed by Topic
WordPress大学
WordPress大学
宝玉的分享
宝玉的分享
T
Tenable Blog
H
Hacker News: Front Page
N
News and Events Feed by Topic
罗磊的独立博客
Google Online Security Blog
Google Online Security Blog
S
Security @ Cisco Blogs
Hacker News - Newest:
Hacker News - Newest: "LLM"
A
About on SuperTechFans
有赞技术团队
有赞技术团队
K
KPMG report finds enterprise disconnect between AI and its ROI | CIO
G
GRAHAM CLULEY
Application and Cybersecurity Blog
Application and Cybersecurity Blog

Forbes - Innovation

Why Do Humans Have Fingerprints? Hint: It’s Not What You Think Booking.com Confirms Data Breach, Reservation PIN Codes Changed Why Major News Sites Are Blocking The Internet Archive’s Wayback Machine iPhone Fold Release Date: New Report Details Frustrating Apple News Comet Tracker: How To See Pan-STARRS And Three Planets On Wednesday NYT Mini Crossword Today: Tuesday, April 14 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Tuesday, April 14 (It’s A Little Unclear) Today’s Wordle #1760 Hints And Answer For Tuesday, April 14 Most Of The Microplastics In Urban Air Come From Tires Today’s Wordle #1759 Hints And Answer For Monday, April 13 NYT Mini Crossword Today: Monday, April 13 Hints And Answers NYT Pips Today: Hints, Answers And Walkthrough For Monday, April 13 The YC Chief Who Codes 10,000 Lines A Day Has A Simple Secret Samsung Expands One UI 8.5 Beta To More Galaxy Owners Why You Should Stop Using Your iPhone If It’s On This List Chamath Says Firms That Treat AI As A Strategy Hand Rivals Their Edge 3 Unexpected Habits Of Secure Couples, By A Psychologist The First Lamp That Folds Your Clothes Samsung’s Disappointing Price Update For Galaxy Phone Buyers 3 Subtle Signs Someone Is Falling In Love With You, By A Psychologist Do Mantis Shrimp See More Colors Than Humans? A Biologist Explains NYT Connections Answers Explained For Monday, April 13 (#1,037) NYT Connections Hints Today: Monday, April 13 Clues And Answers (#1,037) LEGO Luigi & Mach 8 (72050) Review: 2026’s Best Set Yet? Marc Andreessen Says AI Productivity Will Trigger A Hiring Boom 3D Printing Is The Ultimate Hack To Reduce Household Spending Apple iPhone Fold: Striking Design Revealed In Leaked Photos Apple Smart Glasses: New Leak Reveals A Major Design Twist To Beat Meta Tested: The AI Coming To The Rivian R2 Quordle Hints Today: Monday, April 13 Clues And Answers Companies And H-1B Employees Endure Immigration Waits At Consulates 3 Easy Ways To Turn Anxiety Into Sustained Focus, By A Psychologist Here’s The Most Affordable Humanoid Robot You Can Buy Now UFC 327 Results: 5 Biggest Takeaways From A Wild Night In Miami UFC 327 Results, Bonus Winners, Highlights And Reactions Dana White Announces Huge New Fight For UFC White House Today’s NYT Strands Hints, Spangram, Answers: Sunday, April 12 (Get Ready) Tesla ‘Model 2’ Rises From The Ashes Today’s Wordle #1758 Hints And Answer For Sunday, April 12 NYT Pips Today: Hints, Answers And Walkthrough For Sunday, April 12 Tyson Fury Vs. Arslanbek Mahkmudov Results: Highlights and Reaction NYT Mini Crossword Today: Sunday, April 12 Hints And Answers How Shadow AI Culture Is Destroying Your Business Venture Capital Funds That Market Like Startups Win More Deals Conor Benn Vs. Regis Prograis Results: Highlights and Reaction Samsung’s Disappointing Price Update For Galaxy Phone Buyers Artemis Reached The Moon. The Grid Can Reach The 21st Century A Biologist Explains How Archerfish Shoot Down Prey. Hint: Their Aim Rivals Human Throwing Is It Time For Apple To Forget About The MacBook Air NYT Connections Hints Today: Sunday, April 12 Clues And Answers (#1036) Trump’s 2027 Budget To Reshape U.S. Environmental And Energy Policy CDC Delays Reporting Of COVID-19 Vaccine Benefits—Here’s What To Know Oura Has Designed A Solution To A Big Smart Ring Problem Netflix’s Best New Show Has A Near-Perfect 95% Rotten Tomatoes Score Coachella 2026 Is Being Taken Over By Creator Streams Quordle Hints Today: Sunday, April 12 Clues And Answers This Startup Wants To Use AI To Help Digitize History How To Get The Best Shield In ‘Crimson Desert’ Microsoft Venom Attack Targets C-Suite Executives ‘Maul: Shadow Lord’ Sets Even More Star Wars Rotten Tomatoes Records 3 Ways Happy Couples Argue Differently, By A Psychologist Success For Leapmotor Might Have Negatives For Stellantis New Names Surface As Potential Rogue And Wonder Woman In The MCU And DCU 4 Reasons Artemis Mission Matters Even If You Think It Is Wasteful Fast ‘Crimson Desert’ Patch Adds New Moves, Shield Hiding And One Great Feature Why Do Humans Blush? An Evolutionary Biologist Explains The Signal We Can’t Control Apple iPhone Fold: Striking Design Revealed In Leaked Photos Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update iOS 26.4.1 Release: Crucial iPhone Feature Update Arrives, But No Security Fix Fury vs. Makhmudov Full Card, Ring Walk Times and How to Watch Can’t Stand Liquid Glass? This New Hidden iPhone Setting Is A Game-Changer Test-Driving The 2026 Changan Deepal S05: Italian Style Made In China NSA Warning—Reboot Your Internet Router Now Ways That Human-AI Collaboration Slides People Into ‘AI Brain Fry’ And Cognitive Downturns Stop Using These Networks—Google, NSA And TSA Warn NASA Changes Moon Plan: Landing Now Depends On SpaceX Or Blue Origin Samsung Expands One UI 8.5 Beta To More Galaxy Owners The Evolution Of Programmable Hardware At Xilinx NYT Mini Today: Saturday, April 11 Hints And Answers Today’s NYT Strands Hints, Spangram, Answers: Saturday, April 11 (You’re Putting Me On) Splashdown! NASA’s Artemis II Returns To Earth After Moon Mission Attention Is All You Need. The Human Kind Is Still The One That Counts Today’s Wordle #1757 Hints And Answer For Saturday, April 11 NYT Pips Today: Hints, Answers And Walkthrough For Saturday, April 11 Android Circuit: Galaxy S27 Pro Emerges, Honor 600 Pre-Order Offers, Pixel 11 Display Leaks Apple Loop: iPhone 18 Pro Leak, Urgent iOS Update, MacBook Neo Issues Morgan Stanley Has Mostly Positive Outlook On Tesla Robotaxi, FSD V15 Running Out Of AI Tokens Faster Than Ever? Here’s Why CoreWeave Shares Pop 13% After Anthropic Deal ‘Euphoria’ Season 3’s Rotten Tomatoes Score Crashes, Has Lost Key Player People Don’t Agree On What AI Can Do, But They Don’t Even Use The Same Product ‘Overwhelming’—Google Issues Gemini Update For Gmail Users NYT Connections Hints Today: Saturday, April 11 Clues And Answers (#1035) Quordle Hints Today: Saturday, April 11 Clues And Answers The Costly Dream Of Space-Based AI Infrastructure Can You See The Watcher In This ‘Daredevil: Born Again’ Shot? Adobe Attacks Underway—Windows And Mac Users Given 72 Hours To Update You Just Watched The Backdoor Pilot For ‘The Pitt: Night Shift’ Are Nicotine Pouches Like Zyn And VELO Safe To Use? A Doctor Answers Human Resources (HR) Is The Key To AI Success Per WalkMe ( SAP)
​Ghost Agents: The Hidden AI Risk Most Enterprises Are Missing
Michael Engle · 2026-06-17 · via Forbes - Innovation

Michael Engle is Cofounder at 1Kosmos and was previously head of InfoSec at Lehman Brothers and Cofounder of Bastille Networks.

getty

Lately, I’ve been watching the same movie play out in enterprise AI identity. It goes like this: You register an agent, map it to a human owner, issue credentials and move on, assuming governance is solved.

But over the past year, the organizations I’ve worked with, many with strong identity access management (IAM), disciplined offboarding and credential rotation, are discovering agents operating long after their creators have left. These aren’t anomalies. They’re a byproduct of how AI agents are deployed.

I call them host agents. And when they lose their human anchor, they become something more dangerous: ghost agents.

When Host Agents Become Ghosts

I consider AI-driven systems that act on behalf of a human or a business function to be host agents. They execute workflows, call APIs, provision infrastructure and make decisions across systems without requiring constant human interaction. In theory, each host agent has an owner, but in practice, that ownership is often symbolic.

The moment the human relationship breaks, through role change, project shutdown or employee departure, the agent isn’t terminated. It continues operating with its own credentials, permissions and logic. That’s when a host agent becomes a ghost agent.

I’ve seen this firsthand. In one case, a finance automation agent continued reconciling accounts months after its creator left. It wasn’t malfunctioning. It was doing what it was designed to do. But the business context had changed, and no one was there to correct it.​

Four Ghost Agent Risk Factors

Ghost agents don’t just create isolated incidents. They introduce four categories of risk that compound the longer they operate unchecked.

1. Financial Damage

Agents tied to procurement, cloud provisioning or subscriptions can continue spending long after their purpose is gone. I’ve seen environments where cloud costs failed to drop after projects ended. The root cause wasn’t billing errors. It was agents still provisioning resources based on outdated logic. The spending looked legitimate, the credentials were valid and the system approved the requests. No one questioned it until finance did.

2. Security Exposure

Agents often require broad permissions to do their jobs. When the owner leaves, those permissions don’t automatically disappear with them. That quietly expands the organization’s attack surface.

Unlike human accounts, agents don’t trigger behavioral anomalies in the same way. They’re expected to run at odd hours, across systems and at scale. That makes malicious use, or credential compromise, harder to detect. I’ve seen cases where credentials tied to dormant agents remained active for months, simply because no one knew they existed.

3. Compliance Failures

Regulators and auditors increasingly expect accountability for automated decisions. Ghost agents break that model. When an auditor asks, “Who authorized this action?” and the answer points to someone who left the company six months ago, that’s more of a control failure than a documentation gap.

Frameworks like SOC 2 and GDPR assume a chain of responsibility, and ghost agents break that model.

4. Reputational Damage

Some agents interact directly with customers, including support bots, communication tools and automated responders. When those agents operate on outdated logic, mistakes start piling up.

I’ve seen customer-facing agents continue to promote expired offers, reference discontinued products or respond with outdated policies. Once these governance failures become public, they can quickly erode trust.

The Agent Identity Security Gap

Most organizations assume their existing IAM stack will address these risks, but it doesn’t. That’s because IAM systems track ownership, not runtime behavior. They can tell you who created an agent, when it was registered and what permissions it was granted. None of that addresses whether the agent should still be active.

Credential rotation doesn't fully address the problem either. In many environments, agents continue operating uninterrupted because their credentials are rotated through established processes, preserving access while leaving the underlying question of ownership unresolved. Manual decommissioning is equally difficult at scale. Over time, organizations lose visibility into which agents still serve a valid business purpose and which are simply continuing to operate by default. Agents live in places that IT doesn’t fully control.

I’ve seen organizations with mature identity programs still miss dozens of active agents during offboarding. This isn't because they lack discipline but because the model itself is incomplete.​

Enabling A Kill Switch For Ghost Agents

Solving the ghost agent problem starts with controlling agent access itself.​ I’ve built agents for projects, sales and marketing. To function, these agents needed access to Slack, Microsoft Entra and HubSpot, which places the underlying data at risk. This access needs to be controlled and monitored over time. Most companies with robust compliance frameworks will have these controls in place, but once credentials are issued, many organizations lose visibility into how they’re used or who is accountable for them.

We also need to shift control from identity registration to runtime authorization. Instead of asking, “Who owns this agent?” we need to ask, “Should this agent be allowed to act right now?” That’s a fundamentally different control point.

In a runtime authorization model, every action an agent attempts is evaluated in real time. Access is not assumed based on prior authentication. It is granted dynamically, based on current policy and context, which includes verifying the status of the human owner.

If the owner is no longer active, the agent doesn’t get access. There’s no manual intervention or checklist required, and there's no delay. That’s the kill switch most organizations don’t have today. Additionally, I’m seeing growing interest in human-in-the-loop controls, where agents pause for approval before taking higher-risk actions. The challenge is whether that model can scale at the speed and volume at which agents are expected to operate.

As agent adoption scales, so does the number of autonomous systems operating across environments, often created outside traditional development workflows and without centralized visibility. The longer they run without oversight, the more those risks compound.​

Based on what I’ve seen, most organizations already have ghost agents. The bigger question now is whether they have control over them.​​


Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?