NextFin

Darktrace CEO: AI Agents Are the New 'Insider Threat'

Summarized by NextFin AI
  • Darktrace's CEO warns AI agents are the new insider threat, acting with employee-level access but without human context or accountability, requiring board-level governance rather than purely technical controls.
  • The threat is structural, not cyclical: Gartner estimates 40% of enterprise apps will integrate AI agents by end-2026 (up from under 5% in 2025), while only 37% of organizations have a formal secure-AI deployment policy, down 8 percentage points year over year.
  • Survey data shows rising concern amid slipping governance: 76% of security professionals worry about AI agent risks, 97% say AI strengthens defense, yet 46% feel unprepared to defend against AI-driven attacks, unchanged from a year earlier.
  • Darktrace trades at roughly 576.8 pence with a £3.72 billion market cap, named a Leader in Gartner's 2026 Magic Quadrant for Network Detection and Response, positioning behavioral detection as the key capability for monitoring non-human actors.

NextFin News - Darktrace's chief executive said in a television interview on Thursday that AI agents are now the "insider threat" of the enterprise era, reframing a risk that security teams have long treated as a human problem into one created by software that acts with employee-level access but without human context or accountability. The warning, delivered as the Cambridge-based cybersecurity group rolled out its SECURE AI platform last week, lands on a market that has already begun repricing what "trust" means inside the corporate network - and it raises a harder question: when the insider is code, the old controls may not just be weak, they may be blind.

The Event: A New Definition of the Insider

The chief executive's core claim is precise and deliberately provocative: autonomous AI agents - software that can read sensitive data, make decisions, and trigger business processes - now occupy the same privileged position inside an organization that a trusted employee once did. The difference is speed, scale, and the absence of a human conscience or a manager's oversight. In the interview, the executive argued that governance, access controls, and monitoring for these agents must be treated as a board-level responsibility rather than a technical one.

The timing is not incidental. Darktrace made Darktrace / SECURE AI generally available on September 22, two days before the interview, and the company has been building toward this moment through a sequence of moves this year: joining OpenAI's Daybreak Cyber Partner Program in June, integrating behavioral risk signals into Microsoft Agent 365 in August, and publishing guidance arguing that approving an agent is "only the starting point" - the real challenge is watching what it does once it is running.

The market backdrop gives the message weight. Darktrace trades on the London Stock Exchange at roughly 576.8 pence, a market capitalization of about £3.72 billion across 644.7 million shares, and the group was named a Leader in Gartner's 2026 Magic Quadrant for Network Detection and Response for a second consecutive year. It is a company whose entire pitch is that behavior, not signatures, reveals the threat - and the chief executive's argument is that the most important behavior to watch is no longer human.

Why the Agent Threat Is Structural, Not Cyclical

The first judgment any investor should make about this story is whether the risk is cyclical - a wave of bad press and patchy incidents that will recede as vendors ship fixes - or structural, a permanent change in the threat model that will not revert on its own. The evidence points firmly to structural.

Three forces are at work. First, the technology is being embedded into the operating fabric of the enterprise, not bolted on. Gartner has estimated that 40 percent of enterprise applications will integrate task-specific AI agents by the end of 2026, up from less than 5 percent in 2025. Second, the access model is employee-equivalent by design: agents are granted credentials, data permissions, and workflow rights so they can actually do work. Third, the governance layer is lagging adoption rather than leading it. Darktrace's 2026 State of AI Cybersecurity Report, released in February, found that only 37 percent of respondent organizations have a formal policy for securely deploying AI - and that figure is down 8 percentage points from the previous year, even as concern about agent risk has climbed.

A cyclical threat produces a cyclical response: patch, update, move on. A structural shift rewrites the rulebook. The rulebook is being rewritten. The insider-threat category, built over two decades around detecting the rogue employee or the compromised credential, assumed a human actor with human speed and human motives. An agent can exfiltrate, decide, and act at machine speed, with no intent to detect and no manager to question it. That is a change in the nature of the actor, not in the volume of attacks - and changes in the nature of the actor do not mean-revert.

The Data: Concern Rising as Governance Slips

The numbers from Darktrace's February survey of security professionals draw the shape of the problem in detail. More than three-quarters - 76 percent - of security professionals are worried about the security implications of integrating AI agents into their organizations, and the anxiety is most acute at the top: 47 percent of security executives say they are "very concerned." At the same time, 97 percent agree that AI in their own security stack significantly strengthens their ability to defend against attackers. The same tool that makes the defense smarter makes the threat more capable.

The specific risks cluster around access and exposure. Data exposure was identified as the top risk by 61 percent of respondents, followed by violations of data-security and privacy regulations at 56 percent, and misuse or abuse of AI tools at 51 percent. These are not hypothetical failure modes. Darktrace's own telemetry observed a 39 percent month-over-month increase in anomalous data uploads to generative AI services in October, with the average anomalous upload running 75 megabytes - roughly 4,700 pages of documents - leaving the organization unchecked.

Enterprises are embracing AI fast, and while AI tools are helping security teams better defend against attacks, agentic AI introduces a new class of insider risk. These systems can act with the reach of an employee - accessing sensitive data and triggering business processes - without human context or accountability. Our research shows security leaders are already worried, and this cannot be treated as an afterthought. If AI agents are operating inside your organization, their governance, access controls, and monitoring are a board-level responsibility, not just a technical one.

Issy Richards, vice president of product at Darktrace, in the company's February report release.

The attack side of the ledger is equally unforgiving. Nearly three-quarters of security professionals - 73 percent - say AI-powered threats are already having a significant impact on their organizations; 87 percent report that AI is significantly increasing the volume of attacks they face, and 89 percent say AI is making attacks more sophisticated overall. Hyper-personalized phishing is seen as the single greatest AI-powered risk at 50 percent, ahead of automated vulnerability scanning at 45 percent, adaptive malware at 40 percent, and deepfake voice fraud at 39 percent. Yet 46 percent of professionals admit they feel unprepared to defend against AI-driven attacks - essentially unchanged from 45 percent twelve months earlier, a flat line that is arguably the most alarming number in the report. Awareness is rising; readiness is not.

The Second-Order Problem: The Insider Is Now a Platform

The first-order reading of the chief executive's warning is straightforward: agents can be hijacked, misconfigured, or prompted into doing harm, so they need monitoring. That is correct and it is already priced in. The second-order problem is different and less discussed: the agent becomes a new attack surface that sits between the user and the system, and it inherits every privilege of both.

Consider the chain. A sales agent is given access to the CRM, the pricing database, and the approval workflow so it can quote deals end to end. That is the productivity case. Now the agent is manipulated - through a prompt-injection attack, a poisoned data source, or a compromised integration - into approving a discount it was never meant to approve, or into emailing a customer list to an address it has never seen before. The security tooling sees an authorized agent using authorized credentials to perform an authorized action. Nothing looks anomalous at the credential layer. The anomaly is in the intent, and intent is invisible to the tools built for the human-insider era.

This is why the industry's own autonomy numbers matter. In the security operations center, 14 percent of organizations now allow AI to act independently, and a further 70 percent enable AI to take action with human approval; only 13 percent keep AI limited to recommendations. The human-in-the-loop is still the dominant control. But a control that depends on a human approving actions at machine speed is a control with a known failure mode - alert fatigue, rubber-stamping, and the simple reality that a reviewer cannot evaluate in three seconds a decision the agent reached in three milliseconds.

The transmission mechanism, then, is this: agent adoption raises the privilege floor for non-human identities; governance lags; the gap between what an agent can do and what the organization can see it doing widens; and the first loss events will look like insider incidents because the forensic trail will point to a trusted identity. The difference is that the trusted identity is software, and software does not respond to HR investigations.

The Counter-Thesis, the Falsifying Signal, and What to Watch

The skeptical read is available in one line: this is vendor framing, timed to a product launch. Darktrace made SECURE AI generally available on September 22; the chief executive appeared on television on September 24 to describe the very problem that product solves. The company has a direct commercial incentive to amplify the threat. Moreover, the counter-argument continues, the market is already containing the risk: 70 percent of organizations still require human approval before AI acts, identity and access management and privileged-access-management vendors are extending their platforms to non-human identities, and national cybersecurity guidance treats approval as the foundation of safe agentic deployment. The insider threat is being managed, not left to drift.

That case is coherent but it rests on a premise the data contradicts. Governance is not tightening; it is loosening. The share of organizations with a formal secure-AI deployment policy fell 8 percentage points year over year to 37 percent, even as 92 percent of respondents say AI-driven threats are driving major upgrades to their defenses. There is a widening gap between spending and control. The guidance that approval is only the starting point is precisely the point: approval is the easy part, and the industry is still treating it as the whole part. And the human-in-the-loop statistic cuts against the skeptic: 70 percent approval sounds reassuring until you ask what a human reviewer can actually verify when the agent's decision space is larger than the reviewer's attention span.

The falsifying signal is concrete. If, over the next twelve months, the share of AI actions taken with human approval stays at or above 70 percent and the share of organizations with a formal secure-AI deployment policy rises above 50 percent, then the thesis that the governance gap is widening and that agents are becoming the dominant insider vector would be wrong. Watch those two numbers. They are the canary.

The beneficiaries are the vendors whose platforms can see behavior rather than just credentials. Darktrace's pitch - behavioral AI that learns what is normal for each customer and flags deviation - is purpose-built for a world where the actor is non-human and the action is authorized. The same logic applies to identity-security and data-loss-prevention vendors that can correlate agent activity across systems rather than inspecting single transactions. The Microsoft Agent 365 integration, in which Darktrace feeds organization-specific behavioral risk signals into the admin center, is a template for how this capability will be distributed: embedded where agents are managed, not sold as a standalone scanner.

The exposed are twofold. First, organizations that have deployed agents at the workflow level without a corresponding inventory of what those agents can access - the 63 percent without a formal deployment policy. Their loss events will be classified as insider incidents and will be investigated too slowly. Second, cybersecurity vendors whose products are rooted in the human-insider model - rule-based, signature-based, or credential-centric - face the risk that their detection logic is looking at the wrong layer. A market capitalization of £3.72 billion prices Darktrace as a significant but not dominant player; the repricing question is whether behavioral detection of non-human actors becomes a must-have category or remains a niche. The answer depends on the first wave of agent-driven loss events and how visibly they are attributed.

Short term, the signal is the earnings and customer announcements from Darktrace and its peers - specifically whether SECURE AI adoption is being sold as a standalone product or bundled into existing platforms, and what attach rates look like. Medium term, the signal is the loss data: the first publicly attributed incident in which an AI agent, rather than a human insider, is the primary actor will be a category-defining event for the sector. Long term, the signal is regulatory: whether data-protection and financial-services supervisors begin to treat agent governance as a board-level obligation, which would convert a technical control into a compliance requirement and expand the addressable market structurally.

The scenarios split cleanly. In the base case, agent risk becomes a standard line item in enterprise security budgets, growing steadily as adoption deepens. In the upside case for behavioral-security vendors, a high-profile agent-driven breach forces the compliance shift early and the category re-rates. In the downside case, human-in-the-loop controls hold, the policy rate recovers above 50 percent, and the threat remains contained enough that the market treats it as a feature, not a category.

The central judgment is this: the insider threat was never really about the person. It was about trust - about the privileged access granted to an actor the organization decided to believe. AI agents are the purest expression of that problem yet, because they are trusted by design and cannot be trusted by nature. The market that learns to monitor the agent, not just the credential, will be the one that prices this risk correctly.

Explore more exclusive insights at nextfin.ai.

Insights

Why are AI agents new insider threats?

What defines enterprise insider risk?

How does Darktrace SECURE AI work?

When did Darktrace launch SECURE AI?

Is agent risk structural or cyclical?

How many apps use AI agents by 2026?

Why is AI governance lagging behind?

What risks do security teams fear?

How does AI increase attack volume?

Why do humans fail machine speed checks?

Is the agent now a new attack platform?

What falsifies governance gap thesis?

Who wins behavioral security market?

What signals show agent risk growth?

Will rules fix agent governance gaps?

What defines downside risk scenario?

Why is trust the core insider problem?

How does prompt injection harm agents?

Is Darktrace a Gartner NDR leader?

Can human approval stop agent attacks?

Search
NextFinNextFin
NextFin.Al
No Noise, only Signal.
Open App