

Authored by Ben Mudie, Field CTO for Asia Pacific and Japan at Tenable
Artificial intelligence is being adopted rapidly by Indian companies seeking a first-mover advantage, but the pace of deployment is creating new security and governance challenges. As AI agents, machine identities, and automated systems become embedded in enterprise environments, traditional security frameworks struggle to keep pace with the risks posed by non-human identities and excessive permissions.
According to the Cloud and AI Security Risk Report 2026, 52% of non-human identities, including machine identities, AI agents, and service accounts, hold critical excessive permissions, compared with 37% of human identities. Nearly half (49%) of identities with administrative-level privileges have also been inactive for 90 days but remain ‘always-on’ targets.
Ben Mudie, Field CTO for APJ at Tenable, argues that organizations need to rethink their approach to AI security as automation accelerates. He highlights the growing exposure stemming from overprivileged machine identities, dormant administrative accounts, compromised third-party packages, and the limitations of conventional security tools for monitoring AI-driven environments. He also emphasizes how exposure management can provide continuous visibility across human and non-human identities, cloud, code, infrastructure, and AI systems without slowing down innovation.
Indian companies are actively prioritizing rapid AI adoption to gain a first-mover advantage. But speed is pushing governance to the sidelines, and attackers are jumping at the chance to exploit this. According to the Cloud and AI Security Risk Report 2026, 52% of non-human identities, including machine identities, AI agents, and service accounts, hold critical excessive permissions, compared to 37% for human identities. What makes this more concerning is that nearly half (49%) of identities with administrative-level privileges have been inactive for 90 days yet remain ‘always-on’ targets.
Overlooking even the most basic security hygiene significantly elevates risk. As non-human identities slip beyond the radar of governance frameworks, attackers are beginning to leverage AI systems to discover and exploit overprivileged accounts and weak access controls across environments. Recently, state-sponsored adversaries used Claude Code as an automated weapon and infiltrated roughly thirty global targets — tech companies, financial institutions, chemical manufacturers, and government agencies. The AI was used to scan systems, harvest credentials, and then leverage high-privilege identities to create backdoors and access critical data. Human operators stepped in only a handful of times. Everything else was the agent acting alone. Such incidents reiterate the consequences of deploying AI without the right guardrails in place.
Today, most security tools are built to monitor human identities. Human employees go through onboarding, offboarding, and access reviews. Machine identities like service accounts, AI agents, and automated roles don't. They accumulate privileges through rapid deployment cycles and are rarely audited. As AI agents increasingly function like employees within organizations, the security perimeter must extend to include them as well.
By granting agents excessive permission to operate without friction, organizations are effectively leaving the keys under the mat. To make things worse, 65% of organizations have unused or unrotated keys tied to identities with critical or highly excessive permissions, as well as forgotten credentials attached to accounts that still hold full administrative access. In this context, unused does not mean harmless.
Conventional tools miss this entirely. Machine identities don't trigger alerts the way suspicious human behavior does. They enter systems using legitimate credentials, move quietly across networks, and blend in. There is no anomaly to flag because everything looks authorized on paper. This is precisely why adversaries are exploiting this gap. They can operate inside an organization's environment, camouflaged as legitimate entities, causing damage that compounds long before anyone notices. This is exactly why Identity remains a preferred attack vector for adversaries.
In India, around 25% of organizations consider risk and governance significant challenges in AI adoption. At the same time, deployment speed matters, as businesses want a first-mover advantage. But this doesn't mean they have to choose between the two. Instead, they can package their AI deployments with exposure management.
Exposure management helps businesses bridge the visibility gap that surfaces when AI is integrated into their systems, from day one. Beyond misconfigurations and vulnerabilities tied to human identities, it goes deeper into non-human-driven exposures that traditional tools don't reach.
AI security risks emerge from how AI tools interact with surrounding infrastructure and identities, and that is exactly where conventional monitoring falls short. A dormant service account connected to an AI workload. An agent with admin permissions nobody has reviewed in months. A third-party package is quietly feeding the model that carries a known vulnerability. A recent report found that 86% of organizations have at least one third-party code package with a critical-severity vulnerability and 13% have deployed packages with a known history of compromise. These vulnerabilities sit within the gaps between tools.
What makes this dangerous is the combination. A forgotten credential attached to an overprivileged identity, connected to a workload running a compromised package, creates a chain that an attacker can follow from entry point to data exfiltration. Exposure management surfaces these toxic combinations before they become paths to breaches.
With exposure management, businesses get a consolidated view of human and non-human identities, their permissions, interactions, and connections. Not just which AI tools employees are using, but how they are using them, what those tools can access, and where the risk chains form. It maps the full web, code, cloud, identity, and AI in one place.
Exposure management ensures continuous, always-on visibility that scales with AI adoption. When organizations get busy with AI implementation, exposure management guards the system without slowing down the efficiency and innovation that comes with it.
Every unreviewed machine identity, every dormant admin account, every third-party package left unaudited is a liability that quietly compounds until it isn't quiet anymore. Pairing visibility with AI adoption is no longer a choice. Businesses that lead with exposure management will find that the advantages of AI deployment become more promising, not less. It guards the AI and the system, rowing the company forward.
Ben Mudie is Field CTO for Asia Pacific and Japan at Tenable, where he advises global enterprises on managing the modern attack surface and addressing the growing “exposure gap.” With 20 years of experience in the regional technology sector, he brings an engineer’s perspective to Exposure Management, helping organisations identify vulnerabilities and hidden attack paths across IT, cloud and AI environments.
Based in Sydney, Australia, Mudie works at the intersection of customer advocacy, strategic advisory and technical expertise. He is also a frequent contributor to the Asia Pacific cybersecurity community and a speaker at industry conferences.