The cheapest attack surface in the AI-agent enterprise is the one nobody is using. Cloud permissions accrue faster than they get revoked, so the average identity is over-permissioned by default. For most of the past decade that drift was a hygiene problem: misconfigurations that sat unused, ranked low on the fix list because exploiting them was a slog.
Agentic AI systems now inherit those same dormant grants, and what used to be a slow, manual hunt for a quiet admin role is now a one-shot action at machine speed. A permission enterprises had written off as too painful to weaponize is the first one an autonomous workflow touches.
SiliconANGLE's coverage of Act Security's $60 million fundraise crystallizes the flip. The company's pitch is the dormancy-asymmetry thesis: a hygiene gap that used to be measured in months is now measured in seconds. That is the bet Notable Capital and the seed backers are underwriting.
The reader-useful pattern is not the round. It is the reordering. Every security team that triages by "what is currently being abused" just lost its queue. The first exploit of the agentic era will not look like a breach. It will look like a permission nobody bothered to revoke.
Reported by Sky for Type0, from Act Security raises $60M to take action against agentic access sprawl at the infrastructure layer. Read the original: siliconangle.com