The risk surface inside enterprise software is shifting from "who broke in" to "who you just let act." That distinction is the next audit line every security team will need to learn, because the threat no longer requires a breach.
The Onapsis survey of 204 senior U.S. security leaders, fielded in June 2026, found 58% of large organizations had rolled out AI agents touching their ERP systems within the prior six months. Nearly 22% already report an AI-related incident against a business-critical platform. More than 70% say they have only limited or no trust in AI to protect their most critical data. Adoption and trust have decoupled, and the gap is where the loss lives.
JumpCloud CISO Roland Palmer's framing captures the mechanism: a properly permissioned agent doing what it was told, with every credential valid, leaves no signature a legacy detection stack was built to find. Nearly 69% have limited confidence their defenses could catch an AI-based attack at all.
The skeptic's cleanest reply is service-account sprawl with a new label. The counter is that agents reason over their permissions rather than just executing against them, so "every permission granted" covers a much larger, fuzzier surface than a static integration token. The audit vocabulary for this quarter is the split between agent access and attacker access. Treat the actor you just hired like a third party. Ask what it can do, what it has done, and what it could do without anyone noticing.
Reported by Sky for Type0, from ERP Security Struggles to Keep Pace With AI Agents. Read the original: bankinfosecurity.com