AI Agents Are Quietly Multiplying Inside Your Company Directory
Every new AI helper needs its own login. Most companies have no idea how many they now have, or what those logins can touch.

Key points
- Netwrix warned in 2025 that AI agents, meaning software programs that act on their own to complete tasks, are creating a flood of new machine logins inside companies.
- These non-human identities, meaning digital accounts used by software instead of people, now often outnumber staff accounts by a wide margin.
- Most organisations can't say who created each AI agent, what data it can reach, or when it should be switched off.
- Attackers who steal one of these logins can move through systems without triggering the alarms built to catch human intruders.
There's a new kind of employee showing up in company networks, and nobody sent HR the paperwork.
It's the AI agent: a small piece of software that logs in, reads files, sends emails and updates records, doing the busywork a junior colleague used to do. Handy. Also, from a security angle, a genuine headache.
Netwrix flagged the problem, and it's worth translating out of the jargon. A new hire gets an account, a password and a permission set. When an AI agent is spun up, it gets the same things. The hire is on a payroll list. The agent, very often, isn't on any list at all.
Why does this matter to anyone outside IT?
Because these invisible accounts hold real keys to real data, including yours.
An AI agent built to help a sales team might have access to the full customer database. One helping finance might see invoices and salaries. Steal that agent's login and you walk in wearing its uniform. No suspicious 3 a.m. Connection from a foreign laptop. Just a machine account doing what machine accounts do, only now for the wrong person.
Security teams call these accounts non-human identities, or NHIs: service accounts, API keys (the digital passes that let one program talk to another), and now AI agents. In many large companies, they already outnumber human staff accounts by 10 to 1, sometimes far more.
We first covered the NHI problem on 15 June 2026, and the beat hasn't slowed. On 9 July our story "AI Agents Are Taking Over Enterprise Systems. Nobody Knows Who They Are." reported a four-hour outage where no one in the room could name which human had authorised the last action.
How did we get here so fast?
Blame the speed of the rollout and corporate enthusiasm in roughly equal measure.
Over the last two years, teams across marketing, finance and customer support have been encouraged to build their own AI helpers using tools from OpenAI, Anthropic, Microsoft and others. Each helper needs credentials to do its job, and each set of credentials is a door. Nobody wanted to slow down the AI experiments, so doors got cut fast and locks got sorted out later.
Netwrix, in comments picked up by BleepingComputer, says most organisations can't answer three basic questions: what AI agents exist, who owns them, and what each one is allowed to touch. It's the same structural failure web teams faced with forgotten admin accounts, now running at a scale and speed those earlier problems never reached.
Should you worry?
If you're a customer or employee of a company rushing to add AI features, it's fair to ask how they track those tools. Not the marketing version. The operational one: who signs off on a new agent, what data it can see, how quickly it gets shut down when the project ends.
The attacks that emerge from this gap won't look dramatic. A helpful assistant, doing helpful things, for the wrong person. Two recent Threat Vectr stories show the mechanics already in motion: researchers demonstrated on 2 July how poisoned context can turn AI browser agents into credential thieves, and on 7 July Zscaler's data showed enterprise AI assistants falling for hidden payment instructions.
Quiet. Automated. Wearing a badge the company issued.
Because technically, it did.



