
The AI agents you authorized are now your top threat. Forrester analyst Jitin Shabadu published the firm’s top cybersecurity threats for 2026 this month, ranking AI agent threats as the dominant new risk category, and three of the five new entries trace back to a single failure: personal agents operating as shadow operators inside enterprises, with machine-speed data access and no governance framework built to see them.
- Forrester’s 2026 list shifts focus from external nation-state attacks to threats enterprises may have introduced themselves by deploying personal AI agents without governance controls
- Agent threats, AI identity sprawl, and AI software supply chain risk — three of the five new categories — share the same root: non-human identities acting inside your environment with no identity and access management (IAM) system designed to track them
- Nation-state actors are also using AI to automate exploitation at scale, with China-linked actors documented using Claude for cyber-espionage and Iranian-linked groups targeting US programmable logic controllers (PLCs) across critical infrastructure
- The remediation gap is structural: most security teams have no agent inventory, no Model Context Protocol (MCP) server access controls, and IAM tooling designed for human session flows, not autonomous agent calls
Five New Threat Categories Where AI Agent Threats Dominate
Forrester’s Jitin Shabadu has tracked AI-driven threats since 2023, when the focus was data integrity risk in early large language model adoption. By 2024, the list expanded to include AI weaponization for disinformation, deepfakes, prompt injection attacks, and sensitive data spillage. The 2026 list represents a structural shift: the threats are no longer primarily about what adversaries do with AI — they’re about what enterprises are doing to themselves by deploying AI agents without adequate controls.
The “agent threats” category is the most operationally immediate. Personal AI agents infiltrate enterprises via browser hooks and inbox access, operating as shadow operators that access data at machine speed outside security governance, with CISOs left accountable for activity they cannot see. Shabadu’s framing is precise: these agents don’t trigger multi-factor authentication (MFA) prompts, don’t create session logs a security information and event management (SIEM) system can parse, and don’t stop when the employee goes home. If your helpdesk can reset credentials, your browser-extension AI agent may already be doing things your security operations team will never see in its alert queue.
The “provenance and IAM risks of AI agents” category names the structural gap directly. Legacy IAM systems were built for human users: session-based authentication, MFA enrollment, role-based access tied to a named person. An AI agent calling an internal API inbound from a third-party vendor platform has none of those anchors. Shabadu identifies three control planes needing agent-specific treatment: internal agents your organization deploys, inbound agents calling your APIs from outside, and outbound agents your employees are using to reach external services. Most IAM programs have addressed none of the three. We previously covered how cryptominer abuse of AI gateways is exposing exactly this IAM gap in production environments today.
Why AI Agent Threats Outpace What Legacy IAM Controls Can See
Forrester’s framing buries what is operationally the most consequential finding: the governance gap is not primarily a technology problem, it’s a speed problem. Nation-state actors using Claude for cyber-espionage and Iranian-linked actors targeting PLCs across US critical infrastructure are exploiting the same dynamic — AI lowers the cost and raises the operational tempo of attacks faster than defenders can update detection signatures, IAM policies, or governance frameworks.
The AI software supply chain category adds a second dimension to that speed problem. Agentic AI creates sprawling, rapidly-changing supply chain risks across tools, models, and skills — dependencies that sit on Hugging Face repositories and GitHub packages, outside any vendor’s standard software bill of materials process. The 2024 version of this category focused on open-source models. The 2026 version includes the skills and plugins that agents call at runtime, meaning a compromise in a third-party tool a personal agent uses becomes a path into your enterprise without any direct vulnerability in your own stack.
The digital sovereignty category is the outlier on the list and worth reading separately. Sovereignty-driven tech stack fragmentation — where governments mandate local vendors, local cloud, and local data residency — introduces nascent, undervetted providers your security team has not had the production history to evaluate. Shabadu treats these providers as supply chain risks requiring CISO sign-off, not just procurement approval. Sovereignty compliance gains can introduce security regression if the compensating control evaluation doesn’t happen before rollout.
Three Actions Before Your Next AI Agent Deployment Expands the Exposure
The sequencing logic across these five threat categories points to a single starting gate: you cannot govern what you haven’t inventoried. That inventory — agents, models, MCP server connections, and inbound API callers — is the prerequisite for every other control Forrester recommends.
Inventory every AI agent touching your environment before deploying another – Shabadu specifies three planes: internal agents you’ve deployed, inbound agents calling your APIs, and outbound agents your employees are running via browser hooks and inbox integrations. Most security teams have visibility into one of the three at best. A personal agent installed by an employee through a browser extension is invisible to your agent inventory if you only track what IT provisioned.
Require an AI bill of materials for every agentic deployment – The AI software supply chain category in Forrester’s 2026 list maps directly to the same gap that software supply chain attacks exploited in traditional code: undocumented third-party dependencies. An AI-BOM documents the models, skills, and tool connections an agent uses at runtime, giving your security team the same visibility into agentic software that a standard software bill of materials gives for traditional code. For guidance on securing AI agent orchestration, the controls Forrester recommends here map closely to what practitioners are deploying today.
Implement agent-specific IAM controls before the governance gap widens further – The China-linked actors documented using Claude for cyber-espionage and the Iranian-linked groups targeting US PLCs are operating at a tempo that exploits the window between agent deployment and IAM policy update. Inbound API inspection, provenance verification, and least-agency enforcement are the three controls Shabadu names — and they require tooling built for non-human callers, not retrofitted from human session management. The AI agents your employees authorized through their browsers this week are using that same uncontrolled window right now.
Join our LinkedIn group Information Security Community!









