What is an AI insider threat?

By Identra · Updated

An AI insider threat is the risk that someone with legitimate access causes harm through AI, on purpose or by accident. Examples include uploading confidential files to an unapproved AI service or directing an agent to misuse company access.

How does AI change insider risk?

It removes the effort. An analyst who could always open the deal folder can now ask Microsoft 365 Copilot to pull every relevant file into a two-page brief. Their access didn't change. What they can do with it in ten minutes did.

Intent and impact are separate questions. Someone racing a deadline and someone about to leave for a competitor can paste the same spreadsheet into the same chatbot. Establish what happened first. Decide later whether it was a mistake, deliberate misuse or a compromised account.

Where does company data leave through AI?

The browser is the obvious route. A rep pastes customer records into ChatGPT on a personal login instead of the company's ChatGPT Enterprise workspace. That is AI data leakage if the destination falls outside your handling rules. Whether the provider keeps or trains on the content depends on the plan and settings. Training is one concern. Who owns the account, who it's shared with and whether anything can be deleted matter as much.

Endpoints are less obvious. Desktop AI apps and coding agents like Claude Code read local files and run tools. Connected SaaS apps pull data through OAuth grants someone approved months ago. An employee's access is usually much wider than one task needs, which is why AI agent delegation needs explicit limits.

What does it look like in practice?

Say a sales manager is preparing a renewal. They upload the customer's contract and the internal pricing sheet to a personal Claude account to draft negotiation points. The work is legitimate. The upload breaks the rule that pricing stays in the company workspace.

The investigation asks which files went, to which account and whether the chat or output was shared. Use the provider's deletion process, but don't treat deletion as proof that every copy is gone. Then make the company workspace easier to reach than the personal one.

A different case. An employee tells an approved agent to collect customer records for a side business. Same tooling, deliberate misuse. The response is different. The controls on data access and destinations are the same.

How is insider misuse different from account takeover?

An attacker with stolen credentials isn't an insider. Account takeover still makes their actions look like the employee's. A manipulated agent can also act under a trusted identity after reading malicious instructions.

A valid Okta sign-in tells you which account was used. It doesn't tell you who was at the keyboard or why.

  • Accidental exposure

    What sets it apart
    Authorized user makes an unsafe choice
    What to investigate
    Data submitted, destination, applicable policy
  • Deliberate misuse

    What sets it apart
    Authorized user abuses access on purpose
    What to investigate
    Instructions given, business purpose, evidence of intent
  • Compromised account

    What sets it apart
    Attacker controls trusted access
    What to investigate
    Session ownership, unauthorized actions, containment
  • Manipulated agent

    What sets it apart
    Agent departs from the assigned task
    What to investigate
    Original request, content it read, tool actions

How do you reduce AI insider risk?

Start with an AI acceptable use policy people can follow. Name the approved tools. Say plainly whether contracts, source code and customer records can go into them.

Then apply least privilege to agents and connected apps. An approval prompt should show the real action and the real destination.

  • Give people a company AI workspace and enforce work versus personal accounts where you can.
  • Check prompts, pastes and uploads for sensitive data. Test against real workflows and write down the gaps.
  • Scope agents to the repos, folders and mailboxes they need. Reading and exporting are separate permissions.
  • Require a person to approve external sharing, with the data, recipient and action in view.
  • Review OAuth grants after role changes and when projects end.
  • Rehearse two cases. An accidental upload, and an agent export nobody authorized.

What should security teams investigate?

Specific departures from the job. Restricted files going to a personal account. Access to projects the person has no role in. Repeated attempts to get around a block. Odd behavior is a lead. It is not proof of misconduct.

Keep an AI audit trail linking user, account, agent, resource, action and outcome. Pause automation and revoke access as needed. Separate attempted transfers from confirmed exposure.

Limit who sees investigation data and don't collect unrelated employee content. Bring HR and privacy in before anyone judges conduct.

How Identra thinks about it

Identra shows which AI apps people use in the browser and whether they are signed in with a work or personal account, and can redirect them to the company AI workspace. Prompts are checked on the device before they're sent, and uploads to AI are inspected and can be blocked by policy. On macOS and Windows endpoints, AI agent runs are recorded with the user and device. Analysts can revoke risky OAuth grants and, with approval, sign-in sessions.

Go deeper: AI security, built on identity

Frequently asked questions

Does personal AI use prove malicious intent?

No. It may be allowed, accidental or a policy breach. Look at the data, destination and business purpose first.

Can an approved AI tool create insider risk?

Yes. Approving a tool doesn't approve every upload or every agent instruction.

Is an AI agent an insider?

An agent has no intent of its own. It does exercise trusted access, so separate what the employee asked for from what the agent did.

Does turning off model training prevent exposure?

No. Training settings cover one use of the data. They don't make the upload authorized or settle retention, account access and sharing.

Is blocking AI websites enough?

No. Desktop apps, coding agents, APIs and connected SaaS apps are all separate paths.

Related terms

Keep exploring · AI threats and attacks