← 回總覽

Teleport 报告显示:AI 系统权限过高导致安全事件激增 4 倍

📅 2026-03-29 05:00 Matt Saunders 人工智能 5 分鐘 5290 字 評分: 86
AI 安全 身份管理 企业级 AI 智能体 AI 基础设施安全
📌 一句话摘要 Teleport 的一份报告显示,授予 AI 系统过高权限会导致安全事件增加 4.5 倍,凸显了在自主智能体身份管理方面存在的严重缺口。 📝 详细摘要 Teleport 发布的《2026 年企业基础设施 AI 安全状况报告》指出,随着 AI 的采用速度超过了身份管理的发展,一场重大的安全危机正在酝酿。在接受调查的组织中,92% 已经在生产环境中运行 AI;其中,授予广泛访问权限的组织安全事件发生率为 76%,而采用细粒度访问控制的组织仅为 17%。研究指出,静态凭证(67% 的组织正在使用)和缺乏自动化治理是主要的安全漏洞。值得注意的是,报告发现,过度自信的组织所遭受的安全

Title: Teleport Report Finds Over-Privileged AI Systems Linked to Fourfold Rise in Security Incidents | BestBlogs.dev

URL Source: https://www.bestblogs.dev/article/66824b29

Published Time: 2026-03-28 21:00:00

Markdown Content: Enterprises that grant excessive access permissions to AI systems experience 4.5 times as many security incidents as those that do not, according to The 2026 State of AI in Enterprise Infrastructure Security, a report published by infrastructure identity company Teleport. Based on interviews with 205 CISOs, security architects, and platform leaders, the study found that identity management hasn't kept up with AI adoption in production systems.

The research was conducted in December 2025 and covered organisations with between 500 and 10,000 employees. Of those surveyed, 92% already have AI running in production infrastructure. Some 85% of security leaders say they are concerned about the associated risks, and 59% report having experienced an AI-related security incident, or strongly suspect they have.

!Image 1/filters:no_upscale()/news/2026/03/teleport-ai-report/en/resources/1Screenshot%20From%202026-03-28%2021-00-10-1774731656450.png)

The issue of granting granular access to AI is a core finding in the report. Organisations that granted AI broad permissions reported a 76% incident rate, whereas those that granted it only the access it needed for a specific task saw that figure fall to 17%. The report offers multiple possible explanations for this gap, including AI model sophistication and organisational maturity, but found that access scope was the strongest predictor of outcomes.

> It's not the AI that’s unsafe. It’s the access we’re giving it. > > - Ev Kontsevoy, CEO, Teleport

Writing for the report, Ev Kontsevoy, CEO at Teleport, points to a structural problem that predates AI. "AI has broken the camel's back," he said. "The rapidly increasing complexity of computing infrastructure has been putting immense pressure on identity management in recent years. Most organisations have more groups and roles than employees. And deploying non-deterministically behaving agents on top of this mess comes with unpleasant consequences."

The report traces much of the risk to how credentials are issued to AI systems. Some 67% of organisations still use static credentials for AI, and the study finds these correlate with a 20% increase in incident rates. AI agents that operate continuously across tools and environments inherit the permissions of those credentials, so any misconfiguration or compromise carries a much larger blast radius. Only 3% of respondents have automated controls governing AI behaviour at machine speed.

One finding runs counter to common assumptions: the organisations that expressed the most confidence in their AI deployments experienced more than twice the incident rate of those who were less confident. The report does not explain why, but the pattern recurs across the data. The report also suggests that visibility is low: 43% of respondents say AI makes infrastructure changes without human oversight at least monthly, and 7% say they have no idea how often autonomous changes are made.

Agentic AI, in which systems plan and execute actions without direct human instruction, adds another layer of concern. Some 79% of organisations are already evaluating or deploying such systems, yet only 13% feel well-prepared for the security implications. As Brittney Diesel noted on LinkedIn, the findings "reinforce a familiar reality: identity is becoming the primary control plane, not just for humans and machines, but for AI agents acting autonomously inside critical systems."

Teleport is not the only organisation raising concerns over the access that AI systems have into contemporary organisations. Research from Lumos Identity, published in the same month, found that 96% of organisations experienced an identity-related incident over the past year, with 55% pointing to excessive privilege as a contributing factor.

The report recommends that organisations have a unified identity layer, with static credentials replaced by short-lived, scoped credentials for both human and AI actors. Governance controls should operate at machine speed rather than through manual review. As Infosecurity Magazine noted, 43% of respondents currently have no formal AI governance controls in place, and a further 21% have none at all. These figures suggest the distance between what the report recommends and what organisations are doing remains considerable. infosecurity-magazine

The full report can be read on Teleport's web site.

查看原文 → 發佈: 2026-03-29 05:00:00 收錄: 2026-03-29 06:00:40

🤖 問 AI

針對這篇文章提問,AI 會根據文章內容回答。按 Ctrl+Enter 送出。