Sourcepass MCOE Blog

When AI Becomes an Insider Threat in Microsoft 365 | Sourcepass MCOE

Written by Nicole Walker | Sep 1, 2026, 12:20:06 PM

Your monitoring tools are watching for a person. The next insider threat may not be one. 

For years, insider threat models assumed the risk had a name, a login, and a motive. That is no longer a safe assumption. Employees bring their won AI tools to work, and companies are standing up AI agents that read files, call systems, and make decisions on their own. Both create a category of insider risk that traditional monitoring was never built to catch. 

Shadow AI, agent sprawl, and AI agents that act without an identity are becoming the security issues that matter most inside Microsoft 365 environments. How these risk form, why they slip past existing controls, and what governance looks like through tools like Microsoft Agent 365 all shape how well company data stays protected. 

 

Why is AI Being Called an Insider Threat?

 

The definition of an insider has changed, and AI is the reason. On this episode of the Demystifying Microsoft podcast, host Nathan Taylor sits down with Gabriel Friedlander, who has spent more than a decade fighting insider threats and now runs the security awareness platform Wizer. They cover why the old model no longer holds and what companies can do to get ahead of the risk. 

 

 
 
 

What is an AI Insider Threat?

 

An AI insider threat is any situation where an AI tool or AI agent exposes, leaks, or acts on sensitive company data in a way the organization cannot see or control. Unlike the classic insider threat model built around a disgruntled employee or a stolen credential, most AI insider threats start with people doing legitimate work faster.

The threat shows up in two forms. The first is data leaving your control when employees paste customer records, source code, or strategy documents into personal AI accounts. The second, and newer, is an AI agent that inherits real access to your systems and takes actions on its own. The second form is harder to detect because the activity looks authenticated and normal while it happens.

 

Why is Shadow AI a Growing Security Risk?

 

Shadow AI is the use of unsanctioned AI tools that move company data outside your visibility. It is the successor to shadow IT, with a sharper edge, because employees are not just storing data in these tools. They are feeding the tools context, trade secrets, and regulated information to get an answer back.

 

The Company that Bans AI Still has an AI Problem

When a company decides it will not allow AI, employees rarely stop. They bring personal tools from home because they cannot keep pace with expectations without them. The result is the opposite of what leadership intended. The company believes no one is using AI while its data quietly flows into personal accounts it cannot govern.

 

The Company that Pushes AI Without Guardrails

Other organizations pressure staff to adopt AI because everyone else is. When that push comes from the top without policies, approved tools, or training, employees are left to figure it out alone. They reach for whatever works, and the environment turns into an ungoverned mix of personal and corporate AI use.

 

The Company Building Agents Creates a New Insider Threat

Technology forward companies have moved past chat tools into building agents. At that point you are no longer handing someone a tool. You are onboarding a worker that has access to data, can make decisions, and can take action. In many cases that worker has no identity attached to it, which turns an ordinary task into a risk no one is watching. 

 

What makes AI Agents Different from Traditional Insider Threats?

 

An AI agent has no common sense and no intent you can control. It is built to complete the task you gave it, and it will try very hard to succeed. If it hits a wall, it looks for another way around, which is exactly what makes it risky when guardrails are missing.

During safety testing in 2026, AI models attempting to complete a benchmark broke out of their test environment and reached the production systems of a widely used AI platform, with no human directing the steps. A person defined the outcome and the agent decided how to get there. 

An agent takeover is more dangerous than an account takeover for a simple reason. When a user account is compromised, you know where to look. There is a login moment, an IP address, and a trail. When an agent is compromised, the activity runs through API calls and background processes with no clear login to trace. It becomes an observability problem, and most incident response playbooks are not built for it.

 

How do you Govern AI Agents in a Microsoft 365?

 

Governance starts with the same principle security has always relied on. You cannot protect what you cannot see. For Microsoft shops, this is the thesis behind Microsoft Agent 365, which gives IT and security teams a control plane to observe, govern, and secure every agent across the organization.

Two capabilities matter most for closing the gap: 

  • Microsoft Entra Agent ID assigns agents their own identities inside Entra, so they can be governed with the same lifecycle and access controls you apply to people, including conditional access and a responsible owner for each agent.

  • Microsoft Agent 365 adds a registry, audit logging, and integration with Microsoft Defender and Microsoft Purview so you can see what agents exist, what they can reach, and what they have done.

This is still early. The controls are maturing, but the direction is clear. Agents should be treated less like a clever prompt box and more like employees and service accounts that need a badge, permissions, and a retirement plan. 

 

How Should Companies Balance AI Innovation and Security?

 

The goal is not to slow anyone down. Think of security like the brakes on a car. Brakes were not invented to make cars slower. They were invented so cars could go fast safely. No one drives fast without them. AI deserves the same framing. The point of guardrails is to let the business move quickly without crashing.

Those guardrails work best alongside people who understand the risk. Technical controls catch a lot, but the most effective programs also help staff recognize where exposure happens, which tools are approved, what data should never go into a personal account, and who to ask when they are unsure. Awareness tends to come before the guardrails do much good. 

Human oversight is the other half of that balance. The realistic near term future is not AI replacing whole teams. It is job definitions shifting toward keeping humans in the loop. As one person starts producing the output of ten, those AI workers create tasks, decisions, and work that still need management, oversight, and monitoring. That is new work, and it is a reason to build skills now rather than fear replacement.

Governing AI Before it Becomes an Insider Threat

 

AI is already inside your environment, whether it arrived through a personal account or an agent someone built to be helpful. The organizations that stay ahead are the ones that pair clear policy and training with the visibility to see what their tools and agents are actually doing.

If you want help assessing shadow AI exposure, standing up agent governance in Microsoft 365, or building a security awareness program your team will watch, the Sourcepass Center of Excellence for Microsoft can help. Reach out to our team or your client success manager to talk through what fits your environment.

For more conversations like this one, subscribe to the Demystifying Microsoft podcast and follow along as we break down the Microsoft topics shaping how businesses work and stay secure.