
Artificial intelligence is enabling cyber-criminals to break into environments and begin movement at a remarkable pace.
For years, most security discussions have focused on preventing the initial compromise. Phishing, credential theft, malware, and ransomware have dominated the conversation.
Those threats remain important, but AI is changing the scale and speed at which attackers can operate once they are inside an environment. What used to take an attacker hours or days can now happen in minutes.
The rise of autonomous AI agents introduces a new challenge. Organisations are increasingly deploying tools that can access systems, interact with applications, retrieve data, execute workflows, and make decisions with minimal human involvement. These capabilities offer significant productivity benefits, but they also create a new risk if they are not tightly controlled.
Lateral movement has always been one of the most dangerous phases of an attack. The initial compromise is often not the ultimate objective. Attackers typically enter through the path of least resistance before moving deeper into an environment in search of sensitive data, privileged accounts, and critical systems.
Traditionally, lateral movement required a degree of manual effort. An attacker had to identify targets, discover relationships between systems, locate credentials, and determine where valuable information was stored.
AI can exponentially accelerate the analysis of this information. It is particularly effective at graph analysis and can rapidly identify privilege escalation opportunities, delegated permissions, and lateral movement paths that might otherwise require significant manual investigation. AI can help attackers rapidly identify which accounts, systems, and permissions are most likely to provide a path to broader access within an environment.
The concern becomes even greater as organisations connect AI agents directly to business systems through APIs, Model Context Protocol (MCP) servers, and workflow automation platforms. Agents are being granted access to collaboration tools, cloud resources, source code repositories, ticketing systems, databases, and file shares. If one of these agents is compromised or manipulated, it effectively becomes a highly privileged service account with visibility across multiple environments.
Prompt injection attacks further complicate the problem. Both research and real-world incidents show that AI systems can be prompted by untrusted inputs that alter their behaviour. If an agent is authorised to perform actions across multiple systems, a successful prompt injection may allow an attacker to influence how those permissions are exercised without needing to compromise the underlying infrastructure.
There is a growing tendency to view AI as a security challenge in its own right. In reality, most of the risks come from excessive trust, which is the same problem security teams have faced for years.
Many organisations continue to operate under the assumption that once an application is approved, it can be trusted. Once a user is authenticated, they can be granted broad access and when a system is connected, it can communicate freely with other systems.
AI simply amplifies the consequences of those assumptions.
An AI agent with unrestricted access can process information faster than any human user. If compromised, that speed now applies to an attack.
The question organisations should be asking is not whether AI can be trusted, but whether any application, user, process, or agent should be trusted with unrestricted access in the first place.
The answer is no.
As AI adoption accelerates, application control is becoming increasingly important.
Application control is often misunderstood as simply deciding which software can run on an endpoint. While that remains a critical function, modern application control is really about enforcing what applications are allowed to do and preventing everything else by default.
If an attacker compromises an AI agent, a browser, a script, or any other application, their ability to cause damage should be limited by policy.
Security teams often spend significant resources trying to identify malicious activity after it begins. A more effective approach is to prevent applications from performing unauthorised actions in the first place.
Should an AI-powered process attempt to access sensitive repositories outside its approved scope, retrieve credentials or secrets, launch PowerShell, create scheduled tasks, execute unauthorised scripts, or interact with systems it was never intended to access, those actions should be blocked by default.
When those controls exist, the blast radius of a compromise becomes dramatically smaller.
No organisation can realistically assume every attack will be stopped at the perimeter. Credentials will be stolen and users will make mistakes, so naturally, vulnerabilities will emerge.
The goal is to build an environment where a compromise does not automatically become a breach, which requires limiting what can happen after initial access.
Application control, least-privilege access, and strong segmentation all serve the same purpose: reducing an attacker’s freedom to operate. When applications, users, and AI agents are restricted to only the actions they genuinely need to perform, lateral movement becomes significantly more difficult. Privilege escalation becomes harder, meaning attackers lose vital flexibility.
Opportunities to pivot between systems become limited. Most importantly, a single compromise is far less likely to become an organisation-wide incident.
AI has created understandable excitement and concern across the cyber-security industry. While there are few publicly documented cases of fully autonomous AI agents conducting real-world intrusions, we are already seeing AI accelerate many of the individual tasks involved in reconnaissance, attack path discovery, privilege analysis, code generation, and operational decision-making.
The same controls that limit traditional lateral movement also limit AI-powered attacks: least privilege, deny-by-default controls, application control, and strict enforcement of what is allowed to run and communicate.
Attacks can move faster with AI, but only if there is freedom to act.
I believe the future of cyber-security will be determined by how organisations limit what attackers, users, applications, and AI agents are allowed to access.
Danny Jenkins is CEO and Co-Founder of ThreatLocker
Main image courtesy of iStockPhoto.com
Winstone House, 3rd Floor,
Units 306-309, 2-4 Dollis park,
London, N3 1HF
020 8349 4363
© 2026, Lyonsdown Limited. teiss® is a registered trademark of Lyonsdown Ltd. VAT registration number: 830519543