
Meet the Authors
AI-enabled cyberattacks are lowering the expertise and time required to exploit known SAP vulnerabilities, misconfigurations, and access weaknesses.
SAP access control is becoming a larger cybersecurity risk as attackers and AI agents learn to operate through legitimate business permissions.
SAP security teams need faster, more continuous monitoring as machine-speed attacks expose the limits of periodic reviews and manual response.
AI is eroding assumptions that have long protected complex enterprise systems.
Specialized systems knowledge is easier to reproduce. Known vulnerabilities can be identified and chained more quickly. Unchanged default passwords and users with unnecessary administrative credentials can be mapped and exploited at scale. Authorized activity can become harder to distinguish from malicious behavior. AI agents introduce a new class of identities into enterprise systems. And manual security processes struggle to keep pace with machine-speed attacks.
That is the security challenge behind a new collective warning signed by SAP, Oracle, OpenAI, Microsoft, Google and more than 150 other organizations. The letter says businesses have a limited window to strengthen cyber defenses, warning that AI-enabled attacks will become far more widespread and sophisticated in the coming months.
Security experts interviewed by SAPinsider broadly agree with that diagnosis, but argue the implications for SAP are more specific and extend deeper into the business.
AI Has Changed the Economics of Attack
The immediate risk for SAP customers is that AI can reduce the time, effort, and expertise required to exploit weaknesses that already exist.
“AI collapses the attacker’s cost of reconnaissance, exploit development, and social engineering, so techniques that once required rare SAP-specific expertise become scriptable at scale,” said Ivan Mans, Co-Founder of SecurityBridge.
That means AI does not need to create new SAP vulnerabilities to materially change the threat. Mans said it can instead “industrialize exploitation of the enormous documented backlog,” from SAP Security Notes to misconfigured RFC destinations.
“The window is real: an SAP landscape’s known weaknesses won’t change in the coming months, but the number of adversaries capable of finding and exploiting them will grow dramatically,” Mans said. “Defenders who use this period to close known gaps will be in a fundamentally different position than those who don’t.”
Aman Dhillon, Director at Layer Seven Security, sees the same problem extending beyond application vulnerabilities. Overly broad authorizations, segregation of duties conflicts, insecure integrations and weaknesses across operating systems, databases, SAP Cloud Connector, and Web Dispatcher can all provide potential attack paths.
Robert Holland, Vice President and Research Director at SAPinsider, said recent agent behavior suggests enterprises have little room for complacency.
“We’re seeing the warning shots from AI as some agents may only be a generation or two away from being able to penetrate systems and then modify logs to mask their activities,” Holland said. “We’re running out of time to respond.”
SAP Business Authority Is an Attack Surface
Closing technical vulnerabilities addresses only part of the risk. In SAP environments, an attacker may not need to exploit software at all. A compromised identity may already have more authority than the business requires.
“The letter’s list — legacy systems, excessive permissions, weak authentication, unpatched software, misconfigurations, technical debt — is directionally correct but understates how much SAP-specific risk sits in entitlements and segregation of duties rather than patching,” said Chris Radkowski, SAP GRC Expert at Pathlock.
“An AI-assisted attacker doesn’t need a zero-day if a user already has conflicting roles or access that was never revoked,” Radkowski said.
That makes legitimate access part of the attack surface. An AI-assisted attacker could use permissions the system already recognizes as valid, making malicious activity harder to distinguish from ordinary business transactions. Radkowski said AI could learn an SAP authorization model well enough to “operate just inside the rules.”
“The letter is written for IT infrastructure generally and doesn’t address the layer where SAP risk actually concentrates: business process and transaction-level access.”
The same problem takes on another dimension as enterprises give AI agents legitimate access of their own. Jim Routh, Chief Trust Officer at Saviynt, said those agents need to be governed as identities in their own right.
“As AI agents begin taking action in ERP environments, security leaders must know who owns each agent, what business purpose it serves, what it is authorized to do, and how its access can be monitored or revoked,” Routh said.
He said those identities should be governed with the same principles enterprises apply to people, including least privilege, separation of duties, and continuous oversight.
“Lack of visibility is no longer an excuse for security leaders. We need to start governing AI.”
Keng Lim, Founder and CEO of NextLabs, takes that requirement down to the individual interaction between an AI agent and the enterprise systems it can reach.
“The emerging challenge is not just securing AI systems, but securing the interaction between AI agents and the enterprise data and applications they can access,” Lim said.
That means authorization cannot stop when access is first granted. “Every request for sensitive ERP data should be evaluated against the user or agent, the resource, the action, and the surrounding context,” Lim said, “with policies enforced consistently across SAP and other enterprise environments.”
Manual Security Processes Cannot Keep Pace
“The window for defenders is limited because many organizations still rely on manual security processes that cannot scale at the same pace as AI-enabled threats,” Dhillon said.
That makes AI part of the defensive response as well. Dhillon said organizations can use AI-driven automation to analyze vulnerabilities and security alerts, investigate root causes, and prioritize remediation faster. The objective is not simply to generate more alerts, but to shorten the time between identifying a weakness and acting on it.
“As AI increases the speed and scale of attacks, organizations can use AI-driven automation to keep pace,” he said.
The same pressure applies to governance. Radkowski said controls that identify excessive access every few months arrive too late when an attacker can understand and act on those permissions immediately.
“Security leaders need to know whether they can detect anomalous transaction patterns in real time rather than waiting for the next quarterly audit,” Radkowski said.
Faster detection still leaves a broader problem. Holland said organizations cannot concentrate security around a single application, legacy system, or perceived point of vulnerability. AI-enabled attacks can move across connected systems, making the strength of the wider enterprise environment part of the SAP security equation.
“The threat posed by AI-enabled cyberattacks goes beyond any one vendor or system,” Holland said. “This makes it imperative that security leaders do not focus on a single perceived vulnerability or legacy system but a broader, integrated strategy that offers protection across the enterprise.”
What This Means for SAPinsiders
- Complexity no longer buys safety. SAP landscapes have historically required specialist knowledge to navigate and exploit. As AI reduces that barrier, architectural and authorization complexity can become exposure rather than an inadvertent layer of protection.
- Access governance becomes part of incident response. If attackers can abuse legitimate permissions, access reviews can no longer operate only as periodic compliance exercises. Revoking unnecessary permissions and access quickly becomes part of containing an active security event.
- Security speed becomes a measurable risk. Organizations may have strong controls yet remain exposed if detection, investigation, and remediation move too slowly. Time-to-identify and time-to-restrict dangerous access could become as important as control coverage.




