
Meet the Authors
AI mainly speeds up existing attack techniques, shrinking the time attackers need to exploit known weaknesses in enterprise systems.
AI helps defenders triage alerts and interpret SAP-specific telemetry, reducing analyst workload and enabling more precise responses.
AI agents hold credentials and act inside business systems, which is shifting identity security toward decisions about specific actions at runtime.
AI is changing enterprise cybersecurity from two directions at once. Outside the organization, it is compressing the time attackers need to find and exploit weaknesses. Inside, it is increasing the number of software actors that hold credentials and can take consequential actions in business systems. Defenders gain new tools too, as AI helps analysts sort alerts and interpret specialized telemetry faster.
These pressures converge on the ERP systems that run finance, supply chain and payroll. SAPinsider research on SAP security threats shows concerns already moving from data protection toward identity and connectivity. The result is a security problem that increasingly centers on who, or what, is allowed to act.
How Is AI Changing the Cyber Threat Landscape?
AI is changing the threat landscape mainly by compressing the time, cost and expertise attackers need to exploit weaknesses that already exist.
Anthropic’s September 2026 threat intelligence report found that none of the operations it documented relied on an entirely novel technique; the economics of the attacks changed instead. One intrusion moved from a single stolen developer token to full administrative control of a cloud environment in roughly three hours.
In SAP landscapes, that exposes the backlog of known issues, from unapplied security notes to misconfigured systems, which AI can help attackers “industrialize,” in the words of SecurityBridge co-founder Ivan Mans. The defense window increasingly depends on how quickly organizations find and close known exposure.
How Can AI Improve Enterprise Security?
AI can improve enterprise security by reducing analyst workload, sharpening triage and making specialized application telemetry easier to interpret. Most security operations centers are built around network, endpoint and identity data, and many have little visibility into SAP transactions or business processes. When SAP-specific findings do arrive, they often require expertise general SOC analysts lack.
SecurityBridge’s AI Companion translates complex SAP alerts into plain language, explains why a finding matters and suggests remediation steps. Pathlock’s SOC work with NTT Data Business Solutions adds a second point: Linking technical signals to identities and business context lets teams revoke specific access or block a single transaction instead of disrupting an entire system.
AI’s defensive value grows as security data becomes easier to act on precisely.
What New Security Risks Do AI Agents Create Inside Enterprise Systems?
AI agents create a new security problem because they combine the speed of software with authority that once belonged mainly to people. A conventional application follows fixed logic. An agent can hold credentials, reach diverse data sets, call APIs, use tools and take actions based on instructions it interprets at runtime.
That flexibility creates exposure to prompt injection, where malicious content hidden in a document or message redirects an agent’s behavior. NIST’s National Cybersecurity Center of Excellence addressed these issues in a February concept paper on agent identity and authorization, seeking input on how to identify, authorize and audit AI agents and how to establish non-repudiation, meaning proof that a specific agent took a specific action. Without it, an organization may be unable to show which agent acted, on whose behalf and under what authority.
Why Is Identity Becoming Central to AI Security?
Identity is becoming central to AI security because the core control question is shifting from what access an identity holds to whether a human or machine identity should perform a specific action right now. Roles assigned in advance and reviewed periodically strain when an agent’s task changes with each request and its actions can chain across systems in seconds.
NIST’s emphasis on least privilege for agents points toward decisions made at the moment of execution. Saviynt’s Zuma platform illustrates the approach, evaluating each agent’s identity, intent, context and risk at runtime and blocking actions that fall outside its assigned task.
Segregation-of-duties checks face similar pressure, since a conflict can now emerge within a single automated sequence. Identity is becoming the layer where access policy turns into real-time business control.
How Is AI Changing Enterprise Security Governance?
AI is changing enterprise security governance by turning it into a shared control problem that crosses IAM, GRC, application security, SOC operations and compliance. When an agent posts a journal entry or releases a payment, several questions follow: what it could access, which actions required approval, how activity was logged, who owns the risk and whether investigators can reconstruct events afterward.
No single function traditionally answers all of them. SAPinsider’s GRC research describes 2026 as an inflection year, as GRC mandates expand into AI governance many teams are still preparing for. Regulation adds pressure: NIS2 makes management bodies responsible for overseeing cybersecurity measures and requires an early warning within 24 hours of a significant incident, a deadline that depends on evidence spanning identity, application and security logs.
What This Means for SAPinsiders
- Exposure windows are becoming a security metric. As known weaknesses become faster to exploit, the age of an open finding carries risk its severity score may not capture. Time to restrict access is joining time to patch as a benchmark.
- Agent inventories are turning into audit evidence. Records of which agents exist, who owns them and what they touched begin to function like financial controls documentation. A gap in that record can become an audit finding itself.
- Security telemetry needs more business context. Alerts about agent activity are hard to judge without knowing the process, approval chain and data involved. The same signal can be routine in one workflow and fraudulent in another.



